I will secure your llm and ai app against prompt injection and data leaks
Lead Security Architect for Hybrid Cloud, IAM and Zero Trust
Vetted by Fiverr Pro
Marlon Costa was selected by the Fiverr Pro team for their expertise.
Vetted for
Cloud Computing
Cybersecurity
Data Governance & Protection
DevOps Engineering
Regulatory Compliance Consulting
Support & IT
About this Gig
Vetted Pro
What can someone make your AI do that you never intended?
An LLM app takes untrusted input and is trusted with your data and your tools. Most ship with the prompt as the only control, and a prompt is not one.
You are probably here because
- Your agent can move money, change records or send things
- Someone showed you a screenshot of it doing something it should not
- A customer asked how you secure it and you could not say
What you get
- What your agent can be made to do, shown not described
- Every finding with the architectural fix, not a prompt tweak
- Guardrails designed: input filtering, tool limits, isolation
- A live session with your engineers, not a slide deck
How it works
- You show me the app and what data and tools it reaches
- I test it as an attacker would, within limits we agree first
- You get the findings and the changes, worked through
What you can count on
Nothing is tested without written limits agreed first: accounts, caps, stop conditions.
Works with
OpenAI, Anthropic, Bedrock, self-hosted models, RAG, agents.
Tested against OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF.
Tell me what you built and I will say which package fits.
Expertise:
Privacy
•
Configuration management
•
Data protection
Technology:
Cloud - IaaS
•
Monitoring
•
Saas
•
Databases
•
Web Application
Regulation:
GDPR
My Portfolio
Other Cybersecurity Services I Offer
FAQ
Is this a real test or just an automated scan?
Both layers. A broad automated baseline for coverage, then manual targeted testing for the high-impact risks automation cannot find, such as indirect injection through RAG. You get reproduction steps and real findings, not just scanner output.
Do you need access to my system?
I test the application layer you authorize. A staging or test environment is preferred. Production testing is possible with your explicit written consent and agreed limits.
What do you need to start?
Your application or endpoint, a short architecture description (model, RAG, tools or plugins, data sources), and written authorization to test. We agree scope before any order.
Do you test the model provider, like OpenAI or Anthropic?
No. I test your application and its integration layer, where almost all real risk lives. I do not test third-party model infrastructure.
Is this legal?
Yes, when authorized. I require written confirmation that you own or control the target and permit testing within an agreed scope and window. This protects both sides.
Do you cover AI agents and RAG?
Yes. Agentic tool and function-call abuse and indirect injection through retrieval are core parts of the targeted battery.
How does this relate to your AI governance gig?
This is the technical security testing layer. If you need framework readiness across NIST AI RMF, ISO 42001, or the EU AI Act, that is my separate AI Governance assessment. They complement each other.

