I will perform ai security risk assessment and llm penetration testing


About this gig
Is your AI or LLM-powered app secure against prompt injection and data leakage?
Traditional penetration testing often misses the risks unique to AI systems. I help startups, SaaS companies, and development teams identify security weaknesses in AI and LLM-powered applications through structured, manual AI security assessments based on the OWASP Top 10 for LLM Applications.
My assessment focuses on the application layer (not the underlying model provider) and may include:
- Direct & indirect prompt injection testing
- System prompt exposure
- Sensitive information disclosure
- RAG (Retrieval-Augmented Generation) security
- Unsafe output handling
- Tool & agent permission review
- Business logic analysis
- AI threat modeling
Every engagement includes:
- Validated findings with severity ratings
- Proof-of-concept evidence (where appropriate)
- Reproduction steps & business impact
- Practical remediation guidance
- Professional security report
Certifications: TryHackMe AI1, Certified LLM Security Professional (CLLMSP) plus ongoing hands-on research in authorized AI security labs.
️
Testing is performed only on systems you own or have written authorization to test.
Get to know Raduan Ahamed
Web Application Penetration Tester and AI Security Specialist
- FromBangladesh
- Member sinceJul 2026
- Avg. response time1 hour
Languages
Bengali, English, Hindi
FAQ
Do you test the AI model itself (GPT, Claude, Gemini, Llama, etc.)?
No. This service evaluates your application's AI integration layer, including prompts, guardrails, RAG pipelines, tool usage, output handling, permissions, and data flow. It does not assess or attack the infrastructure or security of the underlying AI model provider.
What types of AI applications can you assess?
I can assess AI-powered web applications, chatbots, AI assistants, Retrieval-Augmented Generation (RAG) systems, AI agents, internal AI tools, and applications that integrate GPT, Gemini, Claude, or similar large language models.
What deliverables will I receive?
You'll receive a professional security report containing validated findings, severity ratings, affected components, reproduction steps, evidence where appropriate, business impact, and practical remediation recommendations. Higher-tier packages also include an AI threat model and verification
Do I need to provide authorization before testing?
Yes. I only perform security assessments on applications you own or are explicitly authorized to test. Before starting, we'll confirm the assessment scope and written authorization to ensure all testing is conducted ethically and legally.
Can you test applications that use RAG or external tools?
Yes. Standard and Premium packages can include security assessments for Retrieval-Augmented Generation (RAG) pipelines, external APIs, tool integrations, AI agents, and data retrieval workflows within the agreed testing scope.
Can you guarantee that all security vulnerabilities will be found?
No security assessment can guarantee complete coverage. My goal is to perform a thorough manual assessment within the agreed scope, validate identified security issues, and provide practical recommendations to help strengthen your AI application's security posture.
