How we work

A method, not a prompt pack.

We combine automated sweepers for known jailbreak families with human-led chaining across model, agent, application, and infrastructure. Nothing ships to you unvalidated.

Scope & threat model

Models, agents, tools, data stores, tenants, and the questions the board actually cares about. Rules of engagement, rate limits, staging versus production, and kill criteria are written before a single payload is sent.

Surface mapping

System prompts, tool schemas, retrieval sources, identity boundaries, and inference infrastructure. Where source is available we read it. Where it is not, we infer it the way an adversary would.

Adversarial testing

Language-layer attacks, indirect injection through retrieved content, tool-use abuse, data-plane isolation, and classic application faults in the glue. Multi-turn and multimodal where the product supports it.

Chain & impact

A jailbreak is not a finding. A jailbreak that exfiltrates another tenant’s context, triggers a privileged tool, or poisons a corpus is. We spend the expensive hours on chains with business impact.

Validate & report

Every issue is reproduced, classified, and written twice: once for the engineer, once for the executive. Payloads, transcripts, tool calls, and residual risk. Mapped to OWASP LLM, OWASP Agentic, MITRE ATLAS, and your control set.

Retest

Fixes are verified in a defined window. Continuous retainers keep the library current as you ship.

Alignment

Frameworks we test against

OWASP LLM Top 10

Injection, disclosure, supply chain, agency, unbounded consumption.

OWASP Agentic

Goal hijacking, tool misuse, privilege abuse, identity confusion.

MITRE ATLAS

Adversarial ML tactics from reconnaissance to impact.

NIST AI RMF · ISO 42001

Evidence that governance is more than a policy PDF.

Deliverables

What you hold at the end.