An attack test on the AI that reads text from outside your company
For teams whose AI reads email, documents, tickets or forms
We send 78 written attacks at the place where your model reads text someone else wrote, fix what gets through, retest, and give you the evidence your customers' security reviews ask for.
What you get, and how it is proven
What you get. We take the place in your product where a model reads a document, an email, a ticket or a form that someone outside your company wrote, and attack it the way an attacker would: 78 written attacks across three sets, two of them written blind. You get the fixes, a retest within 30 days, and an evidence pack: a letter stating what was tested and what held, the findings mapped to OWASP LLM01:2025, written answers for the AI sections of your customers' vendor questionnaires, such as FS-ISAC's Generative AI Vendor Risk Assessment, and a signed receipt for every run. The report arrives within ten working days of access. A fixed set of attacks understates what an adaptive attacker can do, so the fixes lead with structure: decisions a later instruction cannot reach, and nothing sent out that you did not allow.
How it is proven. Measured on our own drafting path on 17 September 2026. The fitted set (12 attacks, each run twice) put 8 of 24 attempts through with no defence and 0 of 24 with it. The first blind set (30, each run twice) put 8 of 60 through the defences of that morning, and 0 of 60 after the fixes it prompted. The second (36, run once) put 1 of 36 through, and 0 of 36 after its fix, where 7 attacks produced the wording and every one was held for a person. The blind sets were written by separate agents that were never shown the code. A set that has taught the defence is a baseline: the next unseen set is the next real number.
Price. $7,500 for one integration: the run, the fixes, a retest within 30 days and the evidence pack. The defences can then run through our text-gate API on your own key, from $29 a month.