EresusSecurity
Prompt Injection

Test prompt security by impact, not by response filters alone.

Eresus measures how untrusted inputs such as user messages, email, documents, web pages, RAG sources, and MCP tool descriptions can change LLM behavior.

Best fit

This engagement creates value fastest for teams like these.

AI product and platform teams

Teams shipping LLM, RAG, MCP, agent, or model-intake workflows into internal or customer-facing environments.

Security leaders expanding into AI

Organizations that already run pentest programs and now need guardrail, prompt, and tool-abuse validation.

Teams that need explainable hardening

Groups that need policy, prompt, MCP, and runtime findings translated into concrete mitigations and release decisions.

Scope

Direct prompt injection tests
Indirect injection through documents, email, and web content
RAG and context-window manipulation
Tool-call, data leakage, and approval bypass checks

Risk signals

Model ignores system instructions
Hidden content executes instructions the user did not see
Sensitive data enters summaries or tool output
Agent action creates risk even when prompt filters pass

Outcomes

Prompt injection finding set
Reproduction steps for bypassed controls
Prompt, RAG, and tool-boundary fixes
CI/CD or release-gate test recommendations
Test model

A practical test flow that turns input threats into business impact.

01

Problem

We map which untrusted content the LLM reads and which actions it can reach.

02

Attack scenario

We test visible user messages and hidden document instructions separately.

03

Proof

Successful bypasses are shown through responses, tool calls, accessed data, and logs.

04

Delivery

Fixes are described across system prompts, data separation, tool scopes, and approval gates.

FAQ

The questions buyers want answered early.

What AI surfaces and architectures do you test?+
We test autonomous AI agents, LLM integrations, RAG semantic search pipelines, MCP servers, tool execution boundaries, serialized model files (.pkl, .joblib, .gguf, .onnx, .keras), and guardrail implementations.
Is this limited to simple prompt injection testing?+
No. While prompt injection is evaluated, our red team focuses on systemic abuse: privilege escalation via tool use, indirect injection from retrieved documents, model extraction, training data poisoning, and remote code execution via unsafe model deserialization.
How are findings translated into engineering actions for AI teams?+
We map each vulnerability to specific defensive guardrail rules, system prompt structural hardening, strict JSON schema validators for tool calling, context window isolation, or container sandboxing configurations.
What is the duration and pricing for an AI Security Assessment?+
Typical AI and agentic security assessments take between 7 to 20 business days based on agent tooling count, RAG datasource complexity, and custom model architectures. Pricing is scoped transparently per integration boundary.
Do you assess compliance with the EU AI Act and OWASP LLM Top 10?+
Yes. All tests evaluate the full OWASP Top 10 for LLM Applications and provide risk categorization mapped against EU AI Act high-risk system transparency and cybersecurity requirements.
Is retesting included for AI guardrail and prompt fixes?+
Yes. We re-run targeted adversarial jailbreak suites and tool boundary validation within 30 days to ensure patched guardrails cannot be bypassed with semantic permutations.

We tie risk to business impact.

Findings do not stop at severity labels. We explain which customer workflow, data class, or operational objective is affected.

Deliverables work for engineers and executives.

Engineering teams get reproducible proof and remediation direction; leadership gets the risk narrative, priority, and closure status.

Next step

Let’s scope this work against the surface that matters most.

Whether this starts as a pilot, a single application, a critical API, an AI agent flow, or a wider program, we start from the highest-impact surface.