02 Secure · AI Security Assurance

Test whether the security boundary actually holds.

An independent security assessment of an AI system as it is configured, not as it is documented. We examine identity, privilege, data exposure, injection resistance, tool access, logging and containment, then state the residual exposure plainly.

Assessment sequence

  1. 01Map identity, privilege and data reach
  2. 02Map tools, integrations and write actions
  3. 03Exercise injection, leakage and misuse paths
  4. 04Assess logging, detection and containment
  5. 05State residual exposure and required remediation

Who this is for

Organisations giving an AI system access to sensitive data or real systems.

  • Security leaders assessing an AI capability outside conventional application testing
  • Organisations deploying retrieval, copilots or agents over confidential data
  • Teams integrating AI with systems that can be written to or triggered
  • Risk functions that need exposure stated rather than reassured
  • Boards approving AI use where a breach would be material

Outcomes

What changes for the organisation

Tested control findings

Findings based on exercising the controls, not on reviewing the design description.

Exposure ranked by consequence

Issues ordered by the data, systems and authority genuinely at stake.

Remediation that can be verified

Fixes expressed so retesting can confirm the control now operates.

What Alacrix does

We look at what the system can reach and what an attacker could make it do.

AI security failures usually come from delegated access, retrieved content and tool permissions rather than from the model itself.

  • Review identity, service accounts, scopes and inherited privilege
  • Map retrieval scope, data residency, retention and vendor processing
  • Exercise prompt injection through documents, tools and third-party content
  • Test tool and action permissions, including chained and agentic behaviour
  • Assess logging sufficiency, alerting and investigation capability
  • Assess containment, revocation and recovery under a live incident

Assessment domains

What we examine

Six security domains applied to the system as configured.

Identity and permission

Who and what the system acts as, what it inherits, and whether least privilege survives contact with real workflows.

Data exposure

What the system can read, retain, transmit or expose, including retrieval scope, context leakage and vendor processing.

Prompt and input attack

Injection through documents, tools, email and retrieved content, and whether the system can be steered outside intent.

Tool and action surface

External calls, integrations and write actions the system can invoke, and the blast radius of each.

Logging and detection

Whether the record is sufficient to notice misuse, investigate an incident and reconstruct what happened.

Containment

Rate limits, kill paths, credential revocation, isolation and the practical route to stopping the system quickly.

Deliverables

What you leave with

Independent AI security assessment report
Identity, privilege and data reach map
Injection and misuse test findings
Tool and action surface analysis
Logging, detection and containment gap analysis
Prioritised remediation with verification criteria

Independent, not self-assured

We report exposure, we do not remove it for you.

Remediation is delivered by your team or your supplier. Alacrix verifies whether the fix operates, which keeps the assessment independent.

  • We do not build or operate the system under assessment
  • Every finding names the affected data, system or authority
  • Residual exposure is stated rather than softened
  • This is an independent assurance opinion, not a certification or accreditation

Engagement process

How the work runs

  1. 01

    Map

    Establish identity, privilege, data reach, tool access and the real action surface.

  2. 02

    Test

    Exercise injection, leakage, privilege and containment paths against the live configuration.

  3. 03

    Conclude

    Rank exposure by consequence and set verifiable remediation and retest criteria.

Next step

Find the exposure before someone else does.

An independent AI security assessment establishes what the system can reach, how it can be steered and what would contain an incident.