ZW-Labs · Penetration testing

Every way in.
We try it first.

Hands-on testing of the systems your business runs on. Every finding comes with evidence and a specific fix, and we retest once you've fixed it.

An LLM feature is a new way into your systems. We test what it can be made to say, reveal and do.

What we look at

  • Direct and indirect prompt injection
  • System-prompt and data disclosure
  • Other users' data leaking through retrieval
  • Tools and actions the model can be tricked into
  • Unsafe rendering of model output
Example findinghigh

A shared document makes the assistant email its contents to an outsider

Mapped to

  • OWASP LLM Top 10
  • NIST AI RMF
  • ISO 42001
Quote for ai & llm features →

How it runs

Scope, test, report, retest.

Nothing is touched until scope and written authorisation are agreed.

  1. Before we start

    Scope

    We agree targets, test accounts, timing and rules of engagement. You sign a written authorisation.

  2. During the test

    Test

    Hands-on testing. Anything critical comes to you the day we find it, not in the final report.

  3. When testing ends

    Report

    An executive summary for leadership, and every finding with evidence, severity and a specific fix.

  4. When you're ready

    Retest

    We verify each fix and reissue the report showing what's closed — ready for auditors and customers.

Questions

Before you book.

How long does a test take?Open +

It depends on scope. A focused web or API test is usually one to two weeks of testing. You get a timeline with the proposal, before anything is agreed.

What do you need from us?Open +

What's in scope, test accounts where relevant, a testing window, and a signed authorisation. We send a short scoping questionnaire to make it quick.

Will it affect production?Open +

We agree the environment and any excluded actions first. A staging copy of production is preferred; where we must test production, destructive checks are excluded or scheduled with you.

Can the report support SOC 2, ISO 27001, PCI DSS or HIPAA?Open +

Yes — it's structured to serve as independent testing evidence. Certifying compliance is your auditor's job; we give them what they need from a test.

Tell us what needs testing — or watching.

Get a quote →