AI red-teaming · EU-based

Test your chatbot before someone else does.

AltaSec attacks your AI assistant the way real users and attackers will, checks every answer against your own rules, and hands you evidence — including what we could not test.

A testing service: we run the tests and deliver the report. We need your chatbot’s endpoint and your written authorization — no code access.

Report excerpt · Coverage and findings
Illustrative example · synthetic data
Example report rows: the outcome for each rule tested, with the evidence or reason behind it
OutcomeRule tested · evidence or reason
Violation Discloses system prompt under injectiontranscript + detector match, human-reviewed
Verified pass Never reveals other customers’ dataverified: planted canary not disclosed
No violation found Only discusses our productsjudged, not verified — no positive check exists for this rule
Not assessed Refuses medical advicetarget timed out — not tested, reason stated
Not tested is never green. A pass has to be earned by a positive check.
The problem

AI shipped fast. Testing didn’t keep up.

Classic pentests and scanners look at servers and code, not at how a language model behaves when someone talks to it. That gap is where things go wrong.

  • It leaks what it knows

    System prompts, keys, personal data and internal documents can come out in an answer when someone asks the right way.

  • It gets talked into things

    Prompt injection and jailbreaks push it outside the job you gave it.

  • It breaks your rules

    It gives answers your own policy forbids — and you are the one who has to explain them under GDPR and the EU AI Act.

What we test

Testing that understands language models

Two checks are part of every engagement today. The third is next on our roadmap.

01 · Red-teamNow

Attack your chatbot before someone else does

We run automated adversarial tests against your text chatbot or assistant through its API: jailbreaks, prompt injection and attempts to pull data out of it. Every reply is checked for:

  • leaked secrets and API keys
  • personal data — Dutch, German and English
  • planted canary data turning up where it must not
  • risky output: script injection, javascript: links, markdown-image exfiltration, phishing links
02 · Your rules, as testsNow

Turn your rules into tests that run

You tell us in writing what your AI is for and what it must never share or do. We turn that policy into targeted tests and report on every rule.

Rule packs map the results to GDPR, the EU AI Act and the OWASP Top 10 for LLM Applications — as evidence for your own assessment, not a compliance verdict.

03 · Data checkNext · on the roadmap

Find the data your AI should never have seen

Scanning what you feed the AI — system prompts, knowledge bases and training sets — for personal data and secrets, before they end up in an answer.

On our roadmap, not yet part of an engagement. Today we detect this data when it comes out in the chatbot’s replies.

What you get

A report you can check

Every engagement ends with an HTML report and a machine-readable JSON export. Each finding carries the evidence behind it, and the report says plainly what was and was not tested.

  • Evidence transcripts

    The exact conversation behind each finding, so your team can reproduce it.

  • Coverage statement

    What was tested against which rule — and what was not assessed, with the reason.

  • Explicit limitations

    Results are point-in-time and not exhaustive. The report says so, and names the gaps.

  • JSON export

    The same findings in machine-readable form, for your tracker or your own analysis.

  • Human-reviewed findings

    A person reviews every finding before it reaches the report.

  • A fix per finding

    Each finding comes with a concrete recommendation for your developers.

findings.jsonexcerpt · simplified · synthetic
{
  "rule": "Never reveals other customers’ data",
  "outcome": "no_violation_verified",
  "basis": "planted canary not disclosed"
},
{
  "rule": "Refuses medical advice",
  "outcome": "not_assessed",
  "reason": "target timed out"
}

“Not assessed” is its own outcome. It is never counted as a pass, and a pass is only “verified” when a positive check backs it.

How it works

From scope to evidence

  1. Scope & authorize

    You sign the rules of engagement and a written authorization. Together we agree what is tested and the request limits.

  2. Test

    We run automated attacks against your chatbot’s endpoint, within the agreed limits. No code access needed.

  3. Judge & review

    An LLM judge, kept isolated from the attack content, scores each reply against your rules. A person reviews the findings.

  4. Report & retest

    You get the report and the JSON export. Re-testing with a fixed / regressed / new comparison between runs is next.

    Re-test comparison: Next
Why AltaSec

Precise, calm, accountable

  • EU-only processing

    Engagement data is processed in the EU only, by processors named in our data processing agreement with you.

  • Not tested is never green

    Anything we could not test is marked “not assessed”, with the reason. A pass has to be earned by a positive check.

  • Evidence you can check

    Every finding links to its transcript and the check that caught it. You do not have to take our word for it.

  • Pseudonymised, then deleted

    Your data is pseudonymised, and evidence is deleted when the engagement closes, per the retention we agree with you.

Our results are point-in-time and not exhaustive. We issue reports with evidence — never certificates, seals or badges.

Roadmap

What we do now, and what comes next

Now

Available today

  • Red-team of your text chatbot or assistant over its API
  • Tests generated from your written policy, mapped to GDPR, the EU AI Act and the OWASP Top 10 for LLM Applications
  • Evidence report: HTML and JSON, with coverage statement and limitations
Next

In development

  • Re-testing with a fixed / regressed / new comparison between runs
  • Policy conformance checks
  • Scanning data fed into the AI — system prompts, knowledge bases, training sets — for personal data and secrets
  • Multi-turn attacks
  • Testing through the live chat widget on your website
  • PDF reports
Later

Planned

  • Voice agents, on the web and by phone
  • Tool-using agents and MCP

Only the “Now” column is part of an engagement today.

Contact

Book an AI audit

Tell us which chatbot you want tested and what it is for. We will reply with how an engagement would work for you.