AI Agent & LLM Security Review

AI agents can read your email, call your APIs and change your data, which makes them a new and attractive attack surface. As a CISSP-certified security leader who also builds agents, I review AI systems the way an attacker would look at them, and the way an auditor will.

What I review

  • Prompt injection, including indirect injection through documents, web pages and tool output
  • Tool and MCP server permissions, and least privilege for agent actions
  • Data leakage of secrets, personal data and confidential information through prompts, logs and outputs
  • Human-in-the-loop controls, approval gates and blast-radius limits
  • Supply-chain risk from models, plugins, MCP servers and third-party AI vendors
  • Logging, monitoring and incident response for AI-driven actions
  • Alignment with ISO/IEC 42001, ISO 27001 and the OWASP Top 10 for LLM applications

Also available

Independent review of AI features before launch, AI supplier due diligence, and help answering the AI sections of customer security questionnaires.

AI Agent & LLM Security Review

What you get

  • A prioritised findings report with clear severity ratings
  • Practical remediation guidance your engineers can act on
  • A re-test once fixes are in
  • An executive summary for leadership or the board