Start a build Book an assessment
Services Work Trust Insights Company Contact Start a build Book an assessment

Field notes from real engagements.

Techniques we actually use, mistakes we keep finding, and checklists you can hand to an engineering team on Monday morning.

FeaturedLLM security

Indirect prompt injection is a data-flow problem, not a prompt problem.

Teams spend months hardening the chatbot against direct attacks while the real risk sits in retrieved documents, ticket text and web pages that the model treats as instructions. We explain how we test it and which controls measurably reduce it.

Probe results Indirect injection
3 / 5Runs followed the injected instruction
0 / 5Runs after tool allowlist applied
Before60%
After0%
  • Injection delivered through retrieved help-centre content, not user input
  • Downstream tool call reached an internal endpoint before the control
Tool allowlist + output validation · sample engagement data
Latest writing

Articles and advisories.

Testing agentic workflows safely

Tool-calling agents expand the blast radius. How to scope a test that explores autonomy without triggering real side effects.

8 min read

The five authorisation bugs we find most

A field guide to object-level, function-level and tenant-boundary failures — with the code pattern that causes each one.

11 min read

Infrastructure drift is the new perimeter

Your application hardened correctly last quarter. Your bucket policy did not survive the rebuild. A pattern we see constantly.

6 min read

Writing a report engineers actually read

Why severity inflation destroys trust, and what a reproducible finding needs to contain to survive a busy sprint.

7 min read

Secrets in build pipelines

Token scope creep in CI is one of the highest-impact, lowest-effort findings we report. How to check yours in an afternoon.

5 min read

Turning a pentest into audit evidence

Mapping technical findings to ISO 27001 Annex A and SOC 2 criteria so one engagement satisfies two obligations.

9 min read
Downloads

Checklists you can use today.

API launch checklist

Twenty-two authorisation, rate-limit and token-lifecycle checks to run before an API reaches production.

LLM feature readiness

A pre-ship review for assistant and agent features: injection surfaces, tool permissions, output handling and logging.

Pentest scoping template

The rules-of-engagement and scope template we send clients, ready for legal review and signature.

Newsletter

One useful security note a month.

No round-ups, no product announcements. A short piece on something we found, how to check for it yourself, and what to do about it.

Request received. We will email the guide to that address.

Want this tested on your own product?

Every article here started as something we found in a live engagement.