AI Security AssessmentRAG · agents · vendors

Review the AI system before it becomes production infrastructure

SundAI combines cybersecurity with AI governance to assess how data, identity, retrieval, model behaviour, tools, suppliers, logging and human oversight work together in the real system.

What this service is for

For organisations evaluating an AI assistant, RAG system, copilot, agent, vendor platform or AI-enabled workflow before deployment, renewal or wider rollout.

ArchitectureTrace data, identity, retrieval, model context, tools and output paths.
MisuseTest realistic failure modes such as prompt injection, leakage and excessive agency.
OperationsEnsure logging, incident response, change control and fallback are defined.

Assessment areas

AreaKey questionsExample evidence
DataWhat enters the system, where is it processed, retained or reused?Data-flow map, retention settings, supplier terms.
Identity & accessWho can query, administer, connect sources and invoke tools?SSO/RBAC design, privileged access, tenant controls.
RAGAre source permissions preserved and embeddings protected?Retrieval architecture, ACL filtering, deletion flow.
Prompt injectionCan users or documents override policy or trigger unsafe behaviour?Adversarial test cases and mitigations.
Agents & toolsCan the model take actions beyond the user’s intended authority?Tool allowlists, scopes, approval gates.
Vendor / modelHow do model changes, subprocessors and customer-data terms affect risk?Vendor assessment and change-notification controls.
LoggingCan material actions and incidents be reconstructed?Audit events, SIEM integration, retention.
Human oversightWhere must a person verify, approve, intervene or stop the workflow?Escalation and fallback design.

Typical deliverables

Security references used

The assessment can draw on OWASP GenAI guidance, the NIST AI Risk Management Framework and its Generative AI Profile, and ISO/IEC 27001 security-management principles. These references are used as practical baselines; they do not replace a system-specific threat model or testing.

When to assess

MomentWhy it matters
Before procurementContract, data and architecture constraints can still be changed.
Before pilotBoundaries and test cases can be designed before users depend on the system.
Before productionLogging, incident response and human oversight should be operational.
After major model / tool changesBehaviour and attack surface may have materially changed.
Assessment boundary: an AI security assessment reduces uncertainty; it cannot guarantee that a system is secure or eliminate all model behaviour risk. Findings should be managed through ongoing monitoring and change control.

Reference sources

Need a focused review of an AI system or vendor?

SundAI can assess the control surface and turn findings into a prioritised remediation plan.

Contact SundAI via Services →