LLM and RAG security
Assessment of applications combining language models and document retrieval, focused on authorization and information protection.
What we assess
The scope may include ingestion, retrieval, document permissions, access revocation and separation between instructions and retrieved content. Prompt injection and unintended data exposure risks are discussed using test criteria tied to the actual architecture.
Scope and deliverables
The scope is agreed based on the company’s environment and objectives. It may include technical assessment, documented architecture decisions and a prioritized action plan.
Related reading
Related reading · LLM and RAG security
Services
- Security architecture
- Cloud security
- DevSecOps and AppSec
- Identity and access
- AI security
- Assessment and roadmap
- AWS security consulting
- GCP security consulting
Thiago Lima Soneti da Silva (Thiago Silva) — Cyber Architect · Technical lead, Lima e Silva Tecnologia. Profile and experience · LinkedIn