LLM and RAG security

Assessment of applications combining language models and document retrieval, focused on authorization and information protection.

What we assess

The scope may include ingestion, retrieval, document permissions, access revocation and separation between instructions and retrieved content. Prompt injection and unintended data exposure risks are discussed using test criteria tied to the actual architecture.

Scope and deliverables

The scope is agreed based on the company’s environment and objectives. It may include technical assessment, documented architecture decisions and a prioritized action plan.

Discuss this service

Related reading

Related reading · LLM and RAG security

Services

Thiago Lima Soneti da Silva (Thiago Silva) — Cyber Architect · Technical lead, Lima e Silva Tecnologia. Profile and experience · LinkedIn