AI, LLMs and agents
What we tested: prompt injection, data leakage, insecure outputs, excessive agent and tool permissions, RAG, font poisoning and integration abuse.
We test Web, Mobile iOS and Android applications, APIs, AI solutions, Cloud, infrastructure and other digital surfaces to identify exploitable flaws and guide remediation of the risks that matter most.
The scope is adapted to the organization's environment and risk. Below are the main surfaces evaluated and the methodologies that guide each test.
What we tested: prompt injection, data leakage, insecure outputs, excessive agent and tool permissions, RAG, font poisoning and integration abuse.
What we tested: authentication, sessions, authorization, injections, XSS, SSRF, file uploads, business logic, components and data protection.
What we tested: local storage, encryption, network communication, certificates, deep links, platform controls, tampering, reverse engineering, and APIs.
What we tested: REST, GraphQL, SOAP and gRPC APIs, authorization by object and function, tokens, rate limiting, sensitive flows, data exposure and injections.
What we tested: AWS, Azure and Google Cloud environments, IAM, privileges, storage, secrets, networks, exposed services, metadata, logs and serverless.
What we tested: external perimeters, internal networks, servers, VPNs, Active Directory, services, credentials, segmentation, lateral movement and privileges.
Each assessment begins with a clear definition of the scope, technical context, assets involved, testing objectives and rules of engagement.
Execution follows previously established operational limits, security criteria and communication channels, reducing risks to availability and business continuity.
At the end, findings are technically validated and documented with evidence and remediation recommendations. When applicable, remediation is retested to confirm that the vulnerability has been effectively eliminated.
We align assets, objectives, restrictions, criticality and success criteria.
We identify technologies, exposed surfaces and points relevant to testing.
We validate vulnerabilities with manual techniques and expert-led automation.
We relate technical evidence to real risk to data, systems and operations.
We deliver prioritized recommendations and confirm the effectiveness of corrections.
Tools are important for expanding coverage, but they do not alone understand context, impact and business logic.
The results are organized for technical teams, those responsible for risk and leaders who need to define priorities.
Speak with Fortis Aegis to define the Pentest type, scope and depth appropriate for your environment.
Plan my Pentest