AI penetration testing companies, products & suppliers

Scoped technical pentests of AI-enabled systems, including infra and apps. Jobs: scoped ai pentests; combined app+model tests; remediation retest.

What is AI penetration testing?

Scoped technical pentests of AI-enabled systems, including infra and apps. Jobs: scoped ai pentests; combined app+model tests; remediation retest.

What problems does it solve?

Pentest scopes still omit model hosts, tools and prompt paths.

Typical business use cases

  • Scoped AI pentests
  • Combined app+model tests
  • Remediation retest

Important capabilities

  • Scope
  • Exploit evidence
  • Retest

What buyers should evaluate

  • Tester independence
  • Scope completeness
  • Data handling of exploits

Risks and governance considerations

Exploit payloads stored with production data.

Procurement checklist

  • Scope letter
  • Data handling
  • Retest

Relevant AI Trustmark assurance

AI Trustmark independent findings appear only when an assessment or certificate exists. Category membership does not imply verification.

Methodology · How verification works

Companies and providers

Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.

  • Secure AI agents with Giskard’s continuous AI red teaming. Detect vulnerabilities, improve LLM security, and safeguard your AI systems. Giskard publishes Giskard Guards, Giskard Hu

  • Secure your AI with HiddenLayer’s end-to-end platform that detects threats, protects models, and ensures safe, compliant AI adoption at scale. HiddenLayer, Inc. trades as HiddenLay

  • We help agent builders create reliable, robust and secure products. Invariant Labs publishes Invariant Explorer and Invariant Gateway as named AI products. Invariant Labs is used f

  • Discover, assess and red team AI models, agents and applications with Mindgard’s attacker-aligned AI security platform. Mindgard publishes Mindgard DAST-AI and Mindgard AI Security

  • NCC Group is a UK cyber-security company. Public pages describe assurance, testing, incident response and related security services, including assessment of AI-enabled systems. NCC

  • Protect your AI Agents and Applications from attacks, hallucinations and data leakages with our AI native entreprise-grade cybersecurity solutions. NeuralTrust publishes TrustTest,

  • Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’

  • Open-source tools, research, analysis, and guidance to understand and respond to AI threats. Prompt Security publishes Prompt Security Automated AI Red Teaming and Prompt Security

  • SplxAI provides the most comprehensive platform for AI Security Testing and Red Teaming, ensuring your AI Assistants and Agents are secure and reliable from build to runtime. SPLXA

Products

Claimed products appear first. Ranking packs and payment do not change this list.

Related categories

Relevant procurement and assurance guides

Frequently asked questions

What is AI penetration testing?

Scoped technical pentests of AI-enabled systems, including infra and apps. Jobs: scoped ai pentests; combined app+model tests; remediation retest.

What should not be listed as AI penetration testing?

Products whose buyer job is LLM red-team narrative exercises, scanners, or general cyber pentest without AI scope. Those belong on their own category page so search queries are not split.

Has AI Trustmark independently assessed every AI penetration testing supplier?

No. A category listing is descriptive. Independent assessment is shown only on company or product pages that carry Trustmark evidence.

What security testing evidence should buyers request for an AI product?

Ask what was tested, against which version, whether prompt-injection, data-exfiltration and tenant isolation were in scope, and where failed prompts were stored. A generic ISO certificate or a vendor scanner screenshot is not by itself an AI TrustMark assessment.

How should prompt injection and tool-output attacks be controlled?

Agents that read untrusted content or tool output can be instructed to exfiltrate data or take writes. Buyers should ask what is treated as untrusted, whether tool output can change the plan, and what tests were run. Scanner marketing is not the same as independent testing.

What model or provider changes should a buyer insist on being told about?

Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.

How should buyers verify where AI customer data is processed?

Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.

Does a TrustMark on one product cover the rest of the company?

No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.