Testing for hidden malicious instructions in the content your AI ingests, documents, web pages, emails and more.
What is Indirect Prompt Injection Testing?
Indirect prompt injection hides malicious instructions inside content your AI reads, a web page, a PDF, an email, a support ticket, so the attack fires when the model processes that content, without the attacker ever typing into your chatbot.
Why it matters
This is the injection route most teams miss. Any AI that summarises documents, browses the web or reads user-supplied content can be hijacked by poisoned data it was simply asked to process.
How Solusec tests it
We seed realistic poisoned content across the sources your AI consumes and test whether it can be made to leak data, take actions or subvert its behaviour, then show you how to defend the ingestion path.
AI testing, led by a human
Solusec is one of the first firms worldwide accredited under CREST's AI-Enabled Penetration Testing standard, so our use of AI is independently assured: responsible, transparent and always human-led. You get faster, broader testing, your data stays out of public AI tools, and every finding is validated by a qualified tester. Read about the accreditation.
What you get
You get a clear, prioritised report mapped to business risk, a walkthrough of every finding with practical fixes your developers can action, and a free retest once you have remediated. No scanner dump, no jargon, no sales team: you deal directly with the tester.
Common questions
How is this different from normal prompt injection?
Direct injection comes from the attacker's own input; indirect injection is smuggled in through third-party content your AI later processes.
Which systems are at risk?
Any AI that ingests external or user-supplied content: RAG systems, summarisers, browsing agents and document assistants.
How quickly can testing start?
After a short, free scoping call we give a fixed price and a start date, often within days.
Is your AI use safe and independently assured?
Yes. Solusec holds CREST's AI-Enabled Penetration Testing accreditation, which independently assures that our AI use is responsible, secure and human-led.
Related AI security testing
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day