Prompt injection
Instructions hidden in content the system reads, overriding what it was told to do.
Directly through user input and indirectly through documents and retrieved content.
A scanner that finds SQL injection will not find prompt injection, and a penetration test scoped to endpoints will not find an agent talked into calling a tool outside its scope. Neither substitutes for the other.
The application security surface that has always existed, and has not gone away.
The surface that exists only once a system sends context to a model or lets one act.
Tested adversarially against the deployed feature, not the model in isolation, and repeated on every change to guardrails or tool scope.
Instructions hidden in content the system reads, overriding what it was told to do.
Directly through user input and indirectly through documents and retrieved content.
Extraction of the instructions or embedded values behind a feature.
Adversarial extraction. A secret found in a system prompt is a build defect.
Model output revealing data the requesting user was never entitled to see.
Across roles and permission boundaries, not only against an unauthenticated caller.
A feature able to take actions beyond what its function requires.
By attempting actions outside the intended scope with the feature's own credentials.
Coercing a tool-using feature into calling a tool it should not.
Through argument injection and goal manipulation.
Attacker-controlled content persisting into later sessions and shifting behaviour.
Across sessions rather than within one.
Poisoned or over-permissioned retrieval returning content the user should not reach.
Against the retrieval layer directly, not only through the model.
Tools, plugins and connected services introduced into an agent's reach.
By examining what the agent can call, and the trust it extends to each.
Structured against the OWASP Top 10 for LLM Applications (2025), the OWASP Top 10 for Agentic Applications (2026) and MITRE ATLAS.
Winjit delivers from India and the United States. The controls that make that work are stated here rather than left to a questionnaire.
Access to a client environment is granted per engagement, scoped to the systems the work requires, and revoked when an engineer rolls off.
Client data stays in the client's environment by default. Any processing outside it is named and agreed in writing before work starts.
Client code is worked on from managed devices over controlled network paths, under the access rules agreed for the engagement.
Engineers are background verified and work under confidentiality terms, and access is withdrawn when they leave the engagement.
Certifications and standards are shared with their issuing body, current status and scope during a vendor security review.
There is no comprehensive federal AI statute in the United States. States have legislated separately, and sector regulators have folded AI into existing cybersecurity frameworks. Winjit maintains this picture because delivery decisions depend on it.
Current as of September 2026
Regulatory posture by industry: Insurance Finance Health Tech PropTech
A review of one repository, one service or one AI feature. It returns prioritised findings with severity and a remediation path. No fee for the first review.
Read access to one repository or one deployed feature, and a conversation with whoever owns it.
AI features are tested adversarially against their own threat model, covering prompt injection, system prompt leakage, sensitive information disclosure, excessive agency, tool misuse, memory poisoning and retrieval weaknesses. Testing runs against the deployed feature and repeats on every change to guardrails or tool scope.
Yes. A penetration test scoped to an application's exposed surface will not detect prompt injection, tool misuse or memory poisoning, because those attacks operate through content the system reads rather than through its network surface. Both are required.
Client data stays in the client's environment by default, whoever is working on it. Where an engagement requires processing outside it, the location and the controls are agreed in writing before work starts, and access is scoped to the systems the work requires.
A findings register with severity and state, an AI security test report, a remediation record with retests, a dependency and licence inventory, and a data flow map covering any path that reaches a model provider.