Home Small Business AI Security Security Audits Custom Agents Contact MentourCorp.com Request an audit

AI Continua / Security Audits

An AI security audit that ends with fixes, not a slide deck

We test your AI systems the way an attacker would, review how they are built, and hand your engineers reproducible findings ranked by real-world risk.

What we examine

Four workstreams, one combined picture of risk

An AI system can be robust in the model and fragile everywhere around it. We look at all of it.

Adversarial testing

Prompt injection (direct and indirect), jailbreaks, system-prompt extraction, data exfiltration, tool misuse and multi-turn manipulation, run against your actual deployment.

Architecture and data-flow review

Trust boundaries, authentication, retrieval permissions, secrets handling, logging, and what data reaches which model, vendor and region.

Agent and tool permission review

Which actions each agent can take, with what credentials, under what approvals. We test whether those limits hold when instructions are manipulated.

Governance and compliance mapping

Policies, inventory, ownership, incident response and documentation, compared with NIST AI RMF, ISO/IEC 42001, the EU AI Act and your own control framework.

How it runs

A clear sequence, with no surprises

Scope and rules of engagement

Agree on systems, environments, test accounts, data handling and stop conditions in writing.

Test and review

Automated attack suites plus manual testing, alongside design and configuration review with your engineers.

Report and walkthrough

Findings with evidence, severity and fixes. A live session so your team can ask questions and challenge ratings.

Retest

We verify each fix and mark findings closed, with regression tests left behind in your pipeline.

The report

Every finding can be reproduced and fixed

You get the exact input, the observed output, why it matters in your business context, and the change we recommend. Engineers do not need to guess what we meant.

  • Executive summary written for the CISO and model owner, in plain language.
  • Technical findings with severity, evidence, affected components and framework mapping.
  • Remediation plan ordered by risk reduction per unit of effort.
  • Residual risk statement that is honest about what cannot be fully closed.

Engagement options

Sized to what you need to know

Scope and timing are confirmed after a scoping call, because they depend on how many systems you have and how they connect.

Focused assessment

One AI system

A fast, deep look at a single chatbot, copilot or agent, usually before launch or after a major change.

  • Adversarial testing
  • Configuration and design review
  • Findings report and walkthrough
Scope a focused assessment
Most requested

Full audit with retest

One system or a connected group

The complete four-workstream audit, including governance mapping and verification of your fixes.

  • All four workstreams
  • Framework mapping
  • Retest and closure letter
  • Regression tests for your CI
Request a full audit

Continuous assurance

Ongoing

Scheduled re-testing and monitoring so your assurance keeps pace with model, prompt and data changes.

  • Attack replays on each release
  • Drift and abuse monitoring
  • Regular reporting to owners
Discuss continuous assurance

Audit questions

Is this a certification?

No. An AI Continua audit is an independent technical assessment mapped to recognized frameworks. It is not a formal certification under ISO/IEC 42001 or any other scheme, and it is not legal advice.

What access do you need?

Typically a staging environment, test accounts at several privilege levels, architecture documentation and time with the engineers who built the system. We agree on everything before testing starts.

How do you handle our data?

We work under NDA, limit access to what the scope requires, avoid real customer data where possible, and delete test data at the end of the engagement per the agreed terms.

Can the audit be shared with our customers or regulators?

Yes. We can provide a summary suitable for external sharing, separate from the detailed technical findings.

Do you also fix what you find?

If you want us to. Because our engineers also build agents and guardrails, we can implement the fixes ourselves or support your team while they do.

Know your AI risk before someone else finds it

Send us a short description of your AI systems. We will respond with a proposed scope.

Request an audit