AI security services
We test your LLM applications, RAG pipelines and AI agents from an attacker's perspective, and train your teams to use these systems safely. Findings come with technical remediation steps and a management summary.
- Reporting
- OWASP LLM Top 10, MITRE ATLAS, KVKK
- First step
- 30-minute scoping call
- Proposal
- Scope, timeline and price in writing
- Confidentiality
- NDA on request
LLM penetration testing and AI red teaming
Before your AI systems go live, we identify the risks of prompt injection, data leakage and unauthorised tool use.
Prompt injection and jailbreak
We test whether your safety filters can be bypassed and whether system instructions can be extracted.
AI agents and tool use
We check each tool permission to see whether the agent can be manipulated into unauthorised actions.
RAG and vector databases
We try context poisoning and the extraction of sensitive data from your knowledge base.
Enterprise AI red teaming
We run scenarios that combine several attack vectors and follow the path a real attacker would take.
- You receive
- Proof-of-concept prompts, risk scores, a remediation roadmap and a retest
- For
- Organisations that have deployed AI systems and agents, or are about to
- Framework mapping
- OWASP LLM01–LLM10, MITRE ATLAS, KVKK Article 12, EU AI Act
AI security consulting
Security requirements for the architecture, policies and day-to-day operation of your AI systems.
Architecture and access
Review data flows, RAG sources, agent permissions and trust boundaries against OWASP LLM Top 10 and MITRE ATLAS.
Controls and priorities
Identify controls for sensitive data, model outputs and tool use; prioritise the work together with your technical teams.
Secure AI use training
A training programme on privacy, corporate data and KVKK for employees who use tools such as ChatGPT, Claude and Copilot.
Data privacy risks
Working habits that keep sensitive data away from model providers and their training data.
Secure prompting
Designing inputs safely and masking data before you share it.
KVKK and copyright
The legal responsibilities attached to AI output and the risks they create for your organisation.
Technical support
You can support the training with Guardian Edge, which masks personal data at the browser layer.
- You receive
- An AI security handbook for your organisation, a live training session, a certificate of participation
- For
- All teams that use AI in their daily work
- Basis
- KVKK recommendations on generative AI
Phishing awareness training
Training to recognise phishing attempts by email, SMS, voice call and social media. It includes deepfake voice and video examples.
Phishing tactics
How to recognise manipulative emails and fake domains.
Mobile and SMS phishing
How to spot harmful links sent to mobile devices.
Deepfakes and voice phishing
How to notice requests made with fake voice and video.
- You receive
- Live training and a phishing analysis workshop
- For
- All corporate teams exposed to phishing attempts
Cybersecurity awareness basics
Password hygiene, multi-factor authentication, secure remote work and the basics of social engineering, for all employees.
Passwords and multi-factor authentication
Strong password policies and why a second verification step matters.
Secure remote work
Rules for connecting safely from home or from shared networks.
Social engineering
How to recognise manipulation attempts in everyday work.
- You receive
- A basic cybersecurity exam, a certificate of participation and a results report by department
- Curriculum
- Prepared with ISO/IEC 27001 awareness controls and KVKK in mind
LLM Security Bootcamp
A hands-on, intensive LLM security programme for your security and software teams. It runs as an open cohort or as a closed group for your organisation.
Relevant regulations
AI components belong in your organisation's risk assessment. We take the following regulations into account and link each finding to the relevant provisions.
Cybersecurity Law No. 7545
Organisations within its scope may face testing, documentation and audit obligations. AI components should be part of the inventory and the risk assessment.
KVKK and generative AI
Personal data in prompts, logs, RAG and fine-tuning flows needs technical and administrative safeguards under KVKK, Türkiye's personal data protection law.
EU AI Act
High-risk systems that reach the EU market bring requirements for risk management, record-keeping and technical documentation.
For the core concepts, see the AI security guide. For the regulatory detail, read Cybersecurity Law No. 7545 and AI systems and KVKK and personal data in LLM systems.
How we work
Every step, from the first call to the report, has a defined output.
-
Scoping call
In 30 minutes, we define the systems, integrations, data flows and priorities with you.
-
Proposal
Scope, timeline, assumptions and price in a single written proposal, with a one-page summary for your management.
-
Testing
If we find a critical vulnerability, we tell your team right away instead of waiting for the report.
-
Report and retest
An executive summary, technical detail and a prioritised roadmap. We retest once you have applied the fixes.
Frameworks we use
- OWASP LLM Top 10
- MITRE ATLAS
- OWASP Web Security Testing Guide
- PTES
- NIST AI RMF
- KVKK
Frequently asked questions
How is the scope and cost of an AI security assessment determined?
The scope depends on the number of applications, model and agent architecture, integrations, data sensitivity, and testing depth. AltaySec begins with a scoping consultation and provides a clear timeline, deliverables, and price before testing starts.
We have our own internal security team, why AltaySec?
Internal teams have blind spots when testing their own systems; an independent red team sees what an attacker sees. Furthermore, most classic teams lack the specific expertise to test the LLM/AI attack surface, which is where we step in.
When should an organisation perform AI security testing?
Testing is most useful before deployment, after major model or integration changes, and at scheduled intervals for production systems. This allows teams to address findings before they become incidents or procurement blockers.
Let's define the scope before your next AI release
We will listen to your architecture, map the relevant attack surface, and help you decide whether to start with testing, protection or training.