Ongoing managed security
Managed AI app security & pen testing
Managed AI app security is an ongoing arrangement for businesses running AI built applications that keep changing after release. The scope can include recurring code review, runtime testing, monitoring and remediation, with the cadence and response path written into the proposal. Veracode found that models introduced known security flaws in 45% of tested generation tasks. If you need a point in time review before committing to ongoing work, start with a one off audit.
- Best fit
- Production AI applications that keep changing
- Main deliverable
- Recurring findings, remediation and an evidence trail
- Client input
- Repository, test environment and application owner
- Commercial model
- A managed scope with cadence and response terms
- Scope
- Deliver
- Review
- Handover
The accountable team stays involved from scope through handover. Specialist capability is added where the work needs it, with responsibilities agreed before work starts.
The risk
AI apps ship with real vulnerabilities
Veracode found that models introduced known security flaws in 45% of tested generation tasks. That is why one release review is not enough for a production application that keeps changing.
Our review of AI cyber attacks in Australia and the 2026 evidence explains how attackers are using AI and where the published figures stop. Based in Perth and working nationally, our security work aligns with the Australian Cyber Security Centre's Essential Eight framework and the Australian Privacy Act.
Representative output
What the evidence trail looks like
A managed arrangement needs a usable record of what was reviewed, what was found and what happened next. The evidence trail is written for the application owner as well as the security practitioner.
The final record follows the scope agreed for the application. Findings, remediation, retesting and response terms appear only when they are part of that scope.
Scope
What recurring AI app security covers
Identity and access
- Detect hardcoded secrets in frontend code, environment files and public repositories.
Authentication and authorisation
Review access controls, session management, token security and permission logic.API security and CORS
Audit endpoints, CORS policies, rate limiting and request validation.
Input and AI attack surface
Input validation and injection
Test for SQL injection, XSS, CSRF and other injection vectors in every input.Prompt injection
Test AI powered features for prompt injection and model manipulation attacks.AI API key exposure
Detect model API keys in client code and data leakage to AI providers.
Data and runtime
Data handling and encryption
Review encryption in transit and at rest, plus PII handling and storage.Dependency vulnerabilities
Scan packages and dependencies for known CVEs and outdated libraries.Environment configuration
Review server configuration, file permissions, error handling and logging.
Method
How the managed security cycle works
Analyse
Automated analysis
We use static analysis, dependency scanning and automated vulnerability detection across the codebase.Review
Manual code review
Human review of auth flows, API endpoints, input handling and AI specific attack vectors. Scanners miss context.Test
Runtime testing
Test authentication flows, injection vectors, CORS, sessions and prompt injection in a running environment.Remediate
Remediate and set the next review
We report findings by severity, complete or quote the agreed remediation, retest the changes and record the next review against the agreed cadence.
Pricing
How we scope and quote
Fixed scope before work starts. A free readiness assessment reviews the public, unauthenticated launch and security signals. Full penetration testing and any managed security arrangement are quoted to application size, integrations and risk. You know the cost before we begin.
Free readiness assessment
Fixed audit price
Plain English report
Recurring assurance
Practical details
Questions about AI Security
Veracode's 2025 research found that models introduced known security flaws in 45% of tested generation tasks. Common issues include hardcoded credentials, missing authentication, injection vulnerabilities and insecure API configurations. Generated code still needs human review and testing before production.
Managed security