Skip to content

Ongoing managed security

Managed AI app security & pen testing

Managed AI app security is an ongoing arrangement for businesses running AI built applications that keep changing after release. The scope can include recurring code review, runtime testing, monitoring and remediation, with the cadence and response path written into the proposal. Veracode found that models introduced known security flaws in 45% of tested generation tasks. If you need a point in time review before committing to ongoing work, start with a one off audit.

Best fit
Production AI applications that keep changing
Main deliverable
Recurring findings, remediation and an evidence trail
Client input
Repository, test environment and application owner
Commercial model
A managed scope with cadence and response terms
Delivery ownership
  1. Scope
  2. Deliver
  3. Review
  4. Handover

The accountable team stays involved from scope through handover. Specialist capability is added where the work needs it, with responsibilities agreed before work starts.

The risk

AI apps ship with real vulnerabilities

Veracode found that models introduced known security flaws in 45% of tested generation tasks. That is why one release review is not enough for a production application that keeps changing.

Our review of AI cyber attacks in Australia and the 2026 evidence explains how attackers are using AI and where the published figures stop. Based in Perth and working nationally, our security work aligns with the Australian Cyber Security Centre's Essential Eight framework and the Australian Privacy Act.

Representative output

What the evidence trail looks like

A managed arrangement needs a usable record of what was reviewed, what was found and what happened next. The evidence trail is written for the application owner as well as the security practitioner.

The final record follows the scope agreed for the application. Findings, remediation, retesting and response terms appear only when they are part of that scope.

Scope

What recurring AI app security covers

The managed scope combines static analysis, manual review and runtime testing at the cadence agreed for the application. Every finding is ranked by severity and documented in plain English.

Identity and access

Check who and what can reach the application, its endpoints and its credentials.
  • Exposed credentials and API keys

    Detect hardcoded secrets in frontend code, environment files and public repositories.
  • Authentication and authorisation

    Review access controls, session management, token security and permission logic.
  • API security and CORS

    Audit endpoints, CORS policies, rate limiting and request validation.

Input and AI attack surface

Test how the application handles hostile input, model instructions and expensive requests.
  • Input validation and injection

    Test for SQL injection, XSS, CSRF and other injection vectors in every input.
  • Prompt injection

    Test AI powered features for prompt injection and model manipulation attacks.
  • AI API key exposure

    Detect model API keys in client code and data leakage to AI providers.

Data and runtime

Review sensitive data handling and the environment the application depends on.
  • Data handling and encryption

    Review encryption in transit and at rest, plus PII handling and storage.
  • Dependency vulnerabilities

    Scan packages and dependencies for known CVEs and outdated libraries.
  • Environment configuration

    Review server configuration, file permissions, error handling and logging.
If this is the work in front of you, send us the context. We will tell you whether this service is the right starting point before anything is scoped.

Method

How the managed security cycle works

A one off audit establishes the starting point. Managed security adds an agreed review cadence, monitoring, patch management, retesting and an incident response path.
  1. Analyse

    Automated analysis

    We use static analysis, dependency scanning and automated vulnerability detection across the codebase.
  2. Review

    Manual code review

    Human review of auth flows, API endpoints, input handling and AI specific attack vectors. Scanners miss context.
  3. Test

    Runtime testing

    Test authentication flows, injection vectors, CORS, sessions and prompt injection in a running environment.
  4. Remediate

    Remediate and set the next review

    We report findings by severity, complete or quote the agreed remediation, retest the changes and record the next review against the agreed cadence.

Pricing

How we scope and quote

Fixed scope before work starts. A free readiness assessment reviews the public, unauthenticated launch and security signals. Full penetration testing and any managed security arrangement are quoted to application size, integrations and risk. You know the cost before we begin.

Free readiness assessment

Public, unauthenticated launch and security signals reviewed.

Fixed audit price

The full test scope is agreed before work.

Plain English report

Prioritised findings instead of a two hundred page jargon document.

Recurring assurance

Review cadence, monitoring and response terms agreed for the application.
The proposal states the test environment, cadence, monitoring, remediation, retest and response boundaries. A full penetration test is included only when it is expressly scoped.

Practical details

Questions about AI Security

Commercial terms, delivery, ownership and fit, answered before a proposal is written.

Veracode's 2025 research found that models introduced known security flaws in 45% of tested generation tasks. Common issues include hardcoded credentials, missing authentication, injection vulnerabilities and insecure API configurations. Generated code still needs human review and testing before production.

Managed security

Define the security scope before the next release

The cadence, test scope, remediation and response path are agreed in writing.Enquiries get a reply within one business day.