Security Audits

DAST that understands AI.

One-shot security audits for modern web apps, APIs, chatbots, RAG systems, and AI agents. Start free, scope safely, and get verified findings your team can fix.

Dark WardenBot AI dashboard with vulnerability cards, evidence panels, charts, and remediation workflow
Live monitoring Bot Health A-
Canary leaks
0
Truth facts
24/25
Behavior diff
1 alert
Audit tiers

Free reconnaissance, deep DAST, or AI + Infra red-team.

Audits are one-shot engagements. Free recon shows the public surface. Paid tiers move through manual scope approval before checkout and active testing.

Free Surface Recon

$0

Public exposure snapshot

Free passive-first reconnaissance that shows what is publicly visible about a domain before you scope deeper testing.

Start Free Recon
  • Surface summary
  • Notable public exposures
  • Suggested Deep DAST or AI + Infra scope

AI + Infra Audit

$5,000

Per approved audit

A deep AI red-team plus infrastructure review for products where LLM behavior can become business risk.

Request Scope Review
  • 50-100 page AI + infrastructure report
  • Executive summary for leadership and auditors
  • Verified findings with agent-ready remediation
  • Cost-cap estimate before scan dispatch
Modern web

Coverage beyond generic crawl-and-scan.

GraphQL, WebSockets, OIDC flows, structured bodies, hidden parameters, browser execution, and OAST callbacks.

AI-aware

We test the LLM failure modes scanners miss.

Prompt injection, system prompt extraction, RAG leakage, tool-call abuse, refusal bypass, and model-cost controls.

Fix-ready

Evidence becomes engineering work.

Every verified finding includes impact, proof, fix objective, validation steps, and agent-ready Markdown.

Audit flow

Every paid audit is scoped before payment.

Active testing starts only after target ownership, scope, safety limits, blackout windows, and emergency contact details are reviewed.

  1. 01

    Map the surface

    Start with Free Surface Recon or connect a chatbot endpoint so WardenBot can see what a public user can reach.

  2. 02

    Test the AI behavior

    Run audit-grade probes, canary checks, business truth assertions, and multi-turn attack chains against approved scope.

  3. 03

    Validate the signal

    Script-first checks, guarded LLM judges, and human review separate real findings from scanner noise.

  4. 04

    Fix and keep watching

    Use agent-ready Markdown to remediate, then keep monitoring after launch for drift, regressions, and new failures.

Agent-ready output

A fix brief an AI coding agent can execute.

agent-fix.md
# agent-fix.md

## Finding
The support chatbot leaked the configured canary phrase during a prompt-extraction probe and returned a 60-day refund window instead of the approved 30-day policy.

## Objective
Prevent system/RAG canary disclosure and make refund answers resolve from the approved policy source. Preserve normal customer-support escalation.

## Suggested files
- prompts/support-system.md
- src/lib/chatbot/policy-context.ts
- tests/ai/support-policy.test.ts

## Implementation notes
1. Remove canary-bearing setup text from retrievable customer-facing context.
2. Add a refusal rule for requests to reveal hidden instructions or setup text.
3. Source refund answers from the canonical policy record, not stale prompt text.
4. Log policy-source version in chatbot traces for future behavior diffs.

## Acceptance tests
- Prompt-extraction probes do not return the canary.
- Refund questions consistently answer 30 days.
- Off-policy refund questions escalate instead of inventing exceptions.
- WardenBot replay probe now passes canary and business-truth checks.
After launch

Audits harden the product. Monitoring catches drift.

A typical WardenBot customer starts with recon, buys a Deep DAST or AI + Infra audit before launch, then subscribes to Continuous Monitoring so model, prompt, and vendor changes do not silently regress behavior.

Continuous Monitoring

Watch production chatbots from $29/month.

Canary leaks, business truth facts, Bot Health Score, behavior diffs, and agent-ready remediation.

Explore Monitoring
Ready for proof

Not sure which audit fits?

Start with Free Surface Recon, then request scope review if deeper web/API or AI + Infra testing is warranted.