Solution

Audit retrieval systems before they expose the wrong data.

RAG security audits review indexing, retrieval permissions, source trust, prompt assembly, and output controls for exploitable paths. Monitoring adds recurring RAG canary checks after launch.

Coverage

Tenant boundaries, document permissions, poisoning, retrieval leakage, canary checks, and agent consumption.