KRITERA / CASES

LLM customer assistant security assessment for a private bank

Prompt injection, PII leakage, jailbreak and RAG boundaries required validation before production.

Approach

A scope, threat model, manual validation, remediation and retest chain was applied.

Scope

  • Architecture and data flow
  • Identity and authorization
  • Manual security testing

Outputs

  • Executive summary
  • Technical evidence set
  • Remediation and retest plan

Outcome

The organization could manage technical risks and governance decisions in one closure plan.