AI Security
& Consulting
Secure AI adoption for Australian organisations. AI is already in use across public chatbots, Microsoft Copilot, SaaS platforms, code assistants and internal automation - often without a clear view of where sensitive data is going. RTCS helps organisations assess, govern and secure their use of AI so it can be adopted safely without unnecessary blockers.
- AI risk assessments and AI security reviews
- LLM application security testing - prompt injection, jailbreak and abuse cases
- Microsoft Copilot security and governance review
- AI acceptable use policy and AI governance frameworks
- AI data leakage assessments across staff, SaaS and applications
- RAG pipeline, vector database, agent and plugin security review
- Third-party AI and SaaS vendor reviews
- Executive reporting, remediation roadmaps and staff guidance
AI is already in your environment. The risk is rarely obvious.
Sensitive information gets pasted into public AI tools. SaaS platforms turn AI features on without review. Developers ship AI-generated code without proper testing. Customer data is processed by third-party AI services. AI agents and LLM applications expose new attack paths through prompt injection, insecure plugins, weak access controls, data leakage and unsafe outputs. RTCS reviews how AI is being used, where sensitive data may be exposed, how AI systems are integrated, and what controls are needed to reduce real risk.
Most organisations cannot say where AI is being used.
Staff use public AI tools to summarise documents, draft emails, review source code and analyse business information. Business units enable AI features inside SaaS platforms without formal approval. RTCS assesses current and planned AI use across your organisation and identifies practical security, privacy and compliance risks.
What we review
LLM applications need to be tested differently.
Chatbots, copilots, agents and RAG pipelines are exposed to risks like prompt injection, insecure output handling, excessive agency, system prompt leakage, sensitive information disclosure, weak plugin design and unsafe access to tools or data sources. RTCS tests AI and LLM-powered applications to identify how they can be misused, bypassed or manipulated.
Prompt Injection
Direct and indirect prompt injection, jailbreak and instruction override testing across user inputs, documents, retrieved context and tool outputs.
Data Exposure
Sensitive data exposure testing, system prompt leakage, model memory abuse and information disclosure through outputs, errors and side channels.
Output Handling
Insecure output handling review - rendered HTML, markdown, code execution paths, downstream tool calls and unsafe action chains.
RAG & Vector Stores
RAG pipeline and vector database security testing - poisoning, retrieval scoping, document permissions and tenant isolation.
Agents & Tools
Agent tool abuse testing, plugin and integration review, excessive agency, action scoping and unsafe tool composition.
Access & APIs
Access control testing, API security review, logging and monitoring review, abuse case testing and rate-limit/cost-abuse paths.
Data leakage is the most common AI risk.
It happens when staff enter sensitive information into public AI tools, when SaaS AI features process business data without controls, or when an internal AI application returns information it shouldn't. We assess how information flows into and out of AI systems - prompts, outputs, logs, documents, uploaded files, embeddings, integrations and vendor platforms - to identify whether sensitive data may be exposed, retained, reused, indexed or accessed externally.
AI security is not only a technical problem.
Organisations need clear rules for how AI can be used, who can approve tools, what data can be entered, and how AI-generated outputs should be checked. RTCS helps create practical AI governance that staff can understand and follow - and that supports safe AI adoption without creating unnecessary blockers.
Acceptable Use Policy
A practical AI AUP that explains what staff can use, what data must not be entered, how outputs should be reviewed and how new AI tools are assessed.
Approved Tools Register
A maintained register of approved AI tools, owners, data classifications and conditions of use - mapped to your risk appetite.
AI Risk Process
A lightweight AI risk assessment process and vendor checklist that fits inside your existing change, procurement and security workflows.
Human Review
Human review requirements, data handling rules, prompt and output guidance for staff, and reporting and escalation processes.
Copilot makes existing access problems visible.
If access to files, emails, Teams chats, SharePoint sites or internal records is already too broad, Microsoft Copilot and other SaaS AI features make that problem easier to exploit. We review the security and governance settings that affect AI-enabled platforms.
Vendor Review
Data & Training
Data processing and retention, model training and data reuse, use of subprocessors and where data is stored or processed.
Security Controls
Access controls, encryption, administrative controls, logging and auditability, security certifications and incident response.
Contracts & Assurance
Privacy documentation, contractual and assurance gaps, framework alignment and obligations under Australian privacy expectations.
Integration Risk
Integration risks, API surface, permission scopes and what data the product reads from and writes to your environment.
Mapped to the guidance that matters - without the paperwork.
We use these frameworks to support practical decision making, not to create unnecessary paperwork.
The recurring AI security issues we see.
Staff entering sensitive data into public AI tools
AI tools being used without approval
SaaS AI features enabled without security review
Over-permissive access to internal documents
AI-generated code used without secure review
Customer data processed by third-party AI services
AI outputs treated as accurate without verification
Weak controls over AI agents and plugins
Insecure RAG pipelines and vector databases
Poor logging of AI-assisted actions
No clear accountability for AI decisions
Lack of staff guidance on safe AI use
Discover to Improve
A practical, staged engagement that meets your organisation wherever it is in AI adoption - from informal staff use through to production AI applications.
Identify how AI is currently being used - approved tools, informal use, SaaS features, internal systems and planned AI projects.
Review security, privacy and governance risks - data handling, access control, vendor risk, application security and operational impact.
Test in-scope AI applications for prompt injection, data leakage, insecure plugins, unsafe outputs and weak access controls.
Separate urgent risks from lower-risk items with a clear roadmap your technical, security, risk and leadership teams can act on.
Implement practical controls, policies, review processes and staff guidance so AI can be used safely and consistently.
Who It's For
Who This Service Is For
- Use ChatGPT, Copilot, Gemini or other AI tools
- Planning to approve AI use across the business
- Need an AI acceptable use policy
- Want to reduce staff sharing sensitive data with AI
- Building AI-enabled apps or customer-facing chatbots
- Use RAG pipelines, AI agents or LLM integrations
- Need to review AI vendors or SaaS AI features
- Want clear governance before scaling AI adoption
- Need practical advice for executives, risk & tech teams
What You Receive
- AI risk assessment report
- Risk-rated findings
- Evidence-based technical observations
- AI usage and governance recommendations
- AI acceptable use policy
- Approved AI tools register
- AI vendor review checklist
- Secure AI adoption roadmap
- Executive risk summary
- Remediation guidance & follow-up
AI can improve productivity, but only when the risks are understood and controlled. Talk to us about an AI security review, AI risk assessment, LLM application test or AI governance engagement.
Common Questions
What is AI security?
AI security is the process of identifying and managing the risks created by AI tools, AI-enabled applications and AI-assisted business processes. It includes technical testing, data protection, access control, vendor review, governance, policy and staff awareness.
Do we need AI security if we only use public AI tools?
Yes. Public AI tools can still create risk if staff enter customer information, employee records, source code, credentials, financial data, legal material or confidential business documents. The main risk is often data leakage rather than the AI tool itself.
Do we need testing if we are building an AI chatbot?
Yes. AI chatbots and LLM applications should be tested for prompt injection, data exposure, insecure outputs, access control issues, abuse cases and integration risks. This is especially important if the chatbot can access internal data, customer records, business systems, plugins or APIs.
Can you review Microsoft Copilot readiness?
Yes. We can review Microsoft 365 security and governance controls that affect Copilot readiness, including permissions, SharePoint and Teams access, sensitivity labels, external sharing, audit logging, data loss prevention and identity controls.
Can you write our AI policy?
Yes. We can create a practical AI acceptable use policy that explains what staff can use, what data must not be entered, which tools are approved, how outputs should be reviewed, and how new AI tools should be assessed before use.
What frameworks do you use?
We can align work to the OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001 and MITRE ATLAS where relevant. We also consider Australian privacy and cyber security expectations when reviewing AI use cases.
Available across Australia.
RTCS supports AI security and consulting for Australian organisations adopting LLMs, Copilot and AI-enabled products. See cyber security services across Australia for national delivery context.
Not sure what you need?
Use the enquiry form or email [email protected] with a brief summary. Include your organisation, the service area if known, and any timing requirements.