Provok Book a scoping call
Questions

The questions
you're asking.

Offensive testing raises fair concerns, especially the first time. Here are straight answers to the ones we hear most.

Is this legal?

Yes. Every engagement runs under a signed authorisation and clear rules of engagement. We do not touch a system without written scope. Testing a system without authorisation is a criminal offence, and the signed authorisation is exactly what makes the work we do lawful.

Will you break my system?

Our aim is to find weaknesses, not cause damage. We test in your staging environment by default, you keep current backups, and either side can stop testing instantly. Production is only ever touched with your explicit written sign-off and a contact on call throughout.

Do you need access to production?

No, not by default. Staging is enough for most engagements. If testing production genuinely adds value, it is a separate, explicit authorisation with its own safeguards, never assumed.

What do you need from us?

A staging endpoint for the system in scope, scoped credentials on a least-privilege basis, a point of contact for the test window, and a signed engagement pack. That is usually the whole list.

How long does it take?

Days, not weeks. Fixed scope means a defined window. A Range Probe is a few days, a larger assessment a little longer. You get the report shortly after testing closes.

Where does my data go?

Nowhere offshore. Testing runs on Australian infrastructure, evidence is stored and destroyed in Australia, and the model reasoning stays onshore. Nothing leaves the country.

Are you insured?

Yes. We hold professional indemnity and cyber liability insurance covering offensive security testing. A certificate of currency is available on request.

What do we actually get at the end?

A findings report: every issue severity-rated and evidence-backed, mapped to the OWASP LLM Top 10 and the framework you answer to, with clear remediation direction and a retest once you have fixed things. You can view an illustrative sample.

Do you fix the issues you find?

We identify and document, your team remediates. We give direction your engineers can act on, and we stay independent of the fix on any system we test, so our result stays honest.

How is this different from a normal pen test?

A network or application pen test checks infrastructure and code. We test the AI layer itself, what the model can be talked into, tricked into leaking, or manipulated into doing through its tools. Different attack surface, different techniques.

Still have a question? Book a scoping call →