Where it fits
- Launching a customer-facing AI assistant that can read private account data.
- Adding AI agent actions such as ticket creation, refunds, code changes, email drafts, or database queries.
- Preparing a security review for a buyer, compliance team, or enterprise procurement process.
Operational steps
- Inventory models, prompts, tools, data sources, logs, and user roles.
- Test adversarial conversations across direct input, retrieved content, tool output, and uploaded files.
- Classify failures by impact: disclosure, policy bypass, account action, unsafe recommendation, or availability.
- Create a remediation plan with owners, retest date, severity, and acceptance criteria.
Common risks
- The app logs sensitive customer prompts without a retention policy.
- The model reveals hidden instructions or environment hints during a support conversation.
- An agent treats untrusted web content as a trusted developer instruction.
How PromptGuard Scan fits the workflow
PromptGuard Scan turns audit criteria into executable checks and exportable evidence, so teams can move from checklist review to repeatable security testing.