A poisoned model or a prompt injection exploit leaves different evidence from a typical breach, and the usual incident playbook doesn't say where to look. We know which logs, model artifacts and data pipelines to examine, and we work through them while the incident is still live.
Containment and investigation when a model is stolen, tampered with or quietly manipulated.
Find the poisoned training data that changed the model's behavior, remove it, and confirm the fix.
Response to deepfake-enabled fraud, executive impersonation and disinformation aimed at your organization.
Forensic analysis of models, prompts, logs and pipelines to establish what the attacker reached and, where the evidence allows, who they were.
Investigation of evasion attacks, prompt injection exploits and other attacks on model inputs.
Put the system back into service with the changes needed to stop the same attack working twice.
From the first call to the post-incident review.
Establish the scope and severity of the incident and what needs containing first.
Isolate the affected AI systems to stop further damage or data exposure.
Examine model artifacts, logs and model behavior to work out what happened.
Determine how far the compromise reached, including downstream systems that consume the model's output.
Remove the attacker's access, restore clean models and data, and make the first security fixes.
A written account of the incident, what it taught you, and what to change next.
Tell us what the model or application is doing and what it has access to. Our team is available 24/7.