Prompt injection
Related service Cybersecurity
DEFINITION
Attack where user input overrides the LLM system prompt. Five categories: direct, indirect, RAG-poisoning, tool-abuse, exfiltration. OWASP LLM Top-1.
- Threat model→
A structured exercise that walks the system's actors, attack surface, risks, and controls. Day one of every DField project · before any code.
- Penetration test (pentest)→
Manual + tooled attack simulation that reveals what an attacker could achieve. We deliver findings as PRs in your repo, not an 80-page PDF.
- DevSecOps→
Security as a continuously-running CI step (SAST, DAST, SCA, IaC scan), not an annual project. Runs against every push; every sprint closes at least one security bug.
- MFA (Multi-factor auth)→
Two or more factors (TOTP, WebAuthn, biometric) beyond a password. Table-stakes in SaaS today · enterprise procurement disqualifies you without it.
- SOC 2→
A US audit framework for confidentiality, integrity, availability, and privacy controls. For SaaS, the Type II audit (6-12 months of observation) is the standard enterprise baseline.
- ISO 27001→
International standard for Information Security Management Systems (ISMS). Often preferred in Europe instead of or alongside SOC 2. 3-year certification cycle.
- 0130 Sep 2026Q3 2026 roundup: what shifted, what we shipped, what broke→
- 0229 Aug 2026Does your AI phone assistant have to tell callers it's AI? (EU, 2026)→
- 0328 Aug 2026AI Receptionist for Auto Shops: Never Miss a Booking Call (2026)→
- 0428 Aug 2026AI Receptionist for Clinics: End Missed Calls and No-Shows (2026)→
- 0527 Aug 2026AI Voice Receptionist for Business: Costs & Build vs Buy (2026)→
- 0601 Jul 2026Q2 2026 roundup: what shifted, what we shipped, what broke→
- 0702 Jun 2026AI agent pricing 2026: what an autonomous agent costs→
- 0802 Jun 2026H1 2026 in review: what changed for EU software teams→