SaaS, AI & Product
5 min read
By UnlockLive IT engineering team
Illustration comparing web app penetration testing with LLM red teaming attack types

If your product uses a large language model, "we had a penetration test" no longer settles the security question. A conventional web app pen test checks the login, the API and the database. It does not check what happens when a user, or a document the model reads, tells your AI to ignore its instructions and call a tool it should not.

That second kind of testing is called LLM red teaming. This guide explains what each test covers, how they overlap, what each typically costs, and how to decide whether you need one or both.

The short answer

Web app penetration testLLM red teaming
Question it answersCan an attacker break into the application or its data?Can an attacker manipulate the AI into doing something harmful?
Typical focusAuthentication, access control, injection, configuration, aligned with the OWASP Top 10Prompt injection, jailbreaks, data leakage, tool misuse, retrieval poisoning
Needed whenYou run any web application or API with user dataYour product lets an LLM read private data, take actions or talk to customers
Typical range we quote$12,000 to $30,000, depending on application complexity$15,000 to $40,000

These are the indicative ranges published on our cybersecurity services page. Final pricing depends on scope, and every engagement starts with agreeing what is in and out of bounds.

What a web application pen test covers

A web app pen test is an authorised attempt to break into your running application, using black-box, grey-box or white-box approaches depending on how much access the testers are given. Typical coverage maps to the OWASP Top 10: broken access control, injection, authentication failures, insecure configuration, vulnerable components and similar issues.

It answers questions such as: can one customer read another's data, can a normal user reach admin functions, can input break out of its intended use, and are secrets or debug interfaces exposed? The result is a written report with proven findings, severity and remediation advice, and it should include a re-test after you fix what was found.

If you are earlier in your journey and want to understand which review fits, see our comparison of technical audits, penetration tests and code reviews.

What LLM red teaming covers

LLM red teaming treats the model, and everything wired to it, as the target. The main attack types are:

  • Direct prompt injection: a user writes instructions that try to override your system prompt ("ignore your previous instructions").
  • Indirect prompt injection: hostile instructions hidden in a web page, document, email or tool result that the model reads on a user's behalf.
  • Jailbreaks: getting the model past its safety and policy limits.
  • Data extraction: making the model reveal its prompt, other users' data or content it was trained on or retrieves.
  • Model denial of service: prompts designed to consume excessive compute or cost.
  • Retrieval poisoning: planting content in the documents your retrieval system (RAG) searches so the model repeats or acts on it.
  • Agent tool misuse: persuading an agent to call a powerful tool, such as sending email, issuing refunds or deleting records, with attacker-controlled inputs.
  • Scope escalation through MCP servers and plugins: using a connected tool to reach data or actions the user should not have.
  • Supply-chain risks: malicious third-party prompts, models or tools.

The report shows which of these work against your product, how an attacker would chain them and what to change. Many production AI products expose several of these at the same time, often because each feature was reasonable on its own.

Where the two overlap

The overlap is bigger than it looks. Once an AI agent can call tools, a prompt injection becomes an access control problem: the model is a new, easily persuaded user inside your system. If it can read a customer's records or trigger a payment, then everything a web pen test checks about permissions now also applies to what the model is allowed to do.

It also works the other way. Model output is untrusted text. If your interface renders it without care, a classic web vulnerability such as cross-site scripting can arrive through the model. A good red team will include conventional checks along these paths.

Do you need one or both?

  • A normal web app with no AI features: a web app pen test, once the basics are fixed.
  • A chatbot that only answers from public content: lower risk, but test prompt leakage, abuse and cost limits, and check the web layer too.
  • An assistant with access to private or customer data: both. Data exposure through the model is the most expensive failure to explain.
  • An agent that takes actions through tools or MCP servers: both, with the tool permissions as a central focus.
  • A retrieval (RAG) product over many sources: both, plus attention to who can add documents to the index.

When budget is tight, start by listing three things: what data the model can see, what actions it can take and who can talk to it. The more of each, the more urgent the testing.

Reduce the risk before you test

Prompt injection cannot be fully eliminated today, so good design assumes the model will sometimes be fooled and limits the damage:

  1. Give tools the least privilege possible and scope them per user, never with one powerful shared key.
  2. Require human confirmation for destructive or high-value actions.
  3. Treat model output as untrusted and validate or encode it before it reaches an interface, a database or another system.
  4. Keep instructions and untrusted content separate where your architecture allows it, and avoid putting secrets in prompts.
  5. Log tool calls and set rate and spend limits so abuse is visible and bounded.

Building these in from the start is much cheaper than retrofitting them after a finding. It is the approach we take when we build AI agents and MCP servers.

What to expect from an engagement

A credible provider will agree scope and rules of engagement up front, test only what you authorise, and deliver a written report written for both engineers and decision makers. Fixes should be followed by a re-test so you can show they work. Be wary of anyone who promises that your AI product will be "fully secure"; the honest outcome is a clearer picture, fewer exploitable paths and evidence you can share with customers.

For AI-built apps that are heading towards launch, the order we usually suggest is a technical audit, then fixes, then formal testing. Our production readiness checklist is a good place to start.

Frequently asked questions

What does LLM red teaming test?

It tests direct and indirect prompt injection, jailbreak resistance, data extraction, model denial of service, retrieval (RAG) poisoning, agent tool misuse, MCP server scope escalation and supply-chain risks from third-party prompts, models and tools.

How much does LLM red teaming cost?

Our published indicative range is $15,000 to $40,000, while a focused web app penetration test typically ranges from $12,000 to $30,000. The final price depends on scope: how many models, tools, data sources and user roles are in play.

Is a web app penetration test enough for an AI product?

Usually not on its own. A web app pen test covers conventional weaknesses such as access control and injection, but not model-specific attacks such as prompt injection or tool misuse. Products where the AI reads private data or takes actions normally need both.

Can prompt injection be fixed completely?

Not with today's technology. Good design assumes the model will sometimes be fooled and limits the damage through least-privilege tools, human confirmation for risky actions, validation of model output and logging with rate and spend limits.

How we can help

  • Cybersecurity & AI Security ServicesPenetration testing, SOC monitoring, SOC 2 / ISO 27001 / PCI DSS / HIPAA readiness, and emerging-area work in LLM red teaming and AI agent security.
  • AI Agent DevelopmentProduction AI agents with LangChain, OpenAI Agents SDK, and Claude. RAG, tool use, multi-agent orchestration, voice, and browser-using agents.
  • MCP Server Development ServicesCustom Model Context Protocol (MCP) servers that expose your APIs, databases, and internal tools to Claude, Cursor, ChatGPT, and any MCP-compatible AI.

Talk to an engineer about your project

Tell us what you are building. We reply within one business day with a candid view on scope, approach and effort.

Book a free strategy call

Written by the UnlockLive IT engineering team. UnlockLive IT Limited works with clients through its Toronto headquarters and delivers engineering from its Dhaka delivery centre. About us

Related articles

SaaS, AI & ProductHow Small and Mid-Sized Businesses Can Get Started with AISaaS, AI & ProductHow We Helped a US SaaS Founder Launch an MVP in 60 DaysSaaS, AI & ProductCustom Website or ThemeForest Template: Which is Better for Your Restaurant Website?

Contact Us

Fill out the form below and our team will get back to you shortly to assist with your inquiry.