RAG Security
Retrieval makes the assistant useful and turns your document store into an attack surface: poisoning, cross-tenant leakage and permission drift between the index and the source system.
Sound familiar?
- The index was built once with broad access and no permission mapping.
- Documents from one customer or department can surface for another.
- A poisoned document reaches the model as trusted context.
- Deleted or restricted source documents remain retrievable in the index.
What we do
Permission parity
Ensuring retrieval respects the same access rules as the source systems.
Tenant isolation testing
Systematic attempts to retrieve content across tenant and department boundaries.
Poisoning resistance
What happens when an attacker can place a document into the corpus.
Index lifecycle
Deletion, re-indexing and revocation that actually take effect.
Questions we get
We use a managed RAG service. Is it covered?
Yes. The managed service handles retrieval; permission parity and poisoning resistance are still yours.
Do you test embeddings themselves?
Where relevant — including retrieval manipulation through crafted content.
Tell us what's running in production.
We'll tell you what we'd check first — and what we wouldn't bother with.
Book a call