Independent security assessment evidence
Penetration testing is a separate third-party assessment of the AI and application boundary. The September automated model evaluation does not renew that assessment. Consult the Trust Centre for the available report's date, scope, results and remediation status.
- External
- Assessment process
- Trust Centre
- Evidence access
Attack the boundary, not a demo.
Testing covers prompt injection, jailbreak attempts, cross-user data access, exfiltration paths and instruction extraction across the deployed application boundary.
Because detailed findings could help an attacker, the public record reports scope and status while controlled evidence is available through the October Trust Centre.
Accredited third-party provider · application and AI boundary · annual assessment
What the result says—and what it does not.
- The automated model rerun does not establish a new penetration-testing pass or validate the current gateway's security boundary.
- Testing is performed independently from the product team.
- Findings receive a named owner, severity, target date and closure evidence.
- Customers can request the available assurance material from the Trust Centre.
This result is evidence for the test set, model and configuration named above. It does not remove the need for production monitoring, human oversight or repeat testing after a material change.
A result is only useful while it stays current.
Security evidence should be useful without making the system easier to attack. Detailed reports are shared through controlled assurance channels.
