October
Request a demo
All testingPublished Annual
Luna · Ash · Ivy

Independent Penetration Testing

Independent testing covering prompt injection, jailbreak attempts, data exfiltration and attempts to extract system instructions.

01 · Published resultAnnual control
PassedAnnual control
Current evaluation

Independent assessment completed

October commissions an accredited security provider to test the AI and application boundary. Detailed findings remain controlled security evidence and remediation is tracked to closure.

Passed
Current status
Annual
Assessment cycle
3
Agents in scope
100%
Findings tracked
02 · What this evaluatesDefined scope

Attack the boundary, not a demo.

Testing covers prompt injection, jailbreak attempts, cross-user data access, exfiltration paths and instruction extraction across the deployed application boundary.

Because detailed findings could help an attacker, the public record reports scope and status while controlled evidence is available through the October Trust Centre.

Prompt injectionJailbreakData exfiltrationSystem promptsAccess controls
Test parameters

Accredited third-party provider · application and AI boundary · annual assessment

03 · Assessment scopePublished dataset
CategoryCoverageCadenceOwnerEvidence
AI application boundary
Agents + APIsAnnualIndependent assessorTrust Centre
Remediation
All findingsTrackedSecurity ownerControlled
04 · InterpretationLimits included

What the result says—and what it does not.

  • Testing is performed independently from the product team.
  • Findings receive a named owner, severity, target date and closure evidence.
  • Customers can request the available assurance material from the Trust Centre.
Important limitation

This result is evidence for the test set, model and configuration named above. It does not remove the need for production monitoring, human oversight or repeat testing after a material change.

05 · Ongoing controlChange-triggered retesting

A result is only useful while it stays current.

Security evidence should be useful without making the system easier to attack. Detailed reports are shared through controlled assurance channels.

Next step

Responsible AI is a continuous practice.

Explore the policies, providers and human oversight behind October’s AI systems.