---
title: "AI Red Team engagement: scope, deliverables, SLA"
description: "A fixed-scope AI red team engagement against your agent, its tools and its credentials. Mapped to OWASP LLM and agentic top tens, with the eval suite handed..."
source: "https://www.kensink.com/engagements/ai-red-team/"
canonical: "https://www.kensink.com/engagements/ai-red-team/"
---
SERVICE · AI RED TEAM · FIXED SCOPE

# Break the agent before someone else does.

Three weeks of adversarial testing against every surface your system reads, every tool it can call, and every credential it can reach. The report is not the product. The eval suite is, because it still runs when the model version changes.

Who it's for: Teams with an agent in production that has gained a tool able to spend money, write to production, or email a customer.

THE OFFER

Outcome

A suite that keeps it fixed not hours billed

Engagement

Fixed scope

Timeline

3 weeks

Investment

from $14,000 \+ optional care retainer

Handoff

Full source + eval suite

[Request this service →](https://www.kensink.com/contact) [Book a scoping call](https://www.kensink.com/contact)

IN SCOPE

## What the engagement covers.

-   ✓Prompt injection, direct and indirect, across every surface the system reads
-   ✓Tool misuse and privilege escalation through the tool set
-   ✓Excessive agency, now OWASP's third-ranked LLM risk
-   ✓Memory and context poisoning, and inter-agent message spoofing
-   ✓MCP tool poisoning and server auth review
-   ✓Secrets recoverable from prompts, logs or traces
-   ✓A retest thirty days after fixes ship

OUT OF SCOPE

## What we would quote separately.

-   –Application penetration testing
-   –Infrastructure, network or physical testing
-   –Social engineering
-   –Compliance certification
-   –Fixing the findings, unless you add Agent Containment

DELIVERABLES

## What lands at handoff.

-   ✓Every finding with a working reproduction, ranked by exploitability
-   ✓The regression eval suite, wired into CI with a ship gate
-   ✓A fix list with owners and effort estimates
-   ✓A retest at day thirty, included
-   ✓Full source and complete ownership of the suite

TIMELINE · 4 PHASES

## 3 weeks, problem to production.

1.  01
    
    Week 1
    
    ### Map and arm
    
    Inventory every surface, tool and credential. Build the attack library for your system, not a generic one.
    
2.  02
    
    Week 2
    
    ### Break it
    
    Run and mutate the library continuously, and hand-design the attacks the library does not contain.
    
3.  03
    
    Week 3
    
    ### Prove and gate
    
    Confirm every finding by hand, rank by exploitability, wire the suite into CI with a ship gate.
    
4.  04
    
    Day 30
    
    ### Retest
    
    Re-run the suite against your fixes and report what still fails. Included, not quoted separately.
    

SERVICE LEVELS

## The SLA this service runs under.

During the build and through the warranty window after handoff. This engagement defaults to Priority.

| Commitment | Standard | Priority |
| --- | --- | --- |
| First response | Next business day | Within 4 business hours |
| Critical issue triage | 1 business day | 2 hours |
| Production uptime target | 99.5% | 99.9% |
| Support hours | Mon to Fri, business hours | Extended, plus weekend on-call |
| Change requests / month | 2 included | Unlimited within retainer |
| Post-launch warranty | 30 days | 90 days |
| Named delivery lead | Shared | Dedicated |

ⓘ Standard ships with every fixed-scope build. Priority comes with a care retainer. Pricing is a starting range; final terms are set in the statement of work.

[Read the full AI Red Team capability page ↗](https://www.kensink.com/ai-security)

READY WHEN YOU ARE

## Bring one real problem.  
We'll bring the spec.

[Request this service →](https://www.kensink.com/contact) [All engagements](https://www.kensink.com/engagements)

[← All engagements](https://www.kensink.com/engagements) ENGAGEMENT · AI-RED-TEAM
