RAG Pen Testing & VAPT
Pen testing for Retrieval-Augmented Generation pipelines, vector stores, and indirect prompt injection
Continuous AI pen testing for RAG pipelines — vector store authorisation (Pinecone, Weaviate, Qdrant, Chroma, Milvus, pgvector), retrieval poisoning, cross-tenant document leakage, embedding attacks, filter injection, and compliance mapping for SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, and PCI DSS.
Four steps. One continuous pen testing loop.
RAG Pipeline Mapping
Map the full RAG pipeline — ingestion sources, document processors, chunking strategy, embedding model, vector store (Pinecone, Weaviate, Qdrant, Chroma, Milvus, pgvector), retrieval logic, re-ranking, and the final context assembly reaching the LLM.
Retrieval & Vector Store Testing
Pen test the vector store for authorisation bypass, cross-tenant leakage, filter injection, metadata manipulation, and side-channel attacks via similarity-score leakage. Validate retrieval filters hold under adversarial query inputs.
Indirect Prompt Injection via Retrieval
The dominant RAG risk — attacker-controlled content lives in the index as a legitimate document and reaches the model as context on retrieval. We test both ingestion-time and query-time payloads, with and without delimiter-based isolation.
Evidence & Remediation
Reports include concrete payloads, affected documents, remediation guidance for your specific vector-store and framework (LangChain, LlamaIndex, Haystack, custom), and compliance mapping for SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, and PCI DSS.
Key Features
Full RAG pipeline attack surface — ingestion, embedding, retrieval, context assembly
Vector Store Authorisation
Validate that vector-store ACLs, namespaces, or collection-level permissions actually enforce tenant isolation — not just the application-layer wrapper around them
Metadata Filter Injection
Test user-controlled metadata filters for operator smuggling, type confusion, and bypasses that escalate retrieval scope
Cross-Tenant Retrieval
Pen test every retrieval path in multi-tenant RAG for one tenant's documents reaching another tenant's context
Ingestion-Time Payload Injection
Submit documents containing indirect prompt-injection payloads through every ingestion channel — direct upload, shared library, crawled source, API ingestion
Query-Time Injection
Test retrieval queries for payloads that influence what gets returned — not just what the model does with the result
Embedding-Inversion Attacks
Validate whether stored embeddings can be used to reconstruct source text — a privacy concern for sensitive documents
Side-Channel via Similarity Scores
Test whether similarity-score responses leak information about documents the querying user is not authorised to see
Chunk Overlap / Context Smuggling
Attack the chunking strategy — overlapping chunks that smuggle payloads, oversized chunks that defeat delimiters, undersized chunks that fragment safety context
Delimiter / Trust-Label Bypass
Validate that delimiters separating retrieved content from system / user content hold under adversarial payloads that forge or escape the delimiter
Re-Ranker Manipulation
If a re-ranker is involved, test whether retrieved document ordering can be manipulated to surface poisoned chunks
Provenance & Source Trust
Validate that document provenance metadata (source, author, timestamp, signing) is enforced on retrieval and reaches the model so it can weight accordingly
GDPR / HIPAA Document Scope
For RAG indexes containing personal data, ePHI, or regulated data, validate that retrieval honours purpose limitation, subject-rights requests, and sector-specific access controls
Benefits
Why teams choose TigerStrike for their security needs
Vector-Store-Native Testing
Built for the specific vector stores in production use — Pinecone, Weaviate, Qdrant, Chroma, Milvus, Elasticsearch kNN, Postgres pgvector, Redis vector, Azure AI Search, and OpenSearch. Each has its own authorisation model, metadata filtering, and query semantics; we test the actual one you use.

Cross-Tenant Document Leakage
Multi-tenant RAG deployments routinely leak documents across tenants when metadata filters are implemented wrong at the application layer rather than the vector-store layer. We test every retrieval path for this specific class of bug — the single most common RAG security finding in 2026.

Retrieval Poisoning Resistance
If the attacker can influence what gets indexed — through a shared knowledge base, a user-upload path, an RSS source, a crawled web corpus, or a compromised upstream data feed — they can plant indirect prompt-injection payloads. We test ingestion controls, provenance signals, and whether poisoned documents can be surfaced on realistic queries.

Embedding Model Attacks
Validate the embedding path — embedding model provenance, adversarial-text robustness, embedding-inversion attacks that recover source text from stored vectors, and the specific failure modes of the embedding provider you're using.

Filter Injection & Metadata Attacks
Many RAG implementations expose user-controlled metadata filters. Filter injection, parameter smuggling, and operator confusion allow attackers to bypass tenant isolation or escalate retrieval scope. We test every filter surface for these specific bugs.

Context Window + Rendering Safety
Even if retrieval is clean, how the retrieved content is assembled into the LLM's context matters — delimiter choice, trust labelling, markdown rendering, downstream output handling. We test the whole chain from the chunk to the sampled completion.

Frequently Asked Questions
Ready to get started?
Start securing your applications today with TigerStrike's AI-powered penetration testing platform.
Book a Demo