RAG VAPT

RAG Pen Testing & VAPT

Pen testing for Retrieval-Augmented Generation pipelines, vector stores, and indirect prompt injection

Continuous AI pen testing for RAG pipelines — vector store authorisation (Pinecone, Weaviate, Qdrant, Chroma, Milvus, pgvector), retrieval poisoning, cross-tenant document leakage, embedding attacks, filter injection, and compliance mapping for SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, and PCI DSS.

How It Works

Four steps. One continuous pen testing loop.

1

RAG Pipeline Mapping

Map the full RAG pipeline — ingestion sources, document processors, chunking strategy, embedding model, vector store (Pinecone, Weaviate, Qdrant, Chroma, Milvus, pgvector), retrieval logic, re-ranking, and the final context assembly reaching the LLM.

2

Retrieval & Vector Store Testing

Pen test the vector store for authorisation bypass, cross-tenant leakage, filter injection, metadata manipulation, and side-channel attacks via similarity-score leakage. Validate retrieval filters hold under adversarial query inputs.

3

Indirect Prompt Injection via Retrieval

The dominant RAG risk — attacker-controlled content lives in the index as a legitimate document and reaches the model as context on retrieval. We test both ingestion-time and query-time payloads, with and without delimiter-based isolation.

4

Evidence & Remediation

Reports include concrete payloads, affected documents, remediation guidance for your specific vector-store and framework (LangChain, LlamaIndex, Haystack, custom), and compliance mapping for SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, and PCI DSS.

Key Features

Full RAG pipeline attack surface — ingestion, embedding, retrieval, context assembly

Vector Store Authorisation

Validate that vector-store ACLs, namespaces, or collection-level permissions actually enforce tenant isolation — not just the application-layer wrapper around them

Metadata Filter Injection

Test user-controlled metadata filters for operator smuggling, type confusion, and bypasses that escalate retrieval scope

Cross-Tenant Retrieval

Pen test every retrieval path in multi-tenant RAG for one tenant's documents reaching another tenant's context

Ingestion-Time Payload Injection

Submit documents containing indirect prompt-injection payloads through every ingestion channel — direct upload, shared library, crawled source, API ingestion

Query-Time Injection

Test retrieval queries for payloads that influence what gets returned — not just what the model does with the result

Embedding-Inversion Attacks

Validate whether stored embeddings can be used to reconstruct source text — a privacy concern for sensitive documents

Side-Channel via Similarity Scores

Test whether similarity-score responses leak information about documents the querying user is not authorised to see

Chunk Overlap / Context Smuggling

Attack the chunking strategy — overlapping chunks that smuggle payloads, oversized chunks that defeat delimiters, undersized chunks that fragment safety context

Delimiter / Trust-Label Bypass

Validate that delimiters separating retrieved content from system / user content hold under adversarial payloads that forge or escape the delimiter

Re-Ranker Manipulation

If a re-ranker is involved, test whether retrieved document ordering can be manipulated to surface poisoned chunks

Provenance & Source Trust

Validate that document provenance metadata (source, author, timestamp, signing) is enforced on retrieval and reaches the model so it can weight accordingly

GDPR / HIPAA Document Scope

For RAG indexes containing personal data, ePHI, or regulated data, validate that retrieval honours purpose limitation, subject-rights requests, and sector-specific access controls

Benefits

Why teams choose TigerStrike for their security needs

Vector-Store-Native Testing

Built for the specific vector stores in production use — Pinecone, Weaviate, Qdrant, Chroma, Milvus, Elasticsearch kNN, Postgres pgvector, Redis vector, Azure AI Search, and OpenSearch. Each has its own authorisation model, metadata filtering, and query semantics; we test the actual one you use.

Vector-Store-Native Testing

Cross-Tenant Document Leakage

Multi-tenant RAG deployments routinely leak documents across tenants when metadata filters are implemented wrong at the application layer rather than the vector-store layer. We test every retrieval path for this specific class of bug — the single most common RAG security finding in 2026.

Cross-Tenant Document Leakage

Retrieval Poisoning Resistance

If the attacker can influence what gets indexed — through a shared knowledge base, a user-upload path, an RSS source, a crawled web corpus, or a compromised upstream data feed — they can plant indirect prompt-injection payloads. We test ingestion controls, provenance signals, and whether poisoned documents can be surfaced on realistic queries.

Retrieval Poisoning Resistance

Embedding Model Attacks

Validate the embedding path — embedding model provenance, adversarial-text robustness, embedding-inversion attacks that recover source text from stored vectors, and the specific failure modes of the embedding provider you're using.

Embedding Model Attacks

Filter Injection & Metadata Attacks

Many RAG implementations expose user-controlled metadata filters. Filter injection, parameter smuggling, and operator confusion allow attackers to bypass tenant isolation or escalate retrieval scope. We test every filter surface for these specific bugs.

Filter Injection & Metadata Attacks

Context Window + Rendering Safety

Even if retrieval is clean, how the retrieved content is assembled into the LLM's context matters — delimiter choice, trust labelling, markdown rendering, downstream output handling. We test the whole chain from the chunk to the sampled completion.

Context Window + Rendering Safety

Frequently Asked Questions

Ready to get started?

Start securing your applications today with TigerStrike's AI-powered penetration testing platform.

Book a Demo