Your banking assistant answers customers. Can it be made to answer an attacker?
Skip Security audits customer-facing chatbots in banking and insurance. In three days we test whether your assistant can be pushed into unauthorized commitments, made to reveal internal instructions, or leak another customer's data. You get reproducible proof and a remediation plan you can put in front of your risk committee. DORA has been in force since January 2025; testing the systems that talk to your customers is part of it.
What's specific to finance
A chatbot that quotes a rate, confirms a transfer, or explains a contract isn't a marketing widget — it speaks in your name. When Air Canada's bot invented a refund, the airline paid. Replace "refund" with "rate", "waiver", or "coverage confirmation" and you have the finance version. Your assistant makes commitments; an attacker will try to choose them.
What we test on a finance assistant
- Getting it to promise a rate, fee waiver, or coverage it shouldn't.
- Extracting the system prompt — internal rules, pricing logic, escalation paths.
- Leaking personal or account data across users, or from retrieved documents.
- Bypassing KYC/eligibility wording to reach restricted answers.
- Turning it into free compute billed to you.
The regulatory hook (honest framing)
DORA asks you to test and document the resilience of the ICT systems that serve your clients. A customer-facing assistant is one of them. We don't sell you compliance — we give you reproducible evidence of what your assistant does under attack, in a form your risk and audit teams can use. Where it helps, we map findings to the relevant DORA articles. A lawyer should validate any regulatory claim before it leaves your building.
How it runs (Day 0 → Day 3)
- Day 0
Day 0 — Scoping (30 min)
Scope, test environment, window. A one-page written authorization is signed. We only test what you authorize.
- Days 1–2
Days 1–2 — Testing
Systematic attacks, then manual exploitation. Every attempt is time-stamped and reproducible.
- Day 3
Day 3 — Report + live executive readout (45 min)
A written deliverable, plus a live session where we reproduce the key attacks in front of your digital and security teams. Not slides — your own assistant, broken in front of you.
The deliverable
- Executive summary — overall risk and three key findings in plain language.
- Proof — successful attacks, verbatim, time-stamped, reproducible.
- Severity — each finding scored by impact and ease of exploitation.
- Prioritized remediation — what to fix, in what order, and why.
Fixed fee, agreed before we start. No hourly billing, no surprise.
Neutral by design
We do not sell the AI model we assess. The provider of your AI can't be the judge of its own risk. A European company, built around EU hosting and controlled data residency.
FAQ
Do you touch our production banking system?
No. Scoped test environment, signed authorization, nothing live without it.
Does this make us DORA-compliant?
No tool makes you compliant. We produce evidence you can use in your resilience testing and hand to your auditors.
We already have an annual pentest.
A pentest checks your infrastructure. It rarely tries to manipulate the assistant's behavior — the rate it quotes, the data it recalls. That's what we test.