Your shopping assistant talks to every customer. So does everyone else.
Skip Security audits customer-facing chatbots in e-commerce and retail. In three days we test whether your assistant can be talked into a discount it shouldn't give, a promise it can't keep, or a reply that embarrasses your brand. You get reproducible proof and a fix list — ideally before your peak season, not during it.
What's specific to retail
A Chevrolet dealership's chatbot was talked into "selling" a $76,000 SUV for one dollar, in writing. DPD's assistant swore at its own brand and the screenshots went viral. Retail assistants live in public, handle promotions and returns, and get screenshotted the second they slip. The risk here isn't a fine — it's your brand on X by lunchtime.
What we test on a retail assistant
- Talking it into unauthorized discounts, refunds, or price matches.
- Making it commit to delivery, stock, or returns it can't honour.
- Pushing it off-brand — insults, competitor promotion, off-topic content.
- Leaking order data or another customer's details.
- Prompt injection hidden in content the bot reads (a product page, a review, an email).
Timing (the useful part)
The worst time to discover your assistant can be manipulated is during your peak. We can run the audit before your code freeze, so the fixes ship while there's still time. If you want proof of what a live assistant sees, a 30-day mirror trial observes and alerts without touching your traffic.
How it runs (Day 0 → Day 3)
- Day 0
Day 0 — Scoping (30 min)
Scope, test environment, window. A one-page written authorization is signed. We only test what you authorize.
- Days 1–2
Days 1–2 — Testing
Systematic attacks, then manual exploitation. Every attempt is time-stamped and reproducible.
- Day 3
Day 3 — Report + live executive readout (45 min)
A written deliverable, plus a live session where we reproduce the key attacks in front of your digital and security teams. Not slides — your own assistant, broken in front of you.
The deliverable
- Executive summary — overall risk and three key findings in plain language.
- Proof — successful attacks, verbatim, time-stamped, reproducible.
- Severity — each finding scored by impact and ease of exploitation.
- Prioritized remediation — what to fix, in what order, and why.
Fixed fee, agreed before we start. No hourly billing, no surprise.
Neutral by design
We do not sell the AI model we assess. The provider of your AI can't be the judge of its own risk. A European company, built around EU hosting and controlled data residency.
FAQ
Our chatbot is a third-party SaaS (Zendesk, iAdvize…). Can you still audit it?
Yes — we test it as an attacker would, from the outside, through the same interface your customers use. The audit doesn't require touching the vendor's system.
What if the audit lands during Black Friday prep?
That's the point. We aim to finish before your freeze so the findings are actionable, not a January post-mortem.
Is this a pentest?
No. We target the assistant's behavior — what it can be talked into — not your servers.