RAG Security Assessment
RAG systems can leak sensitive data when retrieval, indexing, chunking, permissions, or tenant boundaries do not match the business model. SCS tests what the system retrieves and what it exposes.
RAG Security Assessment.
Secure Consulting Solutions (SCS) provides a RAG Security Assessment for retrieval-augmented generation systems that search, retrieve, cite, or summarize internal documents and knowledge bases.
The assessment validates whether retrieval filters, tenant boundaries, document permissions, citations, chunking, and indexing decisions expose sensitive data or allow document-driven manipulation.
Deliverables include retrieved-document evidence, sensitive category findings, tenant or role exposure context where applicable, remediation guidance, and retest plans.
Assessment summary
| Identity | Which roles, tenants, or personas can retrieve sensitive documents or generated answers. |
| Evidence | Prompts, assistant output, retrieved docs, citations, source paths, metadata, and canary matches. |
| Risk | Retrieval data leakage, document injection, tenant leakage, authorization failure, and source-path exposure. |
| Deliverable | Executive summary, technical report, findings CSV, retrieved-document evidence, remediation guidance, and retest plan. |
What this assessment answers
- Can one role or tenant retrieve another role or tenant's documents?
- Can poisoned documents alter answers, citations, or tool behavior?
- Do retrieval filters enforce authorization consistently?
- Does the model reveal sensitive chunks, metadata, or source paths?
- Can prompt injection inside retrieved content change system behavior?
What we test
- RAG data leakage
- Tenant leakage and cross-role retrieval
- Document injection and poisoning
- Retrieval manipulation
- Embedding and chunking edge cases
- Citation and source-path leakage
- Knowledge base access control
- Sensitive document exposure
Deliverables
- Findings report with reproduction steps
- Retrieved-document evidence
- Sensitive category findings
- Remediation guidance for retrieval and access controls
- Retest plan for fixed filters and indexes
SCS Approach
Operator-led, evidence-first assessment.
RAG findings are grounded in retrieved context and source evidence. Inventory context can explain likely causes, but SCS does not treat inventory alone as proof of exposure.
Common Buyer Questions
What is RAG security testing?
It is security testing for systems that retrieve documents or data before generating answers, with focus on retrieval behavior, source evidence, authorization, and data exposure.
Can you test tenant isolation?
Yes, when scoped identities, tenants, or representative test accounts are available. SCS compares retrieval and answer behavior across those boundaries.
Do you inspect citations and retrieved documents?
Yes. Findings capture retrieved context, citations, source paths, metadata, and answer output when those signals are available from the system or operator evidence.
Do you use canaries?
Where approved, canaries can help validate whether sensitive markers appear through retrieval or answers. SCS reports canary matches as evidence, not as a substitute for broader assessment.
Need evidence, not a generic scan?
SCS scopes AI security assessments around architecture, identities, data paths, evidence, remediation, and retest.