We test your AI agents against prompt injection.
One message can talk your agent into handing over customer data, approving a refund or firing an action it should never take. We spend a week trying every angle we know, by hand — before someone tries it for real.
Most agents fall for it in five minutes.
That's prompt injection: no code, no exploit, nothing a firewall would catch. Just a message that talks your agent into ignoring its own instructions.
To coax: to talk someone into something. Hence the name.
Three steps. One week. Two hours of your time.
We agree on the rules
A 30-minute call: what your agent is allowed to say, promise and do. That's the line we test against.
We run every injection we know
Twelve families of prompt injection, all by hand. A real person behind every attempt, not a scanner replaying a list.
You get a fix list, not a PDF
Every hole, what it could cost you, and the exact change to make. Your dev can ship it the same day.
Four things an injected message gets your agent to do.
If yours can look up an order, send an email or apply a discount, this is your list.
It hands over someone else's data
One well-worded message and your agent reads out another customer's name, email or order.
It gives away money
A discount, a refund, a promise in your name. Said out loud by your brand — good luck taking it back.
It calls a tool it should never call
Sends the email, cancels the order, writes to the database. Not because it was hacked. Because someone asked nicely.
It leaks its own system prompt
Your instructions, your rules, your internal pricing notes — copy-pasted to a stranger who just asked twice.
Built for teams without a security team.
We test what it does, not how it sounds
An agent can be perfectly polite while it empties your stock or leaks a customer. Politeness isn't the risk.
A human writes the injections, not a scanner
The three biggest prompt-injection breaches of the past year were all found by a person reading how a system behaved — not by a tool replaying a wordlist.
A report your dev can act on
Written in plain English, ordered by what it costs you. Every finding mapped to OWASP LLM01 — and to Article 15 of the EU AI Act, when your system falls under it.
European, and easy to reach
Same timezone, same rules, a real person on the other end. Not a form and a ticket number.
Copilot, GitHub Copilot and ChatGPT were all talked into leaking data. Yours isn't the exception — it's just less tested.
Microsoft 365 Copilot handed over internal data from a single email nobody ever opened — EchoLeak, CVE-2025-32711, CVSS 9.3.
GitHub Copilot Chat was walked out of private repositories — source code and AWS keys — through GitHub's own image proxy. CamoLeak, CVE-2025-59145, CVSS 9.6.
ChatGPT's Deep Research agent emptied a Gmail inbox to an attacker's URL server-side, with nothing rendered in the browser to notice — ShadowLeak.
All three are patched, and all three were built by teams with more security engineers than you have employees. Prompt injection has been number one on OWASP's Top 10 for LLM applications in every edition since 2023 — including the 2026 one.
One price. Agreed before we start.
No day rates, no retainer. A short call, a number, and that number is the number.
The audit
Start hereOne agent, attacked properly, start to finish. The usual starting point.
Keep it tested
Your agent changes every week. This keeps the line held after we leave.
The questions everyone asks us.
What is prompt injection, exactly?
A message that talks your agent into ignoring its own instructions. No code, no hacking — just words, in the right order, sent through the same box your customers type in. It has been number one on OWASP's Top 10 for LLM applications in every edition since 2023 — including the 2026 one.
Nobody here does security. Is that a problem?
No, and most of our clients are in exactly that spot. You bring the person who built the agent, we bring everything else. There's nothing to install and nothing to learn.
Will you break our live agent?
No. We talk to it like a customer would — no code, no exploits, nothing deleted. If yours can move real money or send real emails, we do it on a test account instead.
How much of our time does this take?
About two hours total: a 30-minute call to agree on the rules, a bit of setup, and a 45-minute debrief at the end. We do the rest on our side.
Ours only answers questions. Do we need this?
If it reads from a fixed page and can't do anything else, honestly no. The day it can look up an order, send an email or apply a discount, come back to us.
What do we actually get at the end?
A short document: every hole we found, what it would cost you if a customer found it first, and the exact change to make. Plus a call to walk your dev through it.
Who have you done this for?
We build and run our own AI products — a conversion agent and a sourcing copilot, both live, both taking instructions from text we don't control. Coaxal started as the way we attacked our own. We'd rather show you what it found there.
Can you sign an NDA?
Yes, before anything starts. We're an EU company, and what we find stays between us.
Your agent is talking to someone right now.
Let's find out what it would say yes to — before somebody else does it for free.
Book a call →