Customer case study

Penfield: SOC 2 and AI agent security testing

How an AI process intelligence company tested agent guardrails, RAG ingestion, and traditional app/API surfaces in one engagement.

Penfield

SOC 2 Type II

AI process intelligence

The challenge

What the team needed to prove.

The assessment began with business context, exposed workflows, and the evidence stakeholders needed.

Penfield needed security proof for financial services buyers who asked about SOC 2, app security, and AI agent controls together.

The attack surface included customer workflows, API authorization, RAG ingestion, and agent tool boundaries.

The approach

Testing connected to the real operating surface.

Exploration, validation, and reporting stayed attached to the same approved scope.

DeepScan combined web/API pentesting with AI-specific scenarios including indirect prompt injection, retrieval leakage, and unsafe tool calls.

Human operators reviewed evidence quality and translated technical issues into buyer-readable risk language.

The result

Evidence ready for action and review.

Validated output gave engineering and assurance stakeholders a shared record.

Penfield received one report covering traditional and AI-native risks, reducing the need for separate vendor engagements.

The evidence helped answer financial services procurement questions with concrete proof rather than policy-only responses.

Explore pentesting services

Start with proof

Build your own defensible security story.

Start with an approved target and keep every step from test to retest connected.

Start a pentestExplore case studies