Module 1
Module 2
Module 3
Module 4
Module 5

We test your entire operation. Including your AI.

GenIA Safe tests applications, APIs, mobile, code and infrastructure. And it tests the AI layer in production, which is where almost no one knows how to look. You get reproducible evidence, risk ranked by severity and a remediation plan with deadlines.

The AI layer is tested by people who build AI every day.

Discuss scope

A scoping conversation, no commitment.

How GenIA Safe tests your operation

How GenIA Safe tests your operation.

01

SCOPE

We define the assets, the environments, the execution window and the rules of engagement together with you. Nothing starts before that is agreed in writing.

02

EXECUTION

We test applications, APIs, mobile, code, infrastructure and the AI layer, in black box, white box or gray box mode.

03

PRIORITIZATION

Every confirmed finding enters the risk matrix with its severity, reproduction evidence, business impact and remediation deadline. The result is presented to leadership and to engineering, each in the language they decide in.

Carlos Augusto Verified
Founder of Grupo GenIA
Carlos Augusto

“Testing an AI in production is not the same as testing an application. You need to know how the model was connected, what it can reach, how it responds when someone keeps pushing, and what changes when the provider ships a new version. The people who know how to test that are the people who build it every day. That is where GenIA comes from.”

Case studies in documentation.

We work under non disclosure agreements. A client name appears on this page with written authorization, and not before.

What we test in financial services.

Customer facing applications, integration APIs, the mobile app and the AI layer used in analysis and service.

The full case study is in documentation. We publish client names only with written authorization.

See what you receive
In documentation

What we test in insurance.

Policyholder and broker portals, quotation APIs, reimbursement flows and the AI that reads documents and receipts.

The full case study is in documentation. We publish client names only with written authorization.

See what you receive
In documentation

What we test in manufacturing.

Operational systems and ERP integrations, exposed environments, access control and the AI applied to design and engineering.

The full case study is in documentation. We publish client names only with written authorization.

See what you receive
In documentation

What we test in healthcare.

Platforms holding sensitive data, audit trails, role based access control and compliance with applicable data protection law.

The full case study is in documentation. We publish client names only with written authorization.

See what you receive
In documentation

What we test in logistics.

System to system integrations, tracking APIs, field environments and computer vision in operation.

The full case study is in documentation. We publish client names only with written authorization.

See what you receive
In documentation

Applications, APIs and infrastructure.

OWASP Top 10, injections, authentication, privilege escalation, isolation between users, business logic, exposed services, vulnerable libraries and cryptography. Every finding comes with step by step reproduction, so your team can fix it without depending on us to understand what happened.

Illustration about application and infrastructure testing

The layer nobody else tests.

Your AI is connected to your systems, your data and your customers. We run controlled prompt injection and jailbreak tests, audit real conversations, measure cost and latency per model, and check whether the system started hallucinating after the provider's last update. Traditional security firms do not do this, because they do not build AI.

Illustration about AI security

Where your data could leak.

We identify the application and integration flaws that would allow improper access to customer, user and internal information, with the impact of each one classified by severity before any fix begins.

Illustration about data protection

You receive a complete diagnosis of your digital security.

It reaches you as three documents, each written for the person who will read it.

01

Executive Report

Where the company is exposed, what is serious and what can wait. In business language: you take it into the meeting and everyone understands.

02

Prioritized Remediation Plan

Every finding classified by criticality in the risk matrix, with the evidence, the deadline and remediation guidance ready for your IT team or your vendor to execute.

03

Test Certificate

Proof that your company tests its own security. It is what banks, large clients and auditors ask for when they want evidence, not promises.

Your technical team gets more: the full report, with the mapping of every environment, the evidence and the step by step reproduction of each finding. With retesting contracted, confirmation that the fix worked. And if your operation uses AI, the package also includes a vulnerability report for the AI layer with the prompt already hardened, a model fit matrix by task with cost projection, and a regression report with a mitigation plan.

That is Safe Pontual, our one time assessment, the snapshot of where you stand today. When remediation needs to become routine, Safe Jornada, our continuous engagement, takes over the operation, with test and retest sprints, a live risk backlog and a monthly executive committee. And when the remediation plan points to architecture rather than to a fix, there is a path for that too.

Where it is required
  • Applicable data protection law
  • ISO 27001
  • PCI-DSS
  • Audits
  • Banks and partners

Every deliverable is confidential, shared only with the people you authorize.

What the public incidents of recent years have in common.

In almost all of them, the flaw that was exploited was known, documented and testable before the incident. What was missing was not defensive technology. What was missing was someone to test.

INCIDENT ANALYSIS · APPLICATION SECURITY · OPERATIONAL RISK

Our specialists discuss how to test applications, cloud and AI in production, with real cases and what each test actually finds.

AI IN PRODUCTION · APPLICATION SECURITY · CLOUD

Let's define the scope of your first test.

A conversation to understand your assets, your environments and what makes sense to test first. No proposal before the scope is defined.

Discuss scope A scoping conversation, no commitment.

No. Before any test we define the rules of the work with you: what will be assessed, when and how. Every action is controlled and non destructive. Our role is to identify and confirm the findings, not to cause the damage a criminal would cause. Nothing is deleted, altered or taken offline. If you prefer, the tests can run in a staging environment, without touching the system that serves your customers.

It does, and that is why the reports speak two languages. You get a summary in business language, with the risks found and what should be resolved first. Whoever looks after your systems, whether a vendor, a software house or an internal professional, gets the technical step by step for each fix. And if no one is looking after this today, Safe Jornada, our continuous engagement, works as your outsourced security department.

An executive report in business language, a risk matrix with every finding classified by severity, a prioritized remediation plan, a technical report with the evidence and reproduction steps for each vulnerability, and the Test Certificate. It is the document banks, large clients and auditors ask for when they want evidence rather than promises, and it is the kind of testing evidence that ISO 27001 and PCI DSS processes usually require. If your operation uses AI, the package also includes the AI layer report, with the prompt already hardened.

It depends on the size of what will be assessed. One time packages are sized between 40 and 160 hours of technical work, which in practice means a few weeks between the start of testing and the delivery of the reports. It all starts with a scoping conversation, and the proposal comes out with the schedule and the delivery date already set.

All work is covered by a non disclosure agreement and by scope rules defined in the contract. We access only what is needed to confirm the findings, in a controlled way, and report distribution is restricted to the people you authorize. We operate in line with applicable data protection law, and the test itself helps your company demonstrate the diligence the law requires.

They are different things, and both remain necessary. A firewall and antivirus are automated defenses. The Safe test does the opposite: it simulates a human attacker trying to get in, to find out what gets past those defenses. Most successful attacks exploit exactly what those tools cannot see, such as configuration errors, gaps in login screens and systems exposed to the internet for no reason.

Yes, and this is where we stand apart. AI assistants and agents can be manipulated into leaking information, bypassing business rules or answering on behalf of your brand in ways you never approved. We run controlled prompt injection and jailbreak tests, audit real conversations, measure cost and latency per model, and check whether the system started hallucinating after the provider's last update. You receive the prompt already hardened. Traditional security firms do not test this, because they do not build AI. GenIA does.

Safe Pontual is the snapshot: a package of hours with a full assessment, risk matrix, remediation plan and certificate. It fits audits, go lives, compliance requirements, due diligence or periodic reassessment. Safe Jornada is the operation: a monthly subscription in which we act as your security team, with a live risk backlog, test and retest sprints, an executive committee and continuous maturity growth. If you need to prove something now, start with Pontual. If you need to keep it that way, start with Jornada.

It depends on the scope: how many systems will be assessed, in which environments, at what depth, and whether retesting is needed. We define that with you in the first conversation, and the proposal comes out with the price and the timeline already set, with no surprises later. One time packages are sized in hours, from 40 to 160, and continuous engagement is monthly.