Use cases

Wherever AI acts, permissions must hold

TokenVeto tests the four architectures where permission failures hurt most — with evidence, not vibes.

Customer-facing chatbots

Support bots connected to order systems, CRMs and refund tools can be manipulated into actions far beyond answering questions.

Real outcome

A fintech support bot passed 412 of 438 tests; the 26 failures included a refund path reachable without authentication. Fixed before launch.

What we test

  • ▸Prompt injection via user messages and uploaded files
  • ▸Unauthorized refunds, discounts and account changes
  • ▸Cross-customer data leakage between sessions
  • ▸Tool-call abuse through chained instructions

Internal copilots & assistants

Copilots with access to email, docs and calendars inherit every employee's permissions — and every employee becomes a potential attack surface.

Real outcome

An enterprise copilot rollout was paused after TokenVeto showed a crafted email could make the assistant forward confidential contracts.

What we test

  • ▸Indirect injection through emails and shared documents
  • ▸Privilege escalation across departments
  • ▸Exfiltration of HR, finance and legal data
  • ▸Action approval bypass (send, delete, share)

Autonomous agents

Agents that plan and act over many steps accumulate small permission slips into major incidents — often without any human in the loop.

Real outcome

A coding-agent vendor adopted weekly TokenVeto runs after tests showed the agent could be steered to exfiltrate repository secrets.

What we test

  • ▸Multi-step goal hijacking
  • ▸Sandbox and tool-scope escape attempts
  • ▸Memory poisoning across sessions
  • ▸Unsafe chaining of approved actions

RAG & knowledge pipelines

Retrieval systems trust their corpus. Poisoned or malicious documents turn the knowledge base itself into an attack vector.

Real outcome

A legal-tech platform discovered confidential client documents were retrievable across tenant boundaries in 3 of 12 test scenarios.

What we test

  • ▸Document-level prompt injection
  • ▸Tenant isolation between data sources
  • ▸Access-control enforcement on retrieved chunks
  • ▸Citation spoofing and source manipulation

Built for your industry

Test scenarios tuned to the data and regulations that matter to you.

Finance & Insurance

Refund abuse, transaction authorization, KYC data exposure

Healthcare

Patient record isolation, diagnosis-assistant boundaries

SaaS & Developer Tools

Agent tool-scope, repository and secret access

Retail & E-commerce

Discount manipulation, order data leakage

Legal & Compliance

Tenant isolation, privileged document access

Public Sector

Citizen data boundaries, audit-ready evidence