Tenant boundary
Which organization or data domain owns the request?
RAG Security Assessment
A focused assessment for retrieval-augmented systems that need defensible isolation, authorization, and response-boundary controls.
Your RAG system can retrieve sensitive or multi-tenant material, but enterprise reviewers need confidence that authorization, source boundaries, and response behavior will not create leakage paths.
Best fit: Security, data platform, AI product, and enterprise SaaS teams shipping RAG features over sensitive or multi-tenant data.
Retrieval architecture, tenant and role authorization, vector indexes and metadata filters, query rewriting, document trust, prompt assembly, injection pathways, source attribution, and response controls.
Deliverable
A RAG isolation and authorization package with a data-boundary map, source authorization matrix, exposure scenarios, findings register, and enterprise remediation plan.
Timeline
Typically 10 business days from kickoff and access confirmation.
Signature view / retrieval boundary
The RAG review treats retrieval as a chain of boundaries. Each layer must preserve the user’s authority before material reaches the model and the final response.
Authorization chain
Which organization or data domain owns the request?
What is this user or service identity allowed to access?
Which document, index, metadata filter, or connector can contribute material?
What retrieved content and embedded instructions enter the model prompt?
What attribution, filtering, and output controls prevent leakage?
Sample assessment package
Agree the review boundary, authorized methods, and decision the work must support before starting. The scoped package draws from the outputs below and identifies untested paths and unresolved assumptions alongside the findings.
Findings on tenant, role, document, source, and metadata boundaries before retrieved content reaches model context.
Assess how user identity, tenant membership, metadata filters, and query rewriting affect what material can be retrieved.
Matrix showing which sources require authorization, attribution, trust labeling, filtering, or exclusion from generation.
Review how instructions embedded in documents, emails, webpages, and tool output can influence retrieval and response behavior.
Prepare a concise technical summary of isolation controls, known limits, and remediation priorities for customer security teams.
Risk addressed
When to use it
Use this before enterprise security review, customer launch, multi-tenant rollout, or expansion into higher-sensitivity document sets.
Next step