Customer case study
Penfield: SOC 2 and AI agent security testing
How an AI process intelligence company tested agent guardrails, RAG ingestion, and traditional app/API surfaces in one engagement.
Penfield
SOC 2 Type II
AI process intelligence
The challenge
What the team needed to prove.
The assessment began with business context, exposed workflows, and the evidence stakeholders needed.
Penfield needed security proof for financial services buyers who asked about SOC 2, app security, and AI agent controls together.
The attack surface included customer workflows, API authorization, RAG ingestion, and agent tool boundaries.
The approach
Testing connected to the real operating surface.
Exploration, validation, and reporting stayed attached to the same approved scope.
DeepScan combined web/API pentesting with AI-specific scenarios including indirect prompt injection, retrieval leakage, and unsafe tool calls.
Human operators reviewed evidence quality and translated technical issues into buyer-readable risk language.
The result
Evidence ready for action and review.
Validated output gave engineering and assurance stakeholders a shared record.
Penfield received one report covering traditional and AI-native risks, reducing the need for separate vendor engagements.
The evidence helped answer financial services procurement questions with concrete proof rather than policy-only responses.
Start with proof
Build your own defensible security story.
Start with an approved target and keep every step from test to retest connected.