CADi · Ai input security
What is getting through your prompt defences?
Investigate prompt-injection exposure and the reasons inputs were trusted or refused, starting with the evidence in your application logs.
Bring us a problem, a suspected opportunity or a result that does not add up. We can explore how CADi Prompt could help, starting with your question and the evidence available.
Get in touchPrompt injection is an input crafted to make a language model act against its instructions. As LLM applications take on real decisions, the moment of trusting an input becomes a decision in its own right - and one that is almost never governed or recorded.
A black-box filter can block a prompt, but it cannot tell you why it blocked, under what policy, or whether the block was warranted. When an injection attempt succeeds, or a legitimate input is wrongly refused, there is no defensible record of the call.
CADi Prompt investigates prompt-injection exposure using historical application logs and the evidence behind decisions to trust, refuse or escalate an input. It is designed to examine attempts to redirect an application away from its intended behaviour.
Start with analysis and review of the evidence. Live allow, block or escalate controls are a deployment stage that requires its own validation; the analysis does not guarantee that every injection attempt will be detected.
Review historical inputs and trust decisions for evidence of prompt-injection attempts.
Examine the model, evidence and assumptions supporting a finding.
Investigate why a legitimate input may have been refused as well as why a harmful one was trusted.
Use the findings to guide testing and configuration before enabling any live decision authority.
Builders putting language models on a real decision path, who need the trust boundary governed rather than left to an opaque filter.
The functions accountable for how an Ai system behaves under adversarial input, who must evidence that the trust decision was warranted.
We define the input-trust question with your team and examine the application evidence under an explicit causal model. The reasoning and its limits remain available for review.
Historical analysis can deepen into a one-way evidence feed through CADi SideCar. Any live controls are enabled only within an agreed, validated deployment; your application security remains a broader responsibility.
CADi is in production - its engines are live in the cloud - with nine UK patent applications pending. CADi Prompt records the trust decision and is built to govern it; it is not a guarantee that every injection will be caught, and it does not replace the rest of an application's security posture.
Causal analysis runs on a declared model of the decision environment. Its conclusions depend on that model, the available evidence and explicit assumptions; estimates are analytical approximations. The engine has been tested against injected, synthetic and real ingested data. Live-outcome validation is completed against each client's own outcomes during deployment.