AI security engineering for production systems

Bettag Systems reviews and secures LLM, RAG and agent systems for technical decision makers in the Nuremberg Metropolitan Region and across Germany. Franz Bettag works directly on the architecture, attack paths and implementation.

What gets secured

Prompts and context

Prompt injection, indirect instructions, system-prompt leakage and unsafe context boundaries.

RAG and data

Poisoning, manipulated sources, authorization failures, data exfiltration and missing provenance.

Tools and agents

Over-privileged tools, unsafe action chains, missing approvals and uncontrolled side effects.

Operations

Evals, audit logs, monitoring, cost controls, incident response and secure rollouts.

How the work runs

1. Understand the system

Map architecture, data flows, models, retrieval, tools, permissions and human approval points.

2. Test attack paths

Build a threat model and reproducible tests for injection, exfiltration, poisoning and tool misuse.

3. Remove risk

Implement controls or hand over a prioritized backlog with clear ownership.

4. Secure operations

Anchor regression evals, logging, alerts, approvals and runbooks in production.

Deliverables

Threat model

Concrete assets, trust boundaries, attacker goals and traceable attack paths.

Security findings

Reproducible findings with risk, evidence and actionable remediation.

Secure production path

Prioritized architecture and implementation work, including evals and operational controls.