We test your entire operation. Including your AI.

Genia Safe tests applications, APIs, mobile, code and infrastructure. And it tests the AI layer in production, which is where almost no one knows how to look. You get reproducible evidence, risk ranked by severity and a remediation plan with deadlines.

The AI layer is tested by people who build AI every day.

Discuss scope

A scoping conversation, no commitment.

How Genia Safe tests your operation

How Genia Safe tests your operation.

01

SCOPE

We define the assets, the environments, the execution window and the rules of engagement together with you. Nothing starts before that is agreed in writing.

02

EXECUTION

We test applications, APIs, mobile, code, infrastructure and the AI layer, in black box, white box or gray box mode.

03

PRIORITIZATION

Every confirmed finding enters the risk matrix with its severity, reproduction evidence, business impact and remediation deadline. The result is presented to leadership and to engineering, each in the terms they use to make decisions.

Carlos Augusto Verified
Founder of Grupo Genia
Carlos Augusto

“Testing an AI in production is not the same as testing an application. You need to know how the model was connected, what it can reach, how it responds when someone keeps pushing, and what changes when the provider ships a new version. The people who know how to test that are the people who build it every day. That is where Genia comes from.”

Get to know us

What our clients say.

Three video testimonials recorded by the clients themselves, in Portuguese with English captions. We publish a client’s name and testimonial only with written authorization.

Agribusiness

“The Genia team did this deep dive into the code, into the connections and APIs, to understand those security aspects.”

An agricultural group from Cravinhos, in São Paulo state, with decades of work in sugarcane and agricultural services, was developing its first app built with AI, holding people data and indicators from the group’s companies. Genia reviewed the code, connections and APIs, delivered an assessment of what needed adjusting and helped define the group’s policy for the safe use of AI.

André CavalheirosSenior Business Intelligence and Performance Specialist, Grupo Carbisa

See what you receive

Audit and advisory

“We were able to automate a large part of these tasks, reduce the time spent on analysis and make the process much more agile and productive.”

An audit, tax and advisory firm headquartered in São Paulo and a member of the global HLB International network. For its Financial Advisory practice, Genia developed AI tools for the due diligence process, built around the team’s routine, and the team now devotes more time to the critical analysis of each transaction.

Eduardo VazFinancial Advisory Partner, HLB Brasil

See what you receive

Technology and digital transformation

“The result was turning a concern we had into a clearer view of the landscape and into concrete actions.”

A technology company focused on digital transformation, with process workflow, digitization and identification solutions for businesses and public agencies. With Genia Safe, it mapped its main vulnerabilities and came away with clear direction and concrete actions to keep evolving with the concern under control.

Wallace TeixeiraDirector, OSAS Tecnologia

See what you receive

Applications, APIs and infrastructure.

OWASP Top 10, injections, authentication, privilege escalation, isolation between users, business logic, exposed services, vulnerable libraries and cryptography. Every finding comes with step-by-step reproduction, so your team can fix it without depending on us to understand what happened.

Illustration about application and infrastructure testing

The layer nobody else tests.

Your AI is connected to your systems, your data and your customers. We run controlled prompt injection and jailbreak tests, audit real conversations, measure cost and latency per model, and check whether the system started hallucinating after the provider’s last update. Traditional security firms do not do this, because they do not build AI.

Illustration of a database with a “Protected data” badge

Where your data could leak.

We identify the application and integration flaws that would allow improper access to customer, user and internal information, with the impact of each one classified by severity before any fix begins.

Illustration of a browser with AI and a “Threat detected” alert

You receive a complete diagnosis of your digital security.

It reaches you as three documents, each written for the person who will read it.

01

Executive Report

Where the company is exposed, what is serious and what can wait. In business language: you take it into the meeting and everyone understands.

02

Prioritized Remediation Plan

Every finding classified by criticality in the risk matrix, with the evidence, the deadline and remediation guidance ready for your IT team or your vendor to execute.

03

Test Certificate

Proof that your company tests its own security. It is what banks, large clients and auditors ask for when they want evidence, not promises.

Your technical team gets more: the full report, with the mapping of every environment, the evidence and the step-by-step reproduction of each finding. If retesting is included, confirmation that the fix worked. And if your operation uses AI, the package also includes a vulnerability report for the AI layer with the prompt already hardened, a model fit matrix by task with cost projection, and a regression report with a mitigation plan.

That is Safe Pontual, our one-time assessment, the snapshot of where you stand today. When remediation needs to become routine, Safe Jornada, our continuous engagement, takes over the operation, with test and retest sprints, a live risk backlog and a monthly executive committee. And when the remediation plan points to architecture rather than to a fix, there is a path for that too.

Where it is required
  • Applicable data protection law
  • ISO 27001
  • PCI-DSS
  • Audits
  • Banks and partners

Every deliverable is confidential, shared only with the people you authorize.

What the public incidents of recent years have in common.

In almost all of them, the flaw that was exploited was known, documented and testable before the incident. What was missing was not defensive technology. What was missing was someone to test.

INCIDENT ANALYSIS · APPLICATION SECURITY · OPERATIONAL RISK
A brain made of glowing particles

Let’s define the scope of your first test.

A conversation to understand your assets, your environments and what makes sense to test first. No proposal before the scope is defined.

Discuss scope A scoping conversation, no commitment.

No. Before any test we define the rules of the work with you: what will be assessed, when and how. Every action is controlled and non-destructive. Our role is to identify and confirm the findings, not to cause the damage a criminal would cause. Nothing is deleted, altered or taken offline. If you prefer, the tests can run in a staging environment, without touching the system that serves your customers.

It does, and that is why the reports speak two languages. You get a summary in business language, with the risks found and what should be resolved first. Whoever looks after your systems, whether a vendor, a software house or an internal professional, gets step-by-step technical guidance for each fix. And if no one is looking after this today, Safe Jornada, our continuous engagement, works as your outsourced security department.

An executive report in business language, a risk matrix with every finding classified by severity, a prioritized remediation plan, a technical report with the evidence and reproduction steps for each vulnerability, and the Test Certificate. It is the document banks, large clients and auditors ask for when they want evidence rather than promises, and it is the kind of testing evidence that ISO 27001 and PCI DSS processes usually require. If your operation uses AI, the package also includes the AI layer report, with the prompt already hardened.

It depends on the size of what will be assessed. One-time packages are sized between 40 and 160 hours of technical work, which in practice means a few weeks between the start of testing and the delivery of the reports. It all starts with a scoping conversation, and the proposal comes out with the schedule and the delivery date already set.

All work is covered by a non-disclosure agreement and by scope rules defined in the contract. We access only what is needed to confirm the findings, in a controlled way, and report distribution is restricted to the people you authorize. We operate in line with applicable data protection law, and the test itself helps your company demonstrate the diligence the law requires.

They are different things, and both remain necessary. A firewall and antivirus are automated defenses. The Safe test does the opposite: it simulates a human attacker trying to get in, to find out what gets past those defenses. Most successful attacks exploit exactly what those tools cannot see, such as configuration errors, gaps in login screens and systems exposed to the internet for no reason.

Yes, and this is where we stand apart. AI assistants and agents can be manipulated into leaking information, bypassing business rules or answering on behalf of your brand in ways you never approved. We run controlled prompt injection and jailbreak tests, audit real conversations, measure cost and latency per model, and check whether the system started hallucinating after the provider’s last update. You receive the prompt already hardened. Traditional security firms do not test this, because they do not build AI. Genia does.

Safe Pontual is the snapshot: a package of hours with a full assessment, risk matrix, remediation plan and certificate. It fits audits, go-lives, compliance requirements, due diligence or periodic reassessment. Safe Jornada is the operation: a monthly subscription in which we act as your security team, with a live risk backlog, test and retest sprints, an executive committee and continuous maturity growth. If you need to prove something now, start with Pontual. If you need to keep it that way, start with Jornada.

It depends on the scope: how many systems will be assessed, in which environments, at what depth, and whether retesting is needed. We define that with you in the first conversation, and the proposal comes out with the price and the timeline already set, with no surprises later. One-time packages are sized in hours, from 40 to 160, and continuous engagement is monthly.

Genius