77LeakAI

AI chatbot security · Europe

Your chatbot is telling more than you think.

Internal instructions, discounts nobody approved, other customers' data, promises that bind you. We talk to your AI assistant like any visitor would and show you what slips out. Free.

Nothing to install. No access to your systems. Report within 48 hours.

Two or three ordinary questions. No technical attack whatsoever.

What we find

Six ways a chatbot leaks information

System prompt

The bot repeats its internal instructions: tools, policies, names, URLs that should never have left.

Prices and margins

Maximum discounts, negotiated rates, fee ranges. What a salesperson would never say up front.

Third-party data

Other customers' orders, bookings or files. A GDPR incident waiting to happen.

Prompt injection

The visitor gives the bot orders and the bot obeys. From then on it says whatever the attacker wants.

Off script

Poems about competitors, opinions, brand-damaging content with your logo next to it.

Invented promises

Guarantees, refunds and terms that do not exist, in writing, on behalf of your company.

How it works

Four steps, zero friction

  1. 1Give us your websiteJust the URL and a corporate email. No access or credentials needed.
  2. 2We talk to your botA battery of 6 tests and at most 12 messages, like a normal user. No attacks on your infrastructure.
  3. 3Free basic reportOverall risk, affected categories and a couple of redacted examples. Enough to know whether you have a problem.
  4. 4We fix itIf you hire the remediation you get the full report and we leave the bot hardened, with regression tests.

Free diagnosis

Request your chatbot's basic report

You get it by email within 48 business hours. We only audit chatbots of the company you belong to, which is why we ask for a corporate email.

  • We only interact as a visitor of the public chat.
  • Any personal data the bot may show is redacted on the spot and never stored.
  • Nothing is published or shared with third parties.