How vragen.ai holds up under pressure from an ethical hacker
What does an ethical hacking test mean for the AI search engine vragen.ai?

More and more organizations want to use AI, but responsibly. For many of them, that responsibility takes the shape of strict security requirements. In government, healthcare and education in particular, safety and control are essential.
vragen.ai helps organizations work with AI safely, inside their own knowledge and content. So they can innovate and keep up with technology without losing their grip on their data and their answers.
Security as the foundation
At SWIS, the company behind vragen.ai, we think safe use of AI starts with careful choices. That is why we build vragen.ai on a solid foundation. SWIS is certified for ISO 27001 and NEN 7510, and vragen.ai inherits that way of working and those certifications. NEN 7510 is the standard that applies in healthcare environments. What exactly it covers and what we can provide is on the page about security and data protection.
vragen.ai runs on RAG technology (Retrieval Augmented Generation). Answers always come from controlled sources that the organization manages itself. So you know what the AI says, and where it comes from. vragen.ai always backs answers up with links to the sources it used.

Read more about how vragen.ai works
Testing together in practice
During an implementation with a customer we went a step further than usual. We had one clear goal in mind:
"The proof of concept succeeds if we can demonstrate that the smart (AI) search engine cannot be manipulated into giving risky or harmful answers that could be damaging in any way."
Across several rounds of testing, more than 900 questions were asked, analyzed and rated on reliability, tone and safety. That produced valuable insight into how vragen.ai is best configured for this customer. The way the AI searches within an organization's own content turned out to matter most for the quality of the answers.
Testing yourself is worth a lot, but real certainty only comes when someone from outside takes a look. So we asked an ethical hacker to investigate independently whether vragen.ai holds up under pressure.
Independent assessment
The test was carried out in September 2025 under the Cyber Security Pen Test certification of the Dutch CCV. That certification confirms the test meets high quality standards. The ethical hacker looked into whether user data could be accessed, whether the AI could be influenced with specific prompts, and how well administrator functions were shielded.
The conclusion: the security of vragen.ai holds up well. No critical risks were found. The integrity and confidentiality of data are properly safeguarded.
The test did surface two points to improve. In some situations the output could show links and images from outside the knowledge base, and it proved possible to make the AI change its tone temporarily through targeted prompts.
We fixed both right away. The system prompt is tighter, output is limited to controlled sources and the AI holds its tone better. It may only deviate at the user's request, and that is always clearly indicated.
One step further: anonymizing personal data
During this project we added an extra layer of security as well. Although vragen.ai does not process personal data by default, we wanted to prevent users from sharing personal information unintentionally. So we built a feature that automatically anonymizes personal data entered through the open input field. That keeps the system safe and reliable in everyday use too.

We keep building safer AI
The test confirms that vragen.ai can be used safely, including in environments with high information security requirements. Together with our customers we keep developing vragen.ai further, because this is of course not the end point. The insights from this project help us improve the technology and keep safeguarding security.
That way vragen.ai is reliable today, and stays that way tomorrow.