Manual pentest
One bespoke document, written by the consulting team, dated at engagement end. No machine-readable evidence; mapping to the customer framework is done by hand.
LLM risk is treated by four common approaches and one specialist platform. The matrix below maps each against five axes that matter to a procurement review: time to evidence, framework mapping, continuity, auditor export, and prompt privacy.
Buyers comparing approaches usually have one already in flight. The most common combination we see in pilot deployments is "manual annual pentest plus a compliance spreadsheet"; the most expensive failure mode is "guardrail-only inline gateway with no audit trail" because the block log is not control-mapped evidence.
LLM01 Prompt injectionLLM02 Insecure output handlingLLM03 Training data poisoningLLM04 Denial of serviceLLM05 Supply chainLLM06 Sensitive disclosureLLM07 Insecure plugin designLLM08 Excessive agencyLLM09 OverrelianceLLM10 Model theftSix categories every engineering + GRC review covers: asset discovery, adversarial testing, runtime gating, compliance + evidence, audit + reporting, privacy + deployment. Cells use stable language - planned features are flagged as planned, not as ship today.
Honesty notes: ISO/IEC 27001 is certified and active. SOC 2 Type II is planned. SSO / SAML, on-prem control plane, multi-region data plane, and SARIF export are not yet shipped; they are on the public roadmap. The matrix above reflects the production platform shipping to enrolled customers today.
One bespoke document, written by the consulting team, dated at engagement end. No machine-readable evidence; mapping to the customer framework is done by hand.
JSON findings with severity, often unmapped to control IDs. The auditor receives a list of probes; the customer maps findings to controls themselves.
A block log, time-stamped. Not evidence: the auditor cannot tell which control a block satisfies, and the inline action prevents the underlying finding from ever entering an audit register.
PDF report plus JSON export, pre-mapped to OWASP LLM Top 10, OWASP Agentic, NIST AI 600-1, MITRE ATLAS, EU AI Act, and ISO 42001 Annex A. Twenty-two curated cross-framework overlaps so one row satisfies multiple audit cells. Append-only audit log with tamper-evident database mirror.
Penaxtra is an enterprise AI Security Posture Management (AI-SPM) platform positioned as one of several approaches buyers can pick: manual penetration testing, single-judge LLM scanners, guardrail-only inline gateways, compliance spreadsheets with consulting, or an AI module bundled into a broader CNAPP. The category Penaxtra fits is documented at the AI-SPM platform page.
The matrix above is the overview. Each page below is a written deep-dive into one comparison: where the two approaches overlap, where the gap sits, and how to tell them apart in an evaluation.
If you are running a selection process or preparing for an audit, start here.
Request a demo for a scoped workspace review, or book an architecture review with our security team.