Our engineers set up and run your first chatbot / LLM security scan. Get in touch

OWASP LLM Top 10 Compliance Mapping

OWASP LLM Top 10 (2025) is the community-curated list of the most critical security risks for large-language-model applications, covering LLM01 (prompt injection) through LLM10 (model theft).

Last reviewed July 2026

Why OWASP LLM Top 10 evidence is hard

An auditor works from a framework control list; a scan produces a finding list. Without a mapping between the two, each finding has to be translated onto the controls by hand before an audit.

How Penaxtra maps to OWASP LLM Top 10

Penaxtra ships probe families across all ten categories. The runtime gateway enforces controls aligned to LLM02, LLM06, LLM07, and LLM08.

OWASP LLM Top 10 capabilities

Every finding carries the LLM-NN identifier and the OWASP CWE references that underpin it

.

Audit-ready PDF export with control IDs attached

JSON export for GRC ticketing systems

Configurable audit retention from 1 day to 10 years

Cross-framework overlaps reduce duplicate evidence collection

OWASP LLM Top 10 control coverage

A successful indirect-injection probe via a RAG document is tagged LLM01 (prompt injection) and cross-mapped to LLM06 (sensitive disclosure) when the response leaked context.