OWASP LLM Top 10 Compliance Mapping
OWASP LLM Top 10 (2025) is the community-curated list of the most critical security risks for large-language-model applications, covering LLM01 (prompt injection) through LLM10 (model theft).
Last reviewed September 2026
Why OWASP LLM Top 10 evidence is hard
An auditor works from a framework control list; a scan produces a finding list. Without a mapping between the two, each finding has to be translated onto the controls by hand before an audit.
How Penaxtra maps to OWASP LLM Top 10
Penaxtra ships probe families across all ten categories. The runtime gateway enforces controls aligned to LLM02, LLM06, LLM07, and LLM08.
OWASP LLM Top 10 capabilities
Audit-ready PDF export with control IDs attached
JSON export for GRC ticketing systems
Configurable audit retention from 1 day to 10 years
Cross-framework overlaps reduce duplicate evidence collection
OWASP LLM Top 10 control coverage
A successful indirect-injection probe via a RAG document is tagged LLM01 (prompt injection) and cross-mapped to LLM06 (sensitive disclosure) when the response leaked context.
Controls in this framework
Each control has a dedicated page: what it covers and how Penaxtra tests and evidences it.