Our engineers set up and run your first chatbot / LLM security scan. Get in touch

Company fact sheet.

One page for analysts, press and procurement. Every figure below reflects the shipped product, not a roadmap. Cite freely; verify against the linked pages.

6
Risk frameworks

OWASP LLM + Agentic, NIST AI 600-1, MITRE ATLAS, EU AI Act, ISO/IEC 42001, at control-ID level.

11
AI asset kinds

LLM endpoints, agents, MCP servers, RAG, vector DBs, models, providers, and more, in one inventory.

3+1
Judge consensus

Three independent LLM judges plus a meta-judge score every finding to reduce single-model bias.

EU/TR
Data residency

Self-hosted runtime gateway keeps prompt content inside the customer network.

The company.

Legal entity

Operated by Seccops Siber Guvenlik Teknolojileri A.S. Penaxtra is a registered product of the company.

Registered product

Category

AI Security Posture Management (AI-SPM), with a focused LLM-SPM layer. Adjacent to AI TRiSM and runtime AI security; distinct from CNAPP, DSPM and ASPM.

AI-SPMLLM-SPM

Market and region

Regulated mid-market teams in the European Union and Turkey, in banking, healthcare, insurance and public sector, with EU AI Act and ISO/IEC 42001 obligations.

EUTurkey

Open-source footprint

Apache-2.0 tooling published under the company name, including an MCP-server security auditor. Independently verifiable on public code hosting.

Apache-2.0

The product, in brief.

A continuous assurance platform for organizations deploying LLM-powered applications. It tests systems; it does not sit in the request path, except where the customer chooses to run the optional self-hosted gateway.

What it does

Runs scheduled adversarial test suites against customer LLM endpoints, agents, MCP servers and RAG pipelines; scores findings with multi-judge consensus; and produces control-mapped audit evidence.

Deployment model

SaaS control plane plus an optional self-hosted runtime gateway (a Go reverse proxy with Ed25519-signed policy blobs) that runs inside the customer network for data residency.

Evidence and reporting

Every finding carries framework control identifiers and an append-only audit trail. Exports are built for auditor and GRC consumption.

Coverage

A probe library of 3,000+ templates aligned to the OWASP LLM and Agentic families and MITRE ATLAS, plus cloud AI posture, model supply-chain scanning and MCP security testing.

Certifications: see the trust portal for current status and what is in progress. We describe controls that are implemented and certifications that are planned as exactly that, never as achieved.

For analysts and press.

Need a briefing, a product demo, or written answers to a research questionnaire? Reach out and note your outlet or firm. The analyst relations page has the full source list.

Analyst relations Contact us