Our engineers set up and run your first chatbot / LLM security scan. Get in touch

Every capability mapped to the code that ships it.

Each capability below maps to a shipped subsystem, with the counts and control IDs you can check against the code.

11
Asset kinds

LLM endpoints, tools/functions, AI applications, vector DBs, embedding models, fine-tunes, self-hosted models, model providers, RAG systems, data sources, prompt gateways.

11
URL scanner layers

Scheme, CRLF, traversal, blocklist, DLP, entropy, SSRF, rate limit, length, and per-domain budget.

48
DLP patterns

Built-in credential, secret, PII, payment-card, and seed-phrase detectors.

6
Framework mappings

OWASP LLM Top 10, OWASP Agentic, NIST AI 600-1, MITRE ATLAS, EU AI Act, ISO 42001.

Find the AI assets your CMDB cannot see.

Discovery without an in-VPC agent install. Log-driven, traffic-driven, and credential-scoped pulls converge into a single inventory.

LLM endpoints

Any endpoint speaking the modern chat-completions wire format. Credentials are encrypted with authenticated public-key cryptography; rotation is one click.

Chat completionsBearer rotationLatency probe

MCP servers + agent tools

Tool catalogue per agent. Destructive verbs and secret-accepting parameters are flagged in the inventory and feed the agent surface risk sub-score.

Destructive flagSecret-shaped paramsUntrusted input

Vector databases

Pull operations from major vector database APIs. Index metadata, retriever auth posture, and tenant filter validation feed the RAG security test suite.

Index inventoryTenant filterStale index alert

RAG pipelines

Thirteen automated tests cover injection-via-document, citation leakage, top-K overexposure, cross-tenant leakage, and canary-token planting.

13 testsCanary tokensPII chunk scan

Cloud AI services

Read-only role attestation against major cloud providers, covering guardrails, IAM, encryption, logging, and AI service exposure.

Read-only roleIAMEncryptionLogging

Self-hosted + fine-tuned models

Local model scanner with backdoor detection for major model file formats. Known-bad SHA-256 hashes refreshed from an Ed25519-signed threat-intel feed.

Pickle opcode scanKnown-bad SHA-256Ed25519 signed feed

Inline gateway with cryptographic policy distribution.

A self-hosted agent sits between the application and the network. Policy ships as an Ed25519-signed rule blob. Prompt content stays in the customer VPC.

Eleven-layer URL scanner

Scheme allowlist, CRLF injection, path traversal, domain blocklist, pre-DNS DLP, path entropy, subdomain entropy, SSRF and DNS rebinding, per-domain rate limit, length cap, and per-domain data budget.

Six-pass response normalization

Zero-width stripping, invisible character folding, leetspeak normalization, base64 plus hex unwrap, regex DLP, and Unicode confusable resolution. Bypass-resistant against common LLM evasion tactics.

Forty plus block-reason codes

Stable taxonomy with severity and retry flags. Every block surfaces a reason code your SIEM can pivot on; dashboards group block volume by reason for trend analysis.

Ed25519 signed rule blob

Customer verifies the rule signature offline before activation. Public key is baked into the agent at build time; private key never leaves the control plane.

Scheduled testing scored by three independent judges and a meta-judge.

3,500+ probe templates across OWASP LLM, OWASP Agentic and MITRE ATLAS-aligned families. Each adversarial response is scored by three independent LLM judges (Anthropic, OpenAI, Google). A meta-judge resolves disagreement and routes low-confidence cases (under 0.7) into a human review queue.

Prompt caching is aggressive (five-minute TTL, ninety percent discount on cache hits). Judge runs use the Batch API where the SLA allows for an additional fifty percent reduction.

Every finding ships with the framework control identifier, severity rationale, judge citations, and timestamps. PDF exports are auditor-ready; webhooks ship the same payload to Slack, Jira, and SIEM destinations.

See the pipeline

Attack paths and tool-call chains.

Some risks only appear when you look at how an agent moves through its tools.

Attack-path enumeration

Graph traversal across agents, tools, data sources, and cloud endpoints. Six built-in threat scenarios including external-to-PII, supply-chain MCP server, and compromised-tool-to-secret.

6 scenariosSeverity 0-10Per-path finding

Tool-call chain detection

Subsequence-with-gap-tolerance engine. Ten built-in patterns per tenant cover credential exfiltration, destructive sequences, data pivots, and reconnaissance plus privilege escalation.

10 patternsTunable gapConfigurable window

Agent config poisoning scan

Static, deterministic scan of the config surface an AI coding assistant trusts - Cursor, Cline and Windsurf rule files, MCP mcp.json manifests, editor settings, and agent hooks - for hidden Unicode (Trojan Source), remote command execution, credential exfiltration, MCP manifest poisoning, and human-approval bypass.

Repo poisoningTrojan SourceMCP manifest

Risk overview

Six orthogonal sub-scores (threat exposure, agent surface, attack-path pressure, control maturity, cloud posture, operational hygiene) combine into a composite score with grade bands A through F.

6 sub-scoresPer-dimension driversTrend chart

Cross-framework overlaps

Twenty-two curated similarity pairs (for example NIST GV-3.2 aligns with ISO 42001 A.6.1; OWASP LLM 01 aligns with MITRE ATLAS AML.T0051) so one finding feeds multiple audit cells.

22 overlapsAuditor-grade

Findings reach the systems your team already uses.

HMAC-signed webhooks SSRF guarded Slack OAuth 2.0 Jira Issue create + sync Splunk HTTP Event Collector HEC QRadar Syslog + CEF Bearer-token API /api/v2

See it on your stack.

Request a demo for a private workspace review, or compare Penaxtra against manual pentests, single-judge scanners, and guardrail-only inline gateways.

Request a demo See the comparison