LLM endpoints
Any endpoint speaking the modern chat-completions wire format. Credentials are encrypted with authenticated public-key cryptography; rotation is one click.
Each capability below maps to a shipped subsystem, with the counts and control IDs you can check against the code.
LLM endpoints, tools/functions, AI applications, vector DBs, embedding models, fine-tunes, self-hosted models, model providers, RAG systems, data sources, prompt gateways.
Scheme, CRLF, traversal, blocklist, DLP, entropy, SSRF, rate limit, length, and per-domain budget.
Built-in credential, secret, PII, payment-card, and seed-phrase detectors.
OWASP LLM Top 10, OWASP Agentic, NIST AI 600-1, MITRE ATLAS, EU AI Act, ISO 42001.
Discovery without an in-VPC agent install. Log-driven, traffic-driven, and credential-scoped pulls converge into a single inventory.
Any endpoint speaking the modern chat-completions wire format. Credentials are encrypted with authenticated public-key cryptography; rotation is one click.
Tool catalogue per agent. Destructive verbs and secret-accepting parameters are flagged in the inventory and feed the agent surface risk sub-score.
Pull operations from major vector database APIs. Index metadata, retriever auth posture, and tenant filter validation feed the RAG security test suite.
Thirteen automated tests cover injection-via-document, citation leakage, top-K overexposure, cross-tenant leakage, and canary-token planting.
Read-only role attestation against major cloud providers, covering guardrails, IAM, encryption, logging, and AI service exposure.
Local model scanner with backdoor detection for major model file formats. Known-bad SHA-256 hashes refreshed from an Ed25519-signed threat-intel feed.
A self-hosted agent sits between the application and the network. Policy ships as an Ed25519-signed rule blob. Prompt content stays in the customer VPC.
Scheme allowlist, CRLF injection, path traversal, domain blocklist, pre-DNS DLP, path entropy, subdomain entropy, SSRF and DNS rebinding, per-domain rate limit, length cap, and per-domain data budget.
Zero-width stripping, invisible character folding, leetspeak normalization, base64 plus hex unwrap, regex DLP, and Unicode confusable resolution. Bypass-resistant against common LLM evasion tactics.
Stable taxonomy with severity and retry flags. Every block surfaces a reason code your SIEM can pivot on; dashboards group block volume by reason for trend analysis.
Customer verifies the rule signature offline before activation. Public key is baked into the agent at build time; private key never leaves the control plane.
3,500+ probe templates across OWASP LLM, OWASP Agentic and MITRE ATLAS-aligned families. Each adversarial response is scored by three independent LLM judges (Anthropic, OpenAI, Google). A meta-judge resolves disagreement and routes low-confidence cases (under 0.7) into a human review queue.
Prompt caching is aggressive (five-minute TTL, ninety percent discount on cache hits). Judge runs use the Batch API where the SLA allows for an additional fifty percent reduction.
Every finding ships with the framework control identifier, severity rationale, judge citations, and timestamps. PDF exports are auditor-ready; webhooks ship the same payload to Slack, Jira, and SIEM destinations.
Some risks only appear when you look at how an agent moves through its tools.
Graph traversal across agents, tools, data sources, and cloud endpoints. Six built-in threat scenarios including external-to-PII, supply-chain MCP server, and compromised-tool-to-secret.
Subsequence-with-gap-tolerance engine. Ten built-in patterns per tenant cover credential exfiltration, destructive sequences, data pivots, and reconnaissance plus privilege escalation.
Static, deterministic scan of the config surface an AI coding assistant trusts - Cursor, Cline and Windsurf rule files, MCP mcp.json manifests, editor settings, and agent hooks - for hidden Unicode (Trojan Source), remote command execution, credential exfiltration, MCP manifest poisoning, and human-approval bypass.
Six orthogonal sub-scores (threat exposure, agent surface, attack-path pressure, control maturity, cloud posture, operational hygiene) combine into a composite score with grade bands A through F.
Twenty-two curated similarity pairs (for example NIST GV-3.2 aligns with ISO 42001 A.6.1; OWASP LLM 01 aligns with MITRE ATLAS AML.T0051) so one finding feeds multiple audit cells.
Request a demo for a private workspace review, or compare Penaxtra against manual pentests, single-judge scanners, and guardrail-only inline gateways.