Our engineers set up and run your first chatbot / LLM security scan. Get in touch

AI-SPM Platform for Discovery, Runtime Gateway, Scans and Audit Evidence

Nine subsystems on a shared inventory and findings timeline.

Discovery, runtime enforcement, adversarial scans, and evidence export read and write the same asset inventory, so a discovered endpoint carries through to the control-ID evidence an auditor reads.

11
Asset kinds discovered

LLM endpoints, tools/functions, AI applications, vector DBs, embedding models, fine-tunes, self-hosted models, model providers, RAG, data sources, prompt gateways.

3,500+
Probe templates

OWASP LLM + Agentic + ATLAS-aligned.

3+1
Judge consensus

three judges + a meta-judge, no single model bias.

6
Frameworks mapped

control-ID level, exported as PDF or JSON.

Nine subsystems, one asset inventory.

Each subsystem stands on its own, and all nine read and write the same asset records, event timeline, and finding history.

Inventory & Discovery

Find every LLM endpoint, MCP server, vector DB, RAG pipeline, embedding model and fine-tune in your VPC. No agent install; log-based and traffic-based discovery.

Hosted LLM APIsSelf-hosted inferenceVector databasesRAG pipelines+18
Read the architecture

Runtime Gateway

Self-hosted egress agent with a DLP firewall. Policy ships as an Ed25519-signed rule blob. Prompts, completions, and tool args stay inside your trust boundary.

Self-hostedDocker / k8sOpenTelemetrysub-ms overhead
Gateway docs

Cloud AI Posture

Continuous posture scoring for hosted AI services across major cloud providers. Read-only role attestation covering drift detection, residency checks, IAM, encryption-at-rest, and AI service exposure.

Read-only rolesDrift detectionResidencyEncryption-at-rest
Read the architecture

Adversarial Scans

3,500+ probe templates across OWASP LLM, OWASP Agentic and MITRE ATLAS-aligned families. Three independent LLM judges plus a meta-judge, so no single model decides whether your app is safe.

3,500+ probe templates3 judges + metaper-finding evidence
View Sample Audit Evidence

Model Supply-Chain Scanning

Score any model from a public registry before you deploy it. Model card analysis flags pickle-format weight risk, license drift, missing safety evaluation, trust_remote_code, and EU AI Act Annex IV disclosure gaps - 50+ checks mapped to OWASP LLM Top 10 and NIST AI 600-1.

Pickle vs safetensorsLicense drifttrust_remote_codeAnnex IV gaps
Read the threat model

Agent Config Poisoning Scan

Detect the repo-poisoning attack class before an AI coding assistant loads it: static, deterministic scanning of the configs those assistants trust - Cursor, Cline and Windsurf rule files, MCP mcp.json manifests, editor settings, agent hooks - for hidden Unicode (Trojan Source), remote command execution, credential exfiltration, MCP manifest poisoning, and human-approval bypass.

Repo poisoningTrojan SourceMCP manifestApproval bypass

Compliance Mapping

Every finding pre-mapped to OWASP LLM Top 10, OWASP Agentic, NIST AI 600-1, MITRE ATLAS, EU AI Act articles and ISO 42001 Annex A controls. Twenty-two cross-framework overlaps pre-computed.

6 frameworkscontrol-ID granularity22 overlaps
View control matrix

Findings + Reports

Cross-framework deduplication, attack-path graphs, severity routing, and PDF + JSON export with auditor-ready control IDs. Every finding lands in an append-only audit log with a stable schema.

Attack-path graphsPDF + JSON exportAppend-only audit log
View Sample Audit Evidence

AI Detection + Response

Runtime signals - gateway blocks, tool-chain anomalies, model drift, volume spikes - correlated into prioritized threats with closed-loop containment: revoke the agent or promote the pattern to a signed block rule.

Threat correlationAgent revokePromote-to-rule
Explore AI detection + response

How a scheduled scan produces evidence.

A deterministic three-stage pipeline runs on every scheduled scan. Each stage is independently auditable.

01

Probe

Adversarial prompts drawn from a library covering OWASP LLM Top 10, MITRE ATLAS, and bespoke probes you author. Probes carry the framework references they exercise.

02

Three-judge consensus

Each adversarial response is independently scored by three third-party LLMs (Anthropic, OpenAI, Google) running in parallel. A meta-judge resolves disagreement and flags low-confidence cases for human review.

03

Evidence

Every finding is stamped with the framework control ID, severity rationale, and timestamps. PDF exports are auditor-ready; webhooks ship the same payload to Jira, Slack, or your SIEM.

Three independent judges plus a meta-judge score every response.

Adversarial outputs are scored by three independent third-party LLMs in parallel. Each returns a verdict, confidence, rationale, and citations. A meta-judge resolves disagreement and routes low-confidence cases into a human review queue.

Prompt caching is aggressive (5-min TTL, ~90% discount). Judge runs use the Batch API where SLA allows for another 50% off.

See architecture

Read the architecture deep-dive.

Threat model, rule-blob format, gateway deployment guide, and a sample scan report, in one PDF.

One email. No drip, no sales follow-up unless you ask.