Inventory & Discovery
Find every LLM endpoint, MCP server, vector DB, RAG pipeline, embedding model and fine-tune in your VPC. No agent install; log-based and traffic-based discovery.
Read the architecture →Nine subsystems on a shared inventory and findings timeline.
Discovery, runtime enforcement, adversarial scans, and evidence export read and write the same asset inventory, so a discovered endpoint carries through to the control-ID evidence an auditor reads.
LLM endpoints, tools/functions, AI applications, vector DBs, embedding models, fine-tunes, self-hosted models, model providers, RAG, data sources, prompt gateways.
OWASP LLM + Agentic + ATLAS-aligned.
three judges + a meta-judge, no single model bias.
control-ID level, exported as PDF or JSON.
Each subsystem stands on its own, and all nine read and write the same asset records, event timeline, and finding history.
Find every LLM endpoint, MCP server, vector DB, RAG pipeline, embedding model and fine-tune in your VPC. No agent install; log-based and traffic-based discovery.
Read the architecture →Self-hosted egress agent with a DLP firewall. Policy ships as an Ed25519-signed rule blob. Prompts, completions, and tool args stay inside your trust boundary.
Gateway docs →Continuous posture scoring for hosted AI services across major cloud providers. Read-only role attestation covering drift detection, residency checks, IAM, encryption-at-rest, and AI service exposure.
Read the architecture →3,500+ probe templates across OWASP LLM, OWASP Agentic and MITRE ATLAS-aligned families. Three independent LLM judges plus a meta-judge, so no single model decides whether your app is safe.
View Sample Audit Evidence →Score any model from a public registry before you deploy it. Model card analysis flags pickle-format weight risk, license drift, missing safety evaluation, trust_remote_code, and EU AI Act Annex IV disclosure gaps - 50+ checks mapped to OWASP LLM Top 10 and NIST AI 600-1.
Read the threat model →Detect the repo-poisoning attack class before an AI coding assistant loads it: static, deterministic scanning of the configs those assistants trust - Cursor, Cline and Windsurf rule files, MCP mcp.json manifests, editor settings, agent hooks - for hidden Unicode (Trojan Source), remote command execution, credential exfiltration, MCP manifest poisoning, and human-approval bypass.
Every finding pre-mapped to OWASP LLM Top 10, OWASP Agentic, NIST AI 600-1, MITRE ATLAS, EU AI Act articles and ISO 42001 Annex A controls. Twenty-two cross-framework overlaps pre-computed.
View control matrix →Cross-framework deduplication, attack-path graphs, severity routing, and PDF + JSON export with auditor-ready control IDs. Every finding lands in an append-only audit log with a stable schema.
View Sample Audit Evidence →Runtime signals - gateway blocks, tool-chain anomalies, model drift, volume spikes - correlated into prioritized threats with closed-loop containment: revoke the agent or promote the pattern to a signed block rule.
Explore AI detection + response →A deterministic three-stage pipeline runs on every scheduled scan. Each stage is independently auditable.
Adversarial prompts drawn from a library covering OWASP LLM Top 10, MITRE ATLAS, and bespoke probes you author. Probes carry the framework references they exercise.
Each adversarial response is independently scored by three third-party LLMs (Anthropic, OpenAI, Google) running in parallel. A meta-judge resolves disagreement and flags low-confidence cases for human review.
Every finding is stamped with the framework control ID, severity rationale, and timestamps. PDF exports are auditor-ready; webhooks ship the same payload to Jira, Slack, or your SIEM.
Adversarial outputs are scored by three independent third-party LLMs in parallel. Each returns a verdict, confidence, rationale, and citations. A meta-judge resolves disagreement and routes low-confidence cases into a human review queue.
Prompt caching is aggressive (5-min TTL, ~90% discount). Judge runs use the Batch API where SLA allows for another 50% off.
Threat model, rule-blob format, gateway deployment guide, and a sample scan report, in one PDF.
One email. No drip, no sales follow-up unless you ask.