AI Security Frameworks.
Operational guides for the frameworks regulators, auditors, and enterprise buyers actually reference. Mapped to AI Posture Check questions.
The defining LLM-application security catalog.
Prompt Injection (LLM01)
An attacker manipulates an LLM through crafted inputs that override instructions, exfiltrate context, or trigger unintended actions.
Read the guideSensitive Information Disclosure (LLM02)
An LLM reveals sensitive data through output.
Read the guideSupply Chain (LLM03)
Vulnerabilities or compromises in upstream training data, pre-trained models, third-party datasets, model marketplaces, or fine-tuning services that affect the security of the deployed system.
Read the guideData and Model Poisoning (LLM04)
An attacker injects malicious data into training, fine-tuning, or RAG-corpus content to alter model behavior in their favor, often subtly and often persistently.
Read the guideImproper Output Handling (LLM05)
Downstream systems trust LLM output and execute it without validation, leading to traditional injection vulnerabilities (XSS, SQL injection, command execution) being introduced through LLM-generated payloads.
Read the guideExcessive Agency (LLM06)
An LLM-based agent has more permissions, more tool access, or more autonomy than its task requires.
Read the guideSystem Prompt Leakage (LLM07)
An attacker extracts the system prompt or other privileged context from an LLM.
Read the guideVector and Embedding Weaknesses (LLM08)
Risks specific to vector databases, embedding models, and RAG architectures.
Read the guideMisinformation (LLM09)
An LLM generates incorrect or misleading content that the user trusts and acts on.
Read the guideUnbounded Consumption (LLM10)
An LLM service is consumed in ways that drive cost, latency, or availability problems.
Read the guideNIST AI RMF, ISO 42001, EU AI Act, and MITRE ATLAS.
NIST AI RMF in Operation
The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) defines four core functions for AI risk: Govern, Map, Measure, Manage.
Read the guideISO 42001 in Practice
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system.
Read the guideThe EU AI Act in Practice
Regulation (EU) 2024/1689, the EU's harmonized rules on artificial intelligence.
Read the guideMITRE ATLAS for AI Defenders
MITRE ATLAS (Adversarial Threat Landscape for AI Systems) is a knowledge base of tactics, techniques, and case studies for adversarial machine learning.
Read the guideReady to find out where you actually stand?
Free, under three minutes, results in your browser. No email required.
Take the AI Posture Check