Framework Explorer

OWASP LLM Top 10

Reviewed AuditaAI assessments connect documented offering behavior to OWASP risks. These are not vendor certifications or OWASP endorsements.

Official OWASP source

LLM01:2025

Prompt Injection

User prompts or external content alter an LLM application's intended behavior.

17 reviewed alignments
Reviewed offering assessments+
Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmentmedium confidence · 2 sources

Cranium AI platform interaction inspection is positioned to detect adversarial prompt-injection patterns in runtime workflows.

Prompt-injection pattern inspection aligns with OWASP prompt-injection risk context.

Amazon Web Services · Amazon Bedrock GuardrailsInferred alignmenthigh confidence · 1 source

Amazon Bedrock Guardrails applies inline controls that can block prompt-injection and jailbreak-style requests before model outputs are returned.

Blocking prompt-injection and jailbreak requests aligns with OWASP prompt-injection risk mitigation context.

F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 1 source

F5 AI Guardrails applies inline policy controls that can block prompt-injection payloads before requests reach downstream models and tools.

Blocking prompt-injection payloads aligns with OWASP prompt-injection mitigation context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 1 source

Cato AI Security runtime monitoring detects prompt-injection patterns and policy-violating AI prompt activity.

Detection of prompt-injection patterns aligns with OWASP prompt-injection risk context.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security helps detect prompt attacks, indirect injection, and sensitive data exposure across agent prompts, responses, and tool use.

Detection of prompt and indirect injection behavior aligns with prompt-injection risk mitigation context.

Cisco · AI Runtime ProtectionInferred alignmenthigh confidence · 1 source

AI Runtime Protection provides runtime guardrails for prompt and response threat mitigation.

Runtime guardrails for prompt threat mitigation align to prompt-injection risk context.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

AuditaAI assessment: prompt and jailbreak inspection with a block verdict addresses the documented prompt-injection risk.

Glow · Glow AI-Powered Endpoint Security PlatformInferred alignmentmedium confidence · 1 source

Glow continuous endpoint monitoring can detect suspicious AI interaction patterns and prompt-driven misuse across local applications and browser activity.

Detection of prompt-driven misuse patterns aligns with OWASP prompt-injection risk context.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred alignmenthigh confidence · 2 sources

Lasso runtime enforcement can block prompt-injection attempts and prevent unsafe autonomous agent actions or unauthorized tool invocation.

Inline blocking of prompt-injection attempts aligns with OWASP prompt-injection mitigation context.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmenthigh confidence · 1 source

Runtime guardrails are applied to block prompt injection attack paths before harmful model behavior propagates.

Blocking prompt-injection attack paths aligns with OWASP prompt-injection mitigation context.

Microsoft · Azure AI Content Safety and Prompt ShieldsInferred alignmenthigh confidence · 1 source

Azure AI Content Safety and Prompt Shields identify direct and indirect prompt injection and related unsafe prompt patterns before they reach downstream model behavior.

The source explicitly addresses direct and indirect prompt injection defense behavior.

Nightfall AI · AI Agent SecurityInferred alignmentmedium confidence · 1 source

AI Agent Security uses hook-level interception and tool-call governance to constrain unsafe autonomous actions before execution.

Interception of prompt-driven tool-action chains can mitigate prompt-injection-induced execution abuse.

Palo Alto Networks · Prisma AIRSInferred alignmentmedium confidence · 1 source

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

AuditaAI assessment: real-time safeguards for prompts and model interactions address prompt-injection risk.

Prompt Security · Prompt SecurityInferred alignmenthigh confidence · 1 source

Prompt Security runtime enforcement can block prompt-injection attempts in employee and application AI interaction paths.

Runtime blocking of prompt-injection attempts aligns with OWASP prompt-injection risk mitigation context.

Snowflake Inc. · Cortex AI GuardrailsInferred alignmenthigh confidence · 1 source

Cortex AI Guardrails evaluate runtime prompts and responses to mitigate direct and indirect prompt-injection and jailbreak attempts.

Documented runtime guardrails for direct and indirect prompt injection align with OWASP LLM01 context.

Zenity · Runtime Boundaries and AIDRInferred alignmentmedium confidence · 2 sources

Zenity runtime boundaries can block unsafe agent actions, including risky tool usage and unauthorized task execution.

Runtime prevention of harmful agent decisions can mitigate prompt-driven abuse effects in execution paths.

SPLX · SPLX Runtime GuardrailsInferred alignmenthigh confidence · 1 source

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: runtime blocking of documented prompt injection addresses the prompt-injection risk.

LLM02:2025

Sensitive Information Disclosure

Sensitive information is exposed through an LLM application or its interactions.

5 reviewed alignments
Reviewed offering assessments+
Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor can inspect, transform, tokenize, and redact sensitive elements in AI prompts and responses through Sensitive Data Protection integration.

AuditaAI assessment: inspecting, tokenizing, and redacting sensitive prompt and response content addresses sensitive-information disclosure risk.

HiddenLayer · AI Runtime SecurityInferred alignmentmedium confidence · 1 source

AI Runtime Security can detect, block, or redact unsafe actions and sensitive information according to policy and platform capabilities.

Blocking or redacting sensitive information at runtime is aligned to sensitive-information disclosure context.

Palo Alto Networks · Prisma AIRSInferred alignmentmedium confidence · 1 source

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

AuditaAI assessment: runtime safeguards across data-exposure paths address sensitive-information disclosure risk.

Portkey · PortkeyInferred alignmenthigh confidence · 1 source

Portkey automatically redacts sensitive data from requests before sending them to an LLM.

AuditaAI assessment: redacting sensitive data before an LLM request addresses sensitive-information disclosure risk.

Zscaler · Zscaler Data SecurityInferred alignmenthigh confidence · 1 source

Zscaler Data Security inspects AI usage and prompts and can block risky access or enforce prompt DLP to prevent data loss.

AuditaAI assessment: prompt DLP and access blocking address sensitive information disclosure through AI usage.

LLM03:2025

Supply Chain

LLM supply-chain components introduce vulnerabilities or compromise risk.

6 reviewed alignments
Reviewed offering assessments+
Chainguard · Chainguard Secure AI SDLCInferred alignmenthigh confidence · 1 source

Chainguard AI Security documents software supply chain coverage across SDLC phases, including trusted dependencies, CI/CD integrity, and hardened runtime foundations.

Securing dependencies and CI/CD integrity across AI SDLC phases aligns with software supply-chain risk mitigation.

Chainguard · Chainguard ContainersInferred alignmentmedium confidence · 1 source

Chainguard Containers is positioned as a built-from-source container catalog designed to minimize known vulnerabilities in development and production pipelines.

Built-from-source container artifacts positioned to reduce vulnerability exposure align to supply-chain risk mitigation context.

Wiz · Wiz AI-BOMInferred alignmentmedium confidence · 1 source

Wiz AI-BOM continuously inventories AI models, datasets, frameworks, software dependencies, identities, access paths, and infrastructure.

AuditaAI assessment: a continuously maintained inventory of models, datasets, frameworks, and dependencies supports identifying LLM supply-chain exposure.

HiddenLayer · AI Supply Chain SecurityInferred alignmenthigh confidence · 1 source

AI Supply Chain Security analyzes model architectures, layers, weights, and artifacts for tampering or anomalies and tracks model lineage, origin, and licensing.

Inspecting model artifacts and lineage for tampering aligns to supply-chain risk context.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS scans third-party models for tampering, malicious scripts, and deserialization risks.

AuditaAI assessment: scanning third-party models for tampering and malicious artifacts addresses LLM supply-chain risk.

Koi Security · Koi Agentic Endpoint SecurityInferred alignmentmedium confidence · 1 source

Koi AES evaluates code differences and behavioral shifts in real time to identify software supply-chain risk.

AuditaAI assessment: identifying supply-chain shifts in software and AI model environments supports addressing supply-chain risk.

LLM04:2025

Data and Model Poisoning

Training, tuning, retrieval, or other data is corrupted to affect model behavior.

1 reviewed alignment
Reviewed offering assessments+
SPLX · SPLX Runtime GuardrailsInferred alignmentmedium confidence · 1 source

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: runtime blocking of documented data-poisoning attempts addresses data and model poisoning risk.

LLM05:2025

Improper Output Handling

LLM output is insufficiently validated before downstream use.

1 reviewed alignment
Reviewed offering assessments+
Check Point Software Technologies · Check Point AI Security SolutionsInferred alignmentmedium confidence · 1 source

Check Point AI Security documents runtime enforcement that includes protection against harmful outputs in AI interactions.

Documented runtime protection against harmful outputs aligns with improper-output-handling risk mitigation context.

LLM06:2025

Excessive Agency

An LLM system receives excessive permissions, functionality, or autonomy.

21 reviewed alignments
Reviewed offering assessments+
Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmenthigh confidence · 2 sources

Cranium AI platform is positioned with runtime policy controls to govern unsafe autonomous agent behavior and over-permissioned execution paths.

Controls over unsafe autonomous execution align with OWASP excessive-agency risk mitigation context.

Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmenthigh confidence · 2 sources

Cranium AI platform data controls are positioned to prevent sensitive information disclosure across model and agent workflows.

Preventing sensitive information disclosure in model and agent workflows aligns with OWASP sensitive-disclosure context.

Tenable Holdings, Inc. · Tenable One AI ExposureInferred alignmentmedium confidence · 2 sources

Tenable One AI Exposure surfaces identity and entitlement risk for AI workloads, including over-permissioned access paths that can increase autonomous abuse risk.

Over-permissioned AI access paths align with excessive-agency risk mitigation context.

Amazon Web Services · Amazon Bedrock GuardrailsInferred alignmenthigh confidence · 1 source

Amazon Bedrock Guardrails includes sensitive-information policy controls to reduce protected-data leakage in prompt and response flows.

Sensitive-information protections in prompt and response channels align with OWASP sensitive-disclosure risk context.

F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 1 source

F5 AI Guardrails inspects prompts and responses to redact or block sensitive data and reduce leakage to external AI systems.

Prompt and response sensitive-data protections align with OWASP sensitive-disclosure mitigation context.

F5, Inc. · F5 AI GuardrailsInferred alignmentmedium confidence · 2 sources

F5 AI Guardrails applies agent-focused runtime controls to constrain unsafe autonomous actions and high-risk tool execution paths.

Controls over high-risk autonomous execution paths align with OWASP excessive-agency risk mitigation context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 1 source

Cato AI Security applies inline controls to block sensitive data exfiltration to unauthorized AI services and channels.

Blocking sensitive data transfer in AI interactions aligns with OWASP sensitive-disclosure risk mitigation context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmentmedium confidence · 2 sources

Cato AI Security governance controls constrain unsafe autonomous actions and high-risk tool usage for AI agents and applications.

Controls over unsafe autonomous actions and tool usage align with OWASP excessive-agency risk context.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security governs which tools and MCP servers agents can use, and evaluates agent actions in context to help block unsafe or unauthorized behavior at runtime.

Runtime controls over agent actions and tool use align with excessive-agency risk mitigation context.

Glow · Glow AI-Powered Endpoint Security PlatformInferred alignmenthigh confidence · 1 source

Glow endpoint controls can prevent sensitive information exposure through AI-enabled tools and unmanaged local workflows.

Preventing sensitive information exposure in AI-enabled workflows aligns with OWASP sensitive-disclosure risk context.

HiddenLayer · Agentic and MCP SecurityInferred alignmentmedium confidence · 1 source

HiddenLayer presents Agentic and MCP Security as a use case for protecting autonomous agents and MCP-based systems from prompt injection, unsafe tool use, and harmful autonomous actions.

Protection from unsafe autonomous actions and tool use aligns to excessive-agency risk context.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmentmedium confidence · 1 source

Runtime response workflows support containment and remediation for unsafe agent behavior and unauthorized action chains.

Containing unsafe autonomous action chains aligns with excessive-agency risk mitigation context.

Microsoft · Microsoft Purview for AIInferred alignmenthigh confidence · 1 source

Microsoft Purview for AI applies DLP and sensitivity controls to reduce unauthorized sensitive data transfer in AI interactions.

DLP and sensitivity control behavior aligns with sensitive information disclosure risk mitigation context.

NEO · Neo Security PlatformInferred alignmentmedium confidence · 1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

Controls over over-permissioned agentic execution align with excessive-agency risk mitigation context.

Nightfall AI · AI Application DLPInferred alignmenthigh confidence · 1 source

AI Application DLP applies pre-submission filtering and policy controls to block sensitive prompt, upload, and clipboard data before transfer to AI providers.

Pre-submission blocking of sensitive prompts and uploads aligns with sensitive-information disclosure risk mitigation context.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.

AuditaAI assessment: verifying agent identity and enforcing controls on agent actions addresses excessive agency risk.

Koi Security · Koi Agentic Endpoint SecurityInferred alignmentmedium confidence · 1 source

Koi AES enforces endpoint guardrails that approve, flag, or block autonomous tools.

AuditaAI assessment: approving, flagging, or blocking autonomous tools supports limiting excessive agent agency.

Prompt Security · Prompt SecurityInferred alignmenthigh confidence · 1 source

Prompt Security prompt and content controls redact sensitive enterprise data before it is sent to external models.

Prompt data redaction controls align with OWASP sensitive-disclosure mitigation context.

Prompt Security · Prompt SecurityInferred alignmentmedium confidence · 2 sources

Prompt Security agent-focused governance restricts risky autonomous tool use and unsafe execution decisions.

Agent governance over risky autonomous actions aligns with OWASP excessive-agency mitigation context.

Snowflake Inc. · Cortex AI GatewayInferred alignmenthigh confidence · 2 sources

Cortex AI Gateway records both agent identity and human delegator context for task-scoped attribution and governance workflows.

Task-scoped delegated control and agent identity attribution mitigate excessive autonomous agency risk patterns.

Zenity · Runtime Boundaries and AIDRInferred alignmenthigh confidence · 2 sources

Zenity identity-aware runtime boundaries can prevent sensitive data access and exposure by over-permissioned agents.

Preventing over-permissioned agent access to sensitive data aligns with OWASP sensitive-disclosure mitigation context.

LLM07:2025

System Prompt Leakage

System prompts or related sensitive instructions are disclosed.

0 reviewed alignments

No reviewed offering alignments yet.

LLM08:2025

Vector and Embedding Weaknesses

Vector, embedding, or retrieval components create exploitable weaknesses.

0 reviewed alignments

No reviewed offering alignments yet.

LLM09:2025

Misinformation

LLM output creates or propagates false or misleading information.

0 reviewed alignments

No reviewed offering alignments yet.

LLM10:2025

Unbounded Consumption

LLM use creates uncontrolled resource consumption or denial-of-service conditions.

1 reviewed alignment
Reviewed offering assessments+
Snowflake Inc. · Cortex AI GatewayInferred alignmenthigh confidence · 2 sources

Cortex AI Gateway provides centralized token and API-consumption visibility with spend governance controls to reduce runaway enterprise AI usage.

Spend limits and centralized usage governance align with controls for unbounded consumption risk.