Advisory sideNettra, by Fusionpact
Finds and helps you fix how your AI can be manipulated. We test and remediate; we never attest our own work.
Nettra red-teams your LLM and agent features against the OWASP LLM Top 10, proves each weakness with a harmless canary (never real payloads), and returns a dossier: scored, human-verified, with the fix. Then it re-tests on a schedule — tracking every issue until it's resolved and flagging anything that regresses.
| Crit | Indirect prompt injection via summarized document
LLM01 · CVSS 9.3 · canary echoed from quoted content |
| Crit | System prompt disclosed: ████████████
LLM07 · CVSS 7.5 · instructions leaked verbatim |
| High | Planted confidential flag extracted
LLM02 · CVSS 7.5 · yielded to false-authority framing |
| Med | Unescaped executable markup returned
LLM05 · CVSS 6.1 · raw <script> in model output |
Three moves. Each test fires only at an endpoint you authorize, and proves the weakness with a benign canary token or a value we plant, so nothing dangerous is ever generated.
Point us at one AI feature and confirm you're cleared to test it. No authorization, no traffic.
QueuedAn OWASP LLM Top 10-aligned probe set exercises injection, prompt leakage, disclosure and output handling.
QueuedA resilience index, CVSS-rated findings, and the exact fix for each — human-verified first. Re-tests then track each issue as resolved or regressed over time.
QueuedThe free diagnostic samples the highest-signal categories. A full engagement deepens each — orchestrating established red-team engines (garak, PyRIT, promptfoo) under one method — and validates every finding by hand before it reaches you.
| LLM01 | Prompt Injection. Direct overrides and indirect injection carried in retrieved or quoted content. |
| LLM02 | Sensitive Disclosure. Coaxing secrets, PII, or confidential values out of the model's context. |
| LLM07 | System Prompt Leakage. Extracting your instructions, guardrails, and configuration. |
| LLM05 | Improper Output Handling. Unescaped markup and model output flowing into unsafe sinks. |
| LLM06 | Excessive Agency. Tools and actions the model can be talked into invoking outside policy. |
Resilience isn't a one-time score. Each re-test diffs against the last, so you see exactly what changed since the previous scan:
File the requisition below. We confirm you control the endpoint, run the diagnostic, and return your dossier.
We'll verify endpoint ownership, then run your AI Exposure Report. Most dossiers are returned within a few business days.
Independence is not a footnote here. It's what makes the proof worth anything, so we build the separation into the workflow.
Finds and helps you fix how your AI can be manipulated. We test and remediate; we never attest our own work.
SOC 2 and ISO 42001 are issued independently via isoapplication.com, with no interference from the testing team.