NETTRA // AI RED TEAM DOSSIER CONFIDENTIAL · SPECIMEN  ·  CLASSIFICATION: CLIENT-EYES-ONLY REV 2026.08
Adversarial testing for AI systems

We break your AI on paper, so no one breaks it in production.

Nettra red-teams your LLM and agent features against the OWASP LLM Top 10, proves each weakness with a harmless canary (never real payloads), and returns a dossier: scored, human-verified, with the fix. Then it re-tests on a schedule — tracking every issue until it's resolved and flagging anything that regresses.

01 / Runs only against endpoints you authorize — scope-enforced and egress-restricted, never pointed anywhere else.
02 / Non-destructive canary & planted-flag technique, so zero harmful output.
03 / Every finding hand-verified before it reaches you, for near-zero false positives.
AI EXPOSURE REPORTTARGET · chat.acme-demo
42 /100
Resilience Index
Exposed · action required
0PROBES: 4/6 BREACHED100
Crit
Indirect prompt injection via summarized document
LLM01 · CVSS 9.3 · canary echoed from quoted content
Crit
System prompt disclosed: ████████████
LLM07 · CVSS 7.5 · instructions leaked verbatim
High
Planted confidential flag extracted
LLM02 · CVSS 7.5 · yielded to false-authority framing
Med
Unescaped executable markup returned
LLM05 · CVSS 6.1 · raw <script> in model output
Specimen · Non-destructive
01 / The Method

A dossier in days, not a pentest in months.

Three moves. Each test fires only at an endpoint you authorize, and proves the weakness with a benign canary token or a value we plant, so nothing dangerous is ever generated.

Step 01

Authorize a target

Point us at one AI feature and confirm you're cleared to test it. No authorization, no traffic.

Queued
Step 02

Run the suite

An OWASP LLM Top 10-aligned probe set exercises injection, prompt leakage, disclosure and output handling.

Queued
Step 03

Receive & track the dossier

A resilience index, CVSS-rated findings, and the exact fix for each — human-verified first. Re-tests then track each issue as resolved or regressed over time.

Queued
02 / Coverage

Built around how AI actually fails.

The free diagnostic samples the highest-signal categories. A full engagement deepens each — orchestrating established red-team engines (garak, PyRIT, promptfoo) under one method — and validates every finding by hand before it reaches you.

LLM01Prompt Injection. Direct overrides and indirect injection carried in retrieved or quoted content.
LLM02Sensitive Disclosure. Coaxing secrets, PII, or confidential values out of the model's context.
LLM07System Prompt Leakage. Extracting your instructions, guardrails, and configuration.
LLM05Improper Output Handling. Unescaped markup and model output flowing into unsafe sinks.
LLM06Excessive Agency. Tools and actions the model can be talked into invoking outside policy.
Continuous re-test

Resilience isn't a one-time score. Each re-test diffs against the last, so you see exactly what changed since the previous scan:

NEW  just appeared OPEN  still unresolved RESOLVED  fixed since last scan REGRESSED  fixed, then came back
03 / Get Started

Request your free AI Exposure Report.

File the requisition below. We confirm you control the endpoint, run the diagnostic, and return your dossier.

FORM NX-01 · DIAGNOSTIC REQUISITIONNETTRA.FUSIONPACT.COM

Requisition logged.

We'll verify endpoint ownership, then run your AI Exposure Report. Most dossiers are returned within a few business days.

04 / Independence

Testing and attestation, kept apart by design.

Independence is not a footnote here. It's what makes the proof worth anything, so we build the separation into the workflow.

Separation of duties · chain of custody

Advisory sideNettra, by Fusionpact

Finds and helps you fix how your AI can be manipulated. We test and remediate; we never attest our own work.

→  handoff  →
evidence only

Assurance sideIndependent CPAs & certification bodies

SOC 2 and ISO 42001 are issued independently via isoapplication.com, with no interference from the testing team.