LLM and ML Security Testing

Test your LLM app for prompt injection and PII leaks in one scan

Point OrbTech at your LLM endpoint and get a compliance-mapped security report in minutes. Running classical ML models too? Those get adversarial testing in the same scan.

Your API key is held in memory only - never stored, never logged
12
Security checks
130
Attack prompts
5
Frameworks

How it works

Four steps from your app to an audit report.

01

Connect your app or model

Give us your LLM endpoint and key, or upload an sklearn, XGBoost, LightGBM or Keras model file. No code changes.

02

We run the attack suite

130 attack prompts against your LLM, or 8 adversarial checks against your ML model - all automated, no config.

03

Get your PDF report

Download a full audit report with risk scores, findings in plain English, and regulatory compliance mapping.

04

Fix vulnerabilities

Each finding includes actionable recommendations your engineering team can implement immediately.

12 checks, two modules

LLM apps get 4 checks across 130 attack prompts. ML models get 8 adversarial checks. Each scan runs its full suite.

Prompt Injection

Injection

Feeds crafted instructions that try to override your system prompt and hijack the model. Measures how easily an attacker can make your app ignore its own rules.

Jailbreak Resistance

Jailbreak

Runs known jailbreak patterns to see whether the model can be pushed past its safety guardrails into restricted output.

System Prompt Extraction

Leakage

Tries to trick the model into revealing its hidden system prompt - the instructions and business logic you don't want exposed.

PII Leakage

Privacy

Plants canary values - fake emails, phones, PANs - and checks whether the model repeats them back. A confirmed leak is an exact match, not a guess.

Feature Perturbation Attack

Evasion

Tests whether adding small noise to inputs causes the model to misclassify. Simulates a real attacker crafting adversarial inputs.

Boundary Search Attack

Evasion

Probes the decision boundary to find the minimum change needed to flip a prediction. Measures how exploitable your model boundary is.

Membership Inference

Privacy

Checks if an attacker can determine whether specific data was in your training set. Relevant to GDPR Article 35 compliance.

Model Inversion Attack

Privacy

Attempts to reconstruct what training data looks like from the model's predictions. Measures training data exposure risk.

Model Stealing Attack

IP Risk

Simulates an attacker cloning your model by querying the API repeatedly. Measures how much of your model logic can be replicated.

Data Poisoning Detection

Integrity

Detects statistical anomalies in input data that may indicate poisoning attempts - suspicious distributions, label flipping, boundary clustering.

Feature Integrity Analysis

Integrity

Identifies over-reliance on single features that creates fragility. Relevant to EU AI Act Article 13 explainability requirements.

Baseline Performance

Baseline

Documents ROC-AUC and accuracy before any attacks. Provides the performance benchmark all other checks are measured against.

One report your whole
team can act on

Two layers - plain English for CTOs and compliance teams, full technical findings for engineers.

Executive summary

Plain English findings, immediate actions, and regulatory flags - written for non-technical decision makers.

Technical findings

Full metrics, AUC scores, attack results, and feature analysis - everything your engineering team needs.

Regulatory mapping

Each finding mapped to OWASP LLM Top 10, EU AI Act, GDPR, ISO 42001 and DPDP Act - so your legal team knows exactly what applies.

LLM SECURITY AUDIT REPORT
78HIGH RISK
Prompt InjectionHIGH 38%
Jailbreak ResistanceLOW 4%
System Prompt ExtractionMEDIUM
PII Leakage (canary)HIGH · CONFIRMED
Fabricated PIITRACKED
OWASP LLM01OWASP LLM02EU AI Act Art.10DPDP Act §8

Simple, honest pricing

Built for Indian startups. Not enterprise contracts.

Free
₹0
forever
  • 1 scan per month
  • All 12 checks (LLM + ML)
  • PDF compliance report
  • OWASP, EU AI Act, DPDP mapping
Start free →
Pro
₹2,999
per month
  • 100 scans
  • All 12 checks (LLM + ML)
  • API access
  • Full scan history
  • Priority support
Get started →

Built for compliance teams

Every finding mapped to the regulations your legal team is asking about.

OWASP LLM Top 10

LLM Security

Prompt injection, sensitive information disclosure and system prompt leakage mapped to the OWASP framework for LLM applications.

LLM01LLM02LLM07
EU AI Act 2024

AI Act Compliance

Maps findings to articles most relevant to high-risk AI systems - risk management, data governance, transparency, and monitoring.

Article 9Article 10Article 13Article 15Article 72
GDPR

Data Protection

Privacy vulnerabilities like membership inference and model inversion mapped to GDPR obligations helping assess DPIA requirements.

Article 5Article 25Article 32Article 35
ISO/IEC 42001

AI Management System

Documented evidence for ISO 42001 clauses covering risk identification, impact assessment, and ongoing monitoring obligations.

Clause 6.1Clause 8.4Clause 9.1
DPDP Act 2023

India Data Protection

India's Digital Personal Data Protection Act obligations mapped to privacy scan findings, critical for RBI and SEBI regulated entities.

Section 8Section 11Section 16

Built by someone who
understands both sides

OrbTech started as an adversarial scanner for ML models. It evolved into an AI security platform focused on helping teams test the AI systems they are putting into production - from LLM applications and chatbots to RAG systems and ML models.

Starting with Indian fintech and healthtech - sectors where data protection, security, and regulatory requirements make AI risk particularly important.

S

Shubham Kumar

Founder · OrbTech

I build security tooling for AI systems. OrbTech came from a gap I kept seeing: AI systems reaching production without enough practical security testing.

LLM SecurityPrompt InjectionAdversarial MLSecurity Auditing

Tell me what you think

Tried OrbTech, or have thoughts on where it should go? Send it over - it lands straight in my inbox.

Share your feedback

Bugs, feature requests, or just a reaction - all of it helps.

Frequently asked questions

What models and endpoints does OrbTech support?
OrbTech tests any OpenAI-compatible chat-completions endpoint - including OpenAI, Azure OpenAI, and compatible API gateways. You point OrbTech at your endpoint URL and model name, and it runs its adversarial test suite against it. For classical machine-learning models, OrbTech's ML scanner supports scikit-learn models.
Is my data stored? What about my API key?
Your API key is held in memory only for the duration of the scan - it is never written to disk, never stored in a database, and never logged. It's discarded the moment the scan finishes. Your scan reports are stored securely in your own isolated, access-controlled space, so only you can see your results. We don't store payment card details - payments are handled entirely by Razorpay.
Is it safe to point OrbTech at my production LLM?
Yes. OrbTech only sends prompts to the endpoint you specify and reads the responses that come back - it doesn't modify your system, change your configuration, or persist anything about your model. The adversarial prompts are the same kinds of inputs a real attacker would try, run in a controlled way so you find weaknesses before they do. Your API key stays in memory for the scan only, and your prompts and the model's responses are used solely to generate your report.
What happens after my free scan?
The free tier includes one scan. After that, you can upgrade to Pro for 100 scans, full scan history, API access, and priority support. Your account and any reports you've already generated stay accessible whether or not you upgrade.
How long are my reports kept?
Your reports are stored securely and remain accessible in your dashboard, so you can revisit past scans whenever you need them.
How do I upgrade to Pro?
Click "Upgrade to Pro" from your billing page and we'll get you set up. We're currently onboarding Pro customers directly to make sure everything's tailored to your needs - just reach out and we'll take care of the rest.