Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

LLM Jailbreak

An LLM jailbreak is an attack that gets a language model to bypass its own safety guardrails and produce output it was trained or instructed to refuse. The attacker uses crafted prompts, role-play framings, or obfuscation to talk the model past its restrictions. It differs from prompt injection, which hijacks the instructions an application gives the model, whereas a jailbreak targets the model's built-in limits.

In practice

The stakes rise with what the model can do. A jailbreak on a chatbot that only talks is embarrassing; a jailbreak on an agent that can call tools or reach data is a security incident, so the risk scales with the model's reach.

Testing is the only honest way to know where you stand. Adversarial testing against the OWASP Top 10 for LLM Applications finds the framings that defeat your guardrails before a user does, which is the hands-on work our testing partners co-deliver.

// how traztech helps

traztech delivers LLM red teaming and adversarial testing for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

Jailbreaking matters most when a model's refusals are load-bearing for your product, for example a customer-facing assistant that must not produce certain content or reveal a system prompt. If a jailbreak defeats those refusals, the guardrail you were relying on was never really there. We test for it through LLM red teaming.

As with prompt injection, the defences that hold are architectural rather than a cleverer system prompt. Constrain what the model can do and reach, validate its output, and test adversarially, because safety training alone can be talked around.

LLM Jailbreak: common questions

What is the difference between a jailbreak and prompt injection?

A jailbreak targets the model's own safety restrictions, getting it to produce content it should refuse. Prompt injection targets the application's instructions, getting the model to ignore them and follow attacker-supplied ones. They often appear together.

Can jailbreaks be fully prevented?

No defence is complete at the model layer, because safety training can be framed around. The durable mitigations sit around the model: least-privilege tool access, output validation, and treating model output as untrusted.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.