Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

LLM Prompt Injection Test Pack

Tell us what your AI feature does and get the test cases that apply, grouped by OWASP LLM Top 10 category. Each one says what to try, what to check and what a pass looks like.

What your AI feature does

Tests that need a feature you do not have are left out.

Categories

OWASP Top 10 for LLM Applications 2026.

Test cases

Use a test environment, test accounts and canary strings, never real customer data.

Full test cases

What to try, what to check, and what a pass looks like.

Run these only on systems you own or are authorised to test. They check that the basics hold; they do not show that a system is secure.

Questions

Are these working exploits?

No. They are test patterns built around canary strings and test accounts you control, so a failure shows up as a harmless marker in the output rather than real damage. They are meant for your own application, not anyone else's.

Which OWASP list are these mapped to?

The OWASP Top 10 for LLM Applications 2026, using the categories most relevant to prompt injection: LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM03 Excessive Agency, LLM08 Hidden Context Exposure and LLM10 Improper Output Handling.

What is a canary string?

A unique, meaningless marker such as CANARY-HC-01 that you plant in a system prompt, a document or a test record. If it ever appears in output where it should not, you have proof of a leak or an injection without needing anything sensitive.

If we pass all of these, are we secure?

Passing shows the basic defences hold against known patterns. Attackers chain techniques, vary wording and target the business logic around the model, which is what an objective-based red team exercise tests.

Is this test pack free?

Yes, free and no signup. Your choices stay in your browser.

Not ready for a call yet?

Get your test pack by email

Your test cases to keep, then a few short notes from Jacob on securing LLM applications. Unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want it done for you?

LLM red teaming

An objective-based campaign against your AI application and the logic around the model.

Explore LLM red teaming →

Test it the way an attacker would.

LLM red teaming runs an objective-based campaign against your AI application, chaining techniques against the business logic around the model, from $9,000 CAD. An AI security assessment covers the whole build, from $4,000 CAD.

See LLM red teaming See AI security assessments

Want the full picture?

This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

Start your free assessment See what is in the Workspace

No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.