GALE SCAN · FREE · 90 SEC

Scan Your AI Chatbot Before You Deploy.
Free 90-Second Grade.

Paste your bot's system prompt. Get an A-F security grade + top 3 issues. 100% self-check — your bot, your prompt, your review.

No signup · No data stored · Results in 90 seconds
Grade My Bot →

Three steps. Ninety seconds.

You spend 35 seconds on steps 1 and 2. Our model spends 60 on step 3.

Paste your system prompt

The full instructions you give your AI agent. Don't worry — we don't store it.

30 SEC

Attest bot ownership

One-click legal safeguard. We only scan bots you own or operate — never third parties.

5 SEC

Get your A-F grade + top 3 issues

OWASP LLM Top 10 analysis: prompt injection, data leakage, excessive agency, prompt leakage.

60 SEC

Grade my bot.

Free, instant, and your prompt is never stored. Results stay on your screen.

Minimum 20 characters. Paste the full prompt you give your bot.
🔒 TLS encrypted · Prompt not stored · No account needed

Grading your bot…

Running OWASP LLM Top 10 analysis across 4 vulnerability classes.

PARSE PROBE SCORE
// YOUR GRADE
A
Ship It
Risk score: 0/100

Your system prompt has been graded against the OWASP LLM Top 10 framework.

What we found 0

★ DEEP SCAN · 30-DAY ACTION PLAN

Want the full picture?

Get the full top 10 issues + a 30-day action plan tailored to your bot. Delivered within 24 hours.

$49
one-time · 24-hr delivery · PDF report
  • Top 10 vulnerabilities (vs. top 3 here)
  • 30-day prioritized action plan
  • Drop-in prompt patches for each issue
  • PDF report, white-labeled for your team
  • Email support for follow-up questions

Secure checkout via Stripe · 7-day refund window

What GaleScan actually scans for.

Four high-impact classes from the OWASP LLM Top 10 — the ones that hit SMB chatbots hardest.

OWASP LLM01

Prompt Injection

User input that overrides the system prompt — direct injection, indirect via documents/RAG, multi-turn setup, encoding chains.

OWASP LLM02

Sensitive Information Disclosure

Whether the prompt leaks internal docs, pricing, customer data, API keys, or other secrets through model outputs.

OWASP LLM06

Excessive Agency

Tool-calling permissions, irreversible actions, lack of human-in-the-loop, scope creep in agentic workflows.

OWASP LLM07

System Prompt Leakage

Can a user extract the system prompt verbatim? Reverse-engineer hidden rules? Discover the model and version?

Common questions.

If yours isn't here, email mattgale87@gmail.com.

Do you store my system prompt?

No. The prompt is sent over TLS to the grading function, used for the analysis, and discarded. We do not write your prompt to disk, database, or any log. The analysis result (grade + findings) is held in your browser session only.

Can I scan someone else's chatbot?

No — and we built it that way on purpose. The attestation checkbox is a legal safeguard. We only grade prompts you own or operate. Scanning third-party chatbots raises CFAA / Terms of Service issues we want to avoid entirely.

How is this different from the $149 Snapshot?

GaleScan is automated, instant, and free — it gives you a top-3 issues triage in 90 seconds. The $149 Snapshot is a manual review by Matt Gale (H1 researcher, Zest V2 auditor) with 25+ targeted probes, a branded PDF, and a 15-min walkthrough video delivered in 5 business days. GaleScan is your "should I worry?" check; Snapshot is your "show me exactly what to fix" deliverable.

What does the $49 Deep Scan include?

The full top 10 vulnerabilities (not just the top 3 surfaced here), a 30-day prioritized action plan, drop-in prompt patches for each issue, and a PDF report white-labeled for your team. Delivered within 24 hours. The $49 is a stepping-stone to the $149 Snapshot and the $5K audit engagement if you need deeper work.

Is the A-F grade the same as the Snapshot's risk score?

They measure the same thing (OWASP LLM Top 10 risk surface) but with different fidelity. GaleScan's grade is a quick triage from a single LLM analysis pass — fast and free, but with less precision than 4-6 hours of manual review. If your GaleScan shows Critical or High, the $149 Snapshot is the right next step.

Why is it free?

Because the funnel works: you grade your bot, you see the issues, you want the full fix — that's where the $49 Deep Scan, $149 Snapshot, and $5K audit live. Free grading is the top of the funnel. We make money on the resolutions, not the read.

Scan your bot. Ship it safely.

Free 90-second grade. No signup. Your prompt never leaves the request.

Grade My Bot →