Frequently Asked Questions
What does the scanner check?
Your system prompt is analyzed against 4 OWASP LLM Top 10 vulnerability classes: LLM01 (Prompt Injection), LLM02 (Sensitive Information Disclosure), LLM06 (Excessive Agency), and LLM07 (System Prompt Leakage). Each finding includes severity, evidence from your prompt, and an OWASP reference.
Is my prompt stored?
Free Scan: No. Your prompt is sent to the analysis engine and the result is returned — nothing is persisted. Deep Scan ($49): Yes, your prompt is saved as an intake record so our security team can review it and provide a full remediation report. You'll receive a Stripe checkout link before payment is collected.
How accurate is the scan?
The scanner uses glm-5.2 (Ollama Cloud) with a structured analysis prompt targeting specific OWASP classes. It's a strong automated baseline — not a substitute for a human-led red team. For production systems handling sensitive data, we recommend the
$3,500 MCP Security Assessment or a
$2K/mo retainer.
What's the difference between Free and Deep Scan?
Free Scan returns a grade (A–F), a score (0–100), and your top 3 findings. Deep Scan ($49) returns all findings with full evidence, persists the intake for our team to review, and includes a Stripe checkout link. The Unlimited plan ($99/mo) gives you unlimited Deep Scans plus API access.
What if I need a full security audit?
The scanner is a quick baseline. For a comprehensive assessment covering MCP tool security, RAG poisoning, data exfiltration, and compliance (ISO 42001, SOC 2), book a
free 15-minute audit call.