What is AI security testing?
It is testing an AI system for the ways it can be misused: instructions it can be tricked into ignoring, data it can be made to reveal, and actions it can be pushed to take. It looks at the model, the prompts around it, and the tools and data it can reach.
What can HashGo AIScan test?
Chat and model APIs, agents that call tools, retrieval-augmented applications, MCP servers, and open-weight model files and repositories.
Which frameworks does it map to?
Findings are mapped to the OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework and MITRE ATLAS.
How are credentials handled?
API keys and tokens are encrypted at rest and are never returned by the API once saved.
Does it replace a penetration test?
No. It gives you repeatable, evidence-backed AI testing you can run on every change. Our services team can add a manual assessment when you need one.