Met us at WAVE in Turin? Your first chatbot check is free →

AI red-teaming · EU-based

Test your chatbot before someone else does.

AltaSec attacks your AI assistant the way real users and attackers will, checks every answer against your own rules, and hands you evidence — including what we could not test.

A testing service: we run the tests and deliver the report. We need your chatbot’s endpoint and your written authorization — no code access.

Report excerpt · Coverage and findings
Illustrative example · synthetic data
Example report rows: the outcome for each rule tested, with the evidence or reason behind it
OutcomeRule tested · evidence or reason
Violation Discloses system prompt under injectiontranscript + detector match, human-reviewed
Verified pass Never reveals other customers’ dataverified: planted canary not disclosed
No violation found Only discusses our productsjudged, not verified — no positive check exists for this rule
Not assessed Refuses medical advicetarget timed out — not tested, reason stated
Not tested is never green. A pass has to be earned by a positive check.
The problem

AI shipped fast. Testing didn’t keep up.

Classic pentests and scanners look at servers and code, not at how a language model behaves when someone talks to it. That gap is where things go wrong.

  • It leaks what it knows

    System prompts, keys, personal data and internal documents can come out in an answer when someone asks the right way.

  • It gets talked into things

    Prompt injection and jailbreaks push it outside the job you gave it.

  • It breaks your rules

    It gives answers your own policy forbids — and you are the one who has to explain them under GDPR and the EU AI Act.

What we test

Testing that understands language models

AltaSec is an EU-based AI red-teaming service: we test LLM chatbots and AI assistants for prompt injection, jailbreaks, system-prompt leakage and data leaks. Two checks are part of every engagement today. The third is next on our roadmap.

01 · Red-teamNow

Attack your chatbot before someone else does

We run automated adversarial tests against your text chatbot or assistant through its API: jailbreaks, prompt injection and attempts to pull data out of it. Every reply is checked for:

  • leaked secrets and API keys
  • personal data — Dutch, German and English
  • planted canary data turning up where it must not
  • risky output: script injection, javascript: links, markdown-image exfiltration, phishing links
02 · Your rules, as testsNow

Turn your rules into tests that run

You tell us in writing what your AI is for and what it must never share or do. We turn that policy into targeted tests and report on every rule.

Rule packs map the results to GDPR, the EU AI Act and the OWASP Top 10 for LLM Applications — as evidence for your own assessment, not a compliance verdict.

03 · Data checkNext · on the roadmap

Find the data your AI should never have seen

Scanning what you feed the AI — system prompts, knowledge bases and training sets — for personal data and secrets, before they end up in an answer.

On our roadmap, not yet part of an engagement. Today we detect this data when it comes out in the chatbot’s replies.

What you get

A report you can check

Every engagement ends with an HTML report and a machine-readable JSON export. Each finding carries the evidence behind it, and the report says plainly what was and was not tested.

  • Evidence transcripts

    The exact conversation behind each finding, so your team can reproduce it.

  • Coverage statement

    What was tested against which rule — and what was not assessed, with the reason.

  • Explicit limitations

    Results are point-in-time and not exhaustive. The report says so, and names the gaps.

  • JSON export

    The same findings in machine-readable form, for your tracker or your own analysis.

  • Human-reviewed findings

    A person reviews every finding before it reaches the report.

  • A fix per finding

    Each finding comes with a concrete recommendation for your developers.

findings.jsonexcerpt · simplified · synthetic
{
  "rule": "Never reveals other customers’ data",
  "outcome": "no_violation_verified",
  "basis": "planted canary not disclosed"
},
{
  "rule": "Refuses medical advice",
  "outcome": "not_assessed",
  "reason": "target timed out"
}

“Not assessed” is its own outcome. It is never counted as a pass, and a pass is only “verified” when a positive check backs it.

How it works

From scope to evidence

  1. Scope & authorize

    You sign the rules of engagement and a written authorization. Together we agree what is tested and the request limits.

  2. Test

    We run automated attacks against your chatbot’s endpoint, within the agreed limits. No code access needed.

  3. Judge & review

    An LLM judge, kept isolated from the attack content, scores each reply against your rules. A person reviews the findings.

  4. Report & retest

    You get the report and the JSON export. Re-testing with a fixed / regressed / new comparison between runs is next.

    Re-test comparison: Next
Why AltaSec

Precise, calm, accountable

  • EU-only processing

    Engagement data is processed in the EU only, by processors named in our data processing agreement with you.

  • Not tested is never green

    Anything we could not test is marked “not assessed”, with the reason. A pass has to be earned by a positive check.

  • Evidence you can check

    Every finding links to its transcript and the check that caught it. You do not have to take our word for it.

  • Pseudonymised, then deleted

    Your data is pseudonymised, and evidence is deleted when the engagement closes, per the retention we agree with you.

Our results are point-in-time and not exhaustive. We issue reports with evidence — never certificates, seals or badges.

Roadmap

What we do now, and what comes next

Now

Available today

  • Red-team of your text chatbot or assistant over its API
  • Tests generated from your written policy, mapped to GDPR, the EU AI Act and the OWASP Top 10 for LLM Applications
  • Evidence report: HTML and JSON, with coverage statement and limitations
Next

In development

  • Re-testing with a fixed / regressed / new comparison between runs
  • Policy conformance checks
  • Scanning data fed into the AI — system prompts, knowledge bases, training sets — for personal data and secrets
  • Multi-turn attacks
  • Testing through the live chat widget on your website
  • PDF reports
Later

Planned

  • Voice agents, on the web and by phone
  • Tool-using agents and MCP

Only the “Now” column is part of an engagement today.

FAQ

Questions we get asked

What is AI red-teaming?

AI red-teaming means testing an AI system the way real users and attackers will. AltaSec sends jailbreaks, prompt injection and data-extraction attempts to your text chatbot or assistant through its API, checks every reply against your own rules, and delivers an evidence report that also states what could not be tested.

How is this different from a penetration test?

Classic pentests and scanners look at servers and code. AI red-teaming looks at how a language model behaves when someone talks to it: whether it leaks system prompts, keys or personal data, gets pushed outside its job by prompt injection, or gives answers your own policy forbids.

What do you need from us?

Your chatbot’s endpoint and your written authorization — no code access. You also tell us in writing what your AI is for and what it must never share or do; we turn that policy into targeted tests.

What do we get at the end?

An HTML report and a machine-readable JSON export. Each finding comes with its evidence transcript, human review and a concrete fix. The report includes a coverage statement and states its limitations: results are point-in-time and not exhaustive.

What does “not assessed” mean in the report?

It means a rule could not be tested, and the report says why — for example, the target timed out. Not tested is never counted as a pass, and a pass is only “verified” when a positive check backs it, such as a planted canary that was not disclosed.

Do you issue a certificate?

No. We issue reports with evidence — never certificates, seals or badges. Results are mapped to GDPR, the EU AI Act and the OWASP Top 10 for LLM Applications as evidence for your own assessment, not as a compliance verdict.

Where is our data processed?

In the EU only, by processors named in our data processing agreement with you. Your data is pseudonymised, and evidence is deleted when the engagement closes, per the retention we agree with you.

Which AI systems can you test today?

Text chatbots and AI assistants that we can reach through an API. Testing through a live chat widget on your website and multi-turn attacks are next on our roadmap; voice agents and tool-using agents come later.

Founders

The people behind AltaSec

AltaSec was founded by three ICT students at Fontys University of Applied Sciences in Eindhoven, who won BrabantHack_26 together in the Defence track — reverse engineering ransomware and recovering encrypted files — before starting AltaSec.

  • Matei Patrascu

    Matei Patrascu

    Co-founder · Prompt injection

    Matei focuses on prompt injection and the adversarial tests AltaSec sends to a chatbot. He is a cloud engineer and studies ICT at Fontys University of Applied Sciences in Eindhoven.

    LinkedIn profile of Matei Patrascu
  • Afonso Costa

    Afonso Costa

    Co-founder · EU AI Act

    Afonso focuses on the EU AI Act and on mapping test results to the EU AI Act, GDPR and the OWASP Top 10 for LLM Applications. He studies ICT infrastructure and cybersecurity at Fontys University of Applied Sciences.

    LinkedIn profile of Afonso Costa
  • George Bâtcă

    George Bâtcă

    Co-founder · Data leaks

    George focuses on data leaks: detecting personal data, secrets and planted canaries in what an AI answers. He studies ICT at Fontys University of Applied Sciences.

    LinkedIn profile of George Bâtcă
Contact

Book an AI audit

Tell us which chatbot you want tested and what it is for. We will reply with how an engagement would work for you.

Met us at WAVE in Turin? Your first chatbot check is free. Email us with “Free chatbot check” in the subject.