What is AI red-teaming?
AI red-teaming means testing an AI system the way real users and attackers will. AltaSec sends jailbreaks, prompt injection and data-extraction attempts to your text chatbot or assistant through its API, checks every reply against your own rules, and delivers an evidence report that also states what could not be tested.
How is this different from a penetration test?
Classic pentests and scanners look at servers and code. AI red-teaming looks at how a language model behaves when someone talks to it: whether it leaks system prompts, keys or personal data, gets pushed outside its job by prompt injection, or gives answers your own policy forbids.
What do you need from us?
Your chatbot’s endpoint and your written authorization — no code access. You also tell us in writing what your AI is for and what it must never share or do; we turn that policy into targeted tests.
What do we get at the end?
An HTML report and a machine-readable JSON export. Each finding comes with its evidence transcript, human review and a concrete fix. The report includes a coverage statement and states its limitations: results are point-in-time and not exhaustive.
What does “not assessed” mean in the report?
It means a rule could not be tested, and the report says why — for example, the target timed out. Not tested is never counted as a pass, and a pass is only “verified” when a positive check backs it, such as a planted canary that was not disclosed.
Do you issue a certificate?
No. We issue reports with evidence — never certificates, seals or badges. Results are mapped to GDPR, the EU AI Act and the OWASP Top 10 for LLM Applications as evidence for your own assessment, not as a compliance verdict.
Where is our data processed?
In the EU only, by processors named in our data processing agreement with you. Your data is pseudonymised, and evidence is deleted when the engagement closes, per the retention we agree with you.
Which AI systems can you test today?
Text chatbots and AI assistants that we can reach through an API. Testing through a live chat widget on your website and multi-turn attacks are next on our roadmap; voice agents and tool-using agents come later.