---
title: AltaSec — AI red-teaming for chatbots, EU-based
url: https://alta-sec.com/
---

# AltaSec — Test your chatbot before someone else does

> AltaSec is an EU-based AI red-teaming service. We test text chatbots and AI assistants the way real users and attackers will — jailbreaks, prompt injection and data-extraction attempts, sent to the chatbot's API — check every reply against the client's own written rules, and deliver an evidence report that also states what could not be tested.

AltaSec is a service, not a self-serve tool: we run the tests and deliver the report. We need the chatbot's endpoint and the client's written authorization; no code access.

## What we test today

- Red-team of a text chatbot or assistant over its API: jailbreaks, prompt injection and attempts to pull data out of it.
- Every reply is checked for leaked secrets and API keys; personal data in Dutch, German and English; planted canary data turning up where it must not; and risky output (script injection, `javascript:` links, markdown-image exfiltration, phishing links).
- Your rules, as tests: the client states in writing what the AI is for and what it must never share or do; we turn that policy into targeted tests and report on every rule. Rule packs map results to GDPR, the EU AI Act and the OWASP Top 10 for LLM Applications — as evidence for the client's own assessment, not a compliance verdict.

## What the client receives

- An HTML report and a machine-readable JSON export.
- Evidence transcripts for every finding, reviewed by a person.
- A coverage statement: what was tested against which rule, and what was not assessed, with the reason.
- Explicit limitations: results are point-in-time and not exhaustive.
- A concrete fix recommendation per finding.

## Report outcomes

- Violation: the reply broke a rule; backed by a transcript and detector match, human-reviewed.
- Verified pass: a positive check backs the pass (for example, a planted canary was not disclosed).
- No violation found: judged, not verified — no positive check exists for that rule.
- Not assessed: not tested, with the reason stated. Not tested is never counted as a pass.

## How an engagement works

1. Scope and authorize: rules of engagement and written authorization; agreed scope and request limits.
2. Test: automated attacks against the chatbot's endpoint within the agreed limits.
3. Judge and review: an LLM judge, isolated from the attack content, scores each reply against the client's rules; a person reviews the findings.
4. Report: HTML report and JSON export.

## Data handling

Engagement data is processed in the EU only, by processors named in the data processing agreement. Data is pseudonymised, and evidence is deleted when the engagement closes, per the agreed retention. AltaSec issues reports with evidence — never certificates, seals or badges.

## Roadmap (not yet part of an engagement)

- Next: re-testing with fixed / regressed / new comparison; policy conformance checks; scanning system prompts, knowledge bases and training sets for personal data and secrets; multi-turn attacks; testing through a live website chat widget; PDF reports.
- Later: voice agents (web and phone); tool-using agents and MCP.

## FAQ

### What is AI red-teaming?

AI red-teaming means testing an AI system the way real users and attackers will. AltaSec sends jailbreaks, prompt injection and data-extraction attempts to your text chatbot or assistant through its API, checks every reply against your own rules, and delivers an evidence report that also states what could not be tested.

### How is this different from a penetration test?

Classic pentests and scanners look at servers and code. AI red-teaming looks at how a language model behaves when someone talks to it: whether it leaks system prompts, keys or personal data, gets pushed outside its job by prompt injection, or gives answers your own policy forbids.

### What do you need from us?

Your chatbot’s endpoint and your written authorization — no code access. You also tell us in writing what your AI is for and what it must never share or do; we turn that policy into targeted tests.

### What do we get at the end?

An HTML report and a machine-readable JSON export. Each finding comes with its evidence transcript, human review and a concrete fix. The report includes a coverage statement and states its limitations: results are point-in-time and not exhaustive.

### What does “not assessed” mean in the report?

It means a rule could not be tested, and the report says why — for example, the target timed out. Not tested is never counted as a pass, and a pass is only “verified” when a positive check backs it, such as a planted canary that was not disclosed.

### Do you issue a certificate?

No. We issue reports with evidence — never certificates, seals or badges. Results are mapped to GDPR, the EU AI Act and the OWASP Top 10 for LLM Applications as evidence for your own assessment, not as a compliance verdict.

### Where is our data processed?

In the EU only, by processors named in our data processing agreement with you. Your data is pseudonymised, and evidence is deleted when the engagement closes, per the retention we agree with you.

### Which AI systems can you test today?

Text chatbots and AI assistants that we can reach through an API. Testing through a live chat widget on your website and multi-turn attacks are next on our roadmap; voice agents and tool-using agents come later.

## Founders

- Matei Patrascu — Co-founder, Prompt injection. Matei focuses on prompt injection and the adversarial tests AltaSec sends to a chatbot. He is a cloud engineer and studies ICT at Fontys University of Applied Sciences in Eindhoven. LinkedIn: https://www.linkedin.com/in/matei-patrascu
- Afonso Costa — Co-founder, EU AI Act. Afonso focuses on the EU AI Act and on mapping test results to the EU AI Act, GDPR and the OWASP Top 10 for LLM Applications. He studies ICT infrastructure and cybersecurity at Fontys University of Applied Sciences. LinkedIn: https://www.linkedin.com/in/afonso-m-costa
- George Bâtcă — Co-founder, Data leaks. George focuses on data leaks: detecting personal data, secrets and planted canaries in what an AI answers. He studies ICT at Fontys University of Applied Sciences. LinkedIn: https://www.linkedin.com/in/glbatca

The founders won BrabantHack_26 together in the Defence track.

## Contact

Book an AI audit: email contact@alta-sec.com with the subject "AI audit". Tell us which chatbot you want tested and what it is for.
