We got tired of watching security teams discover AI vulnerabilities the wrong way.
Orithos is built by security engineers who have been on both sides of an AI security incident — the side that finds the vulnerability during a scan, and the side that finds it during a breach. We built the scanner we needed when we were doing the scanning.
Three things we refuse
to compromise on.
Security tooling earns trust through what it won't do as much as what it will. These are the design constraints we've built Orithos around.
How we designed
the scan engine.
The scan architecture is documented and the probe catalog is public. These are the design decisions that distinguish Orithos from generic LLM security tools.
The attack library
is public. Here's why.
Security through obscurity is not a security model. Our full probe catalog — every payload class, severity, and compliance mapping — is published openly on GitHub under the MIT license, so the security community can audit the methodology, challenge probe design, and verify findings. The catalog is version-controlled and every release is tagged.
Frameworks we build against
and map findings to.
Credibility in security is earned through verifiable mappings, not name-dropping. Every framework below is backed by seeded control data your auditors can inspect.
| Framework / Community | Our role | How Orithos uses it | Status |
|---|---|---|---|
OWASP LLM Top 10 2025 edition | Every catalog probe carries an OWASP LLM mapping; we track the 2026 edition as it develops. | Every finding mapped to the specific OWASP LLM control it violates. Included in all compliance exports. | Mapped |
OWASP Agentic Top 10 ASI01–ASI10 · Dec 2025 | Catalog probes carry OWASP Agentic mappings — goal hijack, tool misuse, privilege abuse, supply chain, memory poisoning, inter-agent, rogue agents. | Agentic control mapping included in all compliance exports and sealed evidence packages. | Mapped |
NIST AI RMF AI RMF 1.0 | Probe catalog mapped to GOVERN, MAP, MEASURE, and MANAGE functions. | NIST AI RMF control mapping included in all compliance exports. | Fully mapped |
EU AI Act Regulation (EU) 2024/1689 | Probes and findings mapped to risk-management, logging, robustness, and adversarial-testing obligations (Articles 9, 12, 15, 55). | Sealed evidence packages with per-artifact SHA-256 hashes and a Merkle root, exportable for conformity conversations with your notified body or auditor. | Mapped |
MITRE ATLAS AI Threat Landscape | Catalog probes carry MITRE ATLAS technique references (AML TTPs). | Findings include ATLAS technique identifiers for threat intelligence integration. | Mapped |
ISO/IEC 42001 AI Management System | Probes carry ISO/IEC 42001 references in their compliance tags; formal Annex A control-mapping coverage is on our roadmap. | 42001-tagged findings appear in compliance exports today; full Annex A coverage planned. | Planned |
SOC 2 / ISO 27001 / HIPAA / GDPR Audit frameworks | Findings map to SOC 2 Trust Services Criteria, ISO 27001, HIPAA Security Rule, and GDPR controls. | Included in compliance exports and sealed evidence packages for auditor consumption. | Fully mapped |
What we commit to
every customer.
Security companies earn trust differently. These are the commitments we make — in writing, not in marketing copy.
Scan your agents before a regulator — or an attacker — does it for you.
Early access spots remain. Security teams that establish their AI agent scanning programme now set the baseline before enforcement begins.