×

Offer of Free-to-Use yearly license if available to select US businesses only. The Company reserves all rights to accept or reject requests.

Frequently Asked Questions (FAQ)

General Questions

A: WhiteHaX Al Readiness Verification Platform is an automated testing platform designed to proactively discover security vulnerabilities, data leakage risks, and compliance gaps in applications built on Large Language Models (LLMs) and Generative Al. It simulates real-world adversarial attacks to help you secure your Al systems before deployment.

A: Its built for:

  • Al Developers & Engineering Teams: To integrate security into their CI/CD pipeline.

  • Security & Red Teams: To perform comprehensive audits and penetration tests on Al endpoints.

  • Compliance & Privacy Officers: To verify adherence to regulations like GDPR, HIPAA, and the OWASP Top-10 for LLMs.

  • Product Leaders: To ensure the Al products they release are safe, trustworthy, and reliable.

  • Traditional SAST/DAST tools are designed for standard web applications. They do not understand novel Al-specific threats like prompt injection, jailbreaks, model poisoning, Al Model-specific attacks or the unique data leakage risks associated with LLMs.
  • Since AI is stateful & remebers context and past details of a conversation, the traditional Web/Application security tools that are designed to test one request – one-response without previous context, can not properly test and validate AI applications and adgents.
  • AI Model response are also non-deterministic (i.e. responses may vary for same prompts) that traditional security testing tools that expect same response/behavior can not validate.
  • Finally, AI security issues are very specific to an AI application or AI agent & therefore there are no specific CVEs or CVSS published vulnerabilities that can be tested, validated and remediated using published methods – which again most traditional Web/App security testing tools rely on.

WhiteHaX Al Readiness Verification Platform is specifically engineered to test & validate the entire Al attack surface and provide specific remediation steps to secure the specific AI App/Agent/Servers using code snippets, regex, 3rd-party security tool configuration and other details.

  1. Malicous Data Insertion Attacks: Direct/indirect prompt injection, jailbreaks, and backdoor triggers, user-behavioral threats etc.
  2. Behavioral Threats: Model drift, poisoning, multi-step attacks, and bias etc.
  3. Data Leakage: PII, confidential data, and toxic output detection etc.
  4. Malicious Documents: Tests malicious PDFs, Office files, images with hidden prompts, and QR codes etc.
  5. API Abuse: Invalid requests, key abuse, anomalous patterns, and access control bypasses, LLM Dos etc.

A: Our threat intelligence team continuously researches the latest adversarial techniques from Security Status open-source communities, academic papers, and real-world incidents. These are systemati-cally curated and added to our automated attack library, which is updated weekly for all customers.

A: Absolutely. While we provide an extensive out-of-the-box library, WhiteHaX Al Readiness Verification Platform allows you to create custom test cases tailored to your specific model's behavior, internal policies, and unique compliance requirements through our API and user-friendly dashboard. You can also provide model training data (in JSON format) which can then be used to create customized benign and malicious data insertion attacks to test your spe-cific Al use-case.

A: We maintain a vast repository of specially crafted malicious files. When you test a document-processing endpoint, WhiteHaX Al Readiness Verification Platform uploads these files—such as PDFs with hidden prompt injections in metadata, Excel files with malicious macros, or images with steganographic payloads—and analyzes your Al's response for any signs of vulnerability or data leakage.

You can also create your own set of malicious docs in many different formats using known malicous links, malicous prompts and other methods to utilize in WhiteHaX testing of you AI Apps or Agents.

A: No. WhiteHaX Al Readiness Verification Platform performs black-box testing exclusively through the API endpoints you expose, just like a real-world attacker would. This requires no internal access to your model, ensuring your intellectual property remains secure.

You can however provide model training data (in JSON format) which can then be used to create benign and malicious data insertion attacks to test your specific Al use-case.

Integration & Deployment Questions

A: WhiteHaX Al Readiness Verification Platform is designed for DevSecOps. It offers:

  • CI/CD Integration: Native plugins for GitHub Actions, GitLab Cl, and Jenkins to run tests automatically on every build.
  • API-First Design: Run tests programmatically as part of your automated workflows.
  • Interactive Application & CLI Tool: For developers to run tests locally from their command line.
  • Scheduled Scans: For compliance teams to run regular audits.

A: We offer flexibility to meet your security needs:

  • SaaS (Cloud-Hosted): Fastest time-to-value, automatically updated.
  • On-Premise: For organizations that require all testing and data to remain within their own private cloud or data center.
  • Hybrid: A combination of both, often with the management console in the cloud and testing engines on-premise.

Compliance & Reporting Questions

A: The platform includes pre-built test suites for:

  • GDPR (PII leakage and right to be forgotten tests)
  • HIPAA (Protected Health Information leakage)
  • OWASP Top-10 for LLM Applications
  • NIST AI RMF (AI Risk Management Framework)
  • EU AI Act (Risk category assessment)
  • The platform also helps generate evidence and reports for auditors.

A: You receive detailed, actionable reports that include:

  • Vulnerability Breakdown: Categorized by type (e.g., OWASP LLM category) and severity (prioritized from Critical to Low).
  • Proof-of-Concept: The exact malicious input that caused the failure and the model's vulnerable output.
  • Remediation Guidance: Concrete steps and best practices to fix the identified issue.
  • Compliance Gap Analysis: A clear view of which regulatory requirements are not being met.

Pricing & Support Questions

A: We typically offer tiered subscription models based on:

  • Number of Al Endpoints tested.
  • Testing Volume (number of tests run per month).
  • Deployment Model (SaaS vs. On-Premise).

We also have a free tier for developers to test a limited number of prompts and a proof-of-concept program for enterprises.

A: All plans include access to our documentation and knowledge base. Higher-tier plans include:

  • Technical Support: 24/7 email support.
  • Dedicated Customer Success Manager: For strategic onboarding and best practices.
  • Professional Services: Custom test case development and in-depth penetration testing engagements.

A: You can start in three ways:

  1. Sign up for a free account on our SaaS platform to test a development endpoint.
  2. Contact our sales team to schedule a live demo and discuss a proof-of-concept for your specific use case.
  3. Download and run our lightweight CLI tool to begin testing locally immediately.