AI Chatbot Security Scanner

Is your AI chatbot easy to jailbreak?

Run OWASP-aligned prompt-injection and jailbreak checks against your chatbot.

OWASP-alignedPass/Fail scorecardAutomated OWASP-aligned scan
Security scorecardscan · support-bot
A−
Mostly resilient

1 medium issue found · 5 checks run

LLM07 System prompt disclosurePASS
LLM01 Prompt injectionPASS
LLM01 Jailbreak / persona bypassPASS
LLM02 Sensitive data exposureREVIEW
LLM05 Unsafe content generationPASS
How it works

Three steps to a security scorecard.

01

Point it at your bot

Give the scanner your chatbot endpoint or widget. Only scan bots you own or are authorized to test.

02

We run OWASP LLM checks

Automated prompt-injection, jailbreak and data-leak probes aligned to the OWASP Top-10 for LLM apps.

03

Get scorecard + fixes

A Pass/Fail report with evidence per finding and plain-language remediation guidance you can act on.

What we check

The risks most chatbots miss.

Checks aligned with the OWASP Top-10 for LLM Applications — the failure modes attackers actually use.

LLM01

Prompt injection

Can a crafted message override your instructions or hijack the bot's behavior?

LLM02

Sensitive info disclosure

Will it reveal secrets, keys, or other users' data when coaxed?

LLM07

System prompt leakage

Can an attacker extract your hidden system prompt and business logic?

LLM06

Excessive agency

Does the bot take actions or call tools it shouldn't be allowed to?

JAILBREAK

Guardrail bypass

Common jailbreak patterns that trick the model past its safety rules.

OUTPUT

Insecure output handling

Unsafe content the bot returns that could break the page consuming it.

Plans

Choose a plan, then request your scan.

Every scan starts with a short authorization request — we verify you own or are allowed to test the target before any payment or scan runs.

Normal

$47 one-time · per scan

A full one-off scan with a shareable report.

  • 5 OWASP LLM checks
  • Pass/Fail scorecard
  • Scan starts automatically after payment
  • Branded PDF audit report
  • Evidence per finding + remediation
Request Normal scan
Most popular

Advanced

$197 one-time

Full coverage with a deeper scan and audit report.

  • Everything in Normal
  • All 10 OWASP LLM categories — 7 tested live, 3 by a control review you complete
  • Extended checks the $47 tier never runs
  • PDF reports emailed automatically
Request Advanced scan
Questions

Straight answers.

Do I need to be technical to run a scan?

No. You point the scanner at your chatbot, it runs the checks, and you get a plain-language Pass/Fail report with fixes. No security background needed.

What is OWASP LLM Top-10?

It's the industry-standard list of the most critical security risks for applications built on large language models — the same failure modes real attackers target.

Why do I have to request a scan first?

Scanning a system you don't own is illegal. Every request is reviewed to confirm you own or are authorized to test the target before any payment link is issued or scan runs — it protects you and us.

What happens after I submit the request?

You'll get an email confirming we received it. After review (usually within one business day) we email you either a secure payment link to proceed, or the reason it wasn't approved — no charge either way until approved.

Can I scan any chatbot?

Only chatbots you own or are explicitly authorized to test. The request form captures that authorization, and every request is reviewed by a human before any scan runs.

What do I actually get?

A branded PDF scorecard with a grade, each check's Pass/Fail status, evidence for every finding, and remediation guidance you can hand to a developer.

The process

Authorization first. Then scan.

A short review step keeps this legal and safe — no payment until your request is approved.

1

Request

Pick a plan and submit the scan request form with your target and authorization.

2

Review

We verify ownership/authorization — manually or automatically — usually within one business day.

3

Approved → pay

You get an email with a secure payment link for your chosen tier to start the scan.

4

Not approved

If we can't verify authorization, you get an email with the reason — and no charge.

Request a scan

Tell us what to scan.

Submitting this request doesn’t charge you. We review every request to confirm you’re authorized to test the target, then email you a payment link (if approved) or the reason it wasn’t.

No charge until approved
Reviewed within 1 business day
Your details stay private
Where you actually live and work — cross-checked against your network location during review.

Paste the address of the page your chat widget appears on — we find the widget automatically. If you already know your bot’s message endpoint (the URL it posts to), you can paste that instead.

How do I find this?
  1. Easiest: paste your website address — we look for the chat widget automatically.
  2. If we cannot find it, you can give us the exact link your chat uses. To get it: open your website in Chrome, press F12 (or right-click → Inspect) and click the Network tab, then send your chatbot a test message. A new row appears — click it and copy the Request URL at the top. That is the link.
  3. Nothing to install, and we never need your passwords or API keys.
Your connectionDetecting…
Target hostingEnter the target URL above
Cover 3 more OWASP categories (optional)

Supply chain, training-data poisoning and vector-store isolation can’t be tested from outside your system. Answer these and we assess them from your answers. They’re reported as self-reported and never counted in your tested score. Skip any you’re unsure of — unanswered is recorded as unknown, never as a pass.

Is the base model pinned to a specific version, rather than tracking a floating latest tag?
Are your application dependencies scanned for known vulnerabilities as part of your build or CI?
Are third-party plugins, tools or agent integrations reviewed before you connect them to the model?
Do you verify the provenance of models and datasets you pull in (signature, checksum, or a trusted registry)?
Are the sources used for fine-tuning or retrieval (RAG) restricted to an approved, tracked list?
Is user-submitted or public content prevented from entering training or retrieval data without review?
Do you run a fixed evaluation set against the model before each deployment to catch behaviour changes?
Are training or retrieval datasets checked for anomalies or unexpected content before use?
If multiple customers or teams share the vector store, is their data isolated from each other?
Is retrieval filtered by the requesting user permissions, rather than searching the whole index?
Are documents cleaned of secrets and personal data before they are embedded?
Have you audited what content is actually retrievable across different user accounts?
Platform terms often require you to notify them before a security test runs on infrastructure they host.
AI Sec Tester runs non-intrusive, read-only checks against your chatbot’s conversational interface only — no exploitation, no infrastructure access, no availability/DoS testing. Because the target and its infrastructure remain under your control, The Souls of AI is not liable for any pre-existing issue, malfunction, downtime or component failure observed during an approved scan. See the full clause in our Terms.
Find out before an attacker does

Scan your chatbot today.

Get a security scorecard and fixes — starting at $47 per scan.

Request a scan

Checks aligned with OWASP Top-10 for LLM Applications. Only scan chatbots you own or are authorized to test.

Chat with us

Ask about scans, tiers & reports

Hi 👋 I'm the AI Sec Tester assistant. Ask me what a scan covers, the tiers and pricing, how to start one, or how to read your report. For anything else, use the message form and a human will reply by email.

AI Sec Tester is for defensive chatbot assessments on systems you own or are explicitly authorized to test. Singapore- and Malaysia-hosted/scoped targets are restricted for penetration-testing services unless handled through the required licensed provider path. Other public-sector, critical-infrastructure, sanctioned, or regulated targets require manual legal review before any paid security work.

AI Sec Tester — Scan your chatbot for prompt-injection flaws