Product Datasheet Version 2
WhiteHaX AI-ASM continuously tests deployed generative AI, LLM, RAG, agentic AI, and MCP services for security, compliance, resilience, response time, and cost-amplification risk. It combines adversarial test libraries, customer-specific test generation, repeatable execution, evidence analysis, readiness scoring, and remediation guidance in one operating model.
SecureAI and OptimalAI testing across the deployed AI attack surface
|
Service area |
What WhiteHaX validates |
Representative evidence |
|---|---|---|
|
SecureAI testing |
Prompt injection, jailbreaks, data leakage, malicious documents, model behavior, policy failures, API abuse, agent and RAG misuse, and MCP risks. |
Failed inputs and outputs, category readiness, proof details, compliance gaps, remediation guidance. |
|
OptimalAI testing |
Average and tail response behavior, document and RAG processing, AI-specific load and DoS conditions, resource pressure, token abuse, and cost amplification. |
Latency and throughput observations, resilience findings, failed stress cases, scaling and control recommendations. |
|
Capability |
Version 2 coverage |
|---|---|
|
Endpoint model |
AI application or agentic API, first-party or third-party model, MCP server, and regulation-compliance endpoint patterns. |
|
Profiles |
Prompts and Docs, AI-specific DoS, AI Model Attack Surface, MCP Attack Surface, Response Time Optimization, and regulation-compliance workflows. |
|
Custom generation |
Generate red-team prompts, malicious documents, and regulation-compliance prompt files from approved seed material and example industry prompts. |
|
MCP assurance |
Protocol-aware safe checks plus approved intrusive testing. Supports Streamable HTTP, legacy HTTP with SSE, and local stdio transports in the protocol-aware harness. |
|
Automation |
Console, REST API, CLI, scheduled operation, and CI/CD patterns, including GitHub and GitLab security workflows. |
|
Outputs |
Readiness scores, test evidence, prioritized recommendations, PDF or HTML reporting, normalized JSON, and SARIF conversion for developer security tooling. |
|
Category |
Specification |
|---|---|
|
Management and execution |
Cloud-hosted management with an on-premise WhiteHaX application for Windows, Linux, and macOS, as described on the product website. |
|
Published attack library |
1,000,000+ malicious prompts, 5,000+ malicious documents, and hundreds of testing scenarios. The local help reference also exposes a structured 4,648-case prompt-security dataset. |
|
Published execution scale |
Hundreds of thousands of unique test cases per hour per target system, subject to target capacity, test design, and authorized operating limits. |
|
Customization |
Customer test files, training inputs, request and response adapters, expected-result patterns, test parameters, and custom policy or regulatory cases. |
|
Domain |
Representative checks |
|---|---|
|
Prompt injection and jailbreaks |
Direct and indirect injection, hidden intent, backdoor triggers, model hijacking, multi-step attacks, and contextual drift. |
|
Model and user behavior |
Model drift, poisoning-style probes, bias and influence attempts, unsafe role changes, and coordinated malicious intent. |
|
Data leakage and output integrity |
PII and confidential-data exposure, toxic content, biased output, and unsafe disclosure patterns. |
|
Malicious documents and RAG |
Office, PDF, image, QR, embedded-content, metadata, malformed-file, and document-grounded prompt attacks. |
|
LLM API misuse |
Malformed requests, token or key abuse, access-right violations, anomalous access patterns, scraping, and exfiltration attempts. |
|
AI-specific DoS and cost |
Concurrency, service disruption, context and token overflow, memory pressure, rate-limit bypass, cost amplification, slow requests, burst attacks, and tool-execution abuse. |
|
Policy and compliance |
Framework-mapped validation for GDPR, the EU AI Act, OWASP GenAI LLM Top 10, NIST AI RMF, SOC 2, HIPAA, PCI DSS 4.0.1, and customer-defined controls. |
|
Performance and responsiveness |
Prompt and document response time, overall performance, response-time profiles, and trend-oriented regression tests. |
|
MCP services |
Initialization, discovery, schemas, transports, authentication, pagination, resources, prompts, tools, protocol errors, concurrency, rate limiting, injection, traversal, exfiltration, and abuse. |
WhiteHaX executes versioned technical test packs and generates requirement-mapped evidence for the seven frameworks below. Coverage is tailored to the system, organization role, risk classification, jurisdiction, environment, and controls in scope; it supports compliance readiness and audit work but is not legal advice, regulatory approval, SOC 2 attestation, or PCI assessment certification.
|
Framework |
Validation focus |
|---|---|
|
GDPR |
Privacy and personal-data handling: minimization, purpose and access boundaries, PII disclosure, retention or deletion behavior, and data-subject workflow tests. |
|
EU AI Act |
Role- and risk-class-aware tests supporting risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, and cybersecurity evidence. |
|
OWASP GenAI LLM Top 10 |
Versioned coverage for the current OWASP GenAI LLM Top 10, including prompt injection, sensitive-data disclosure, unsafe output handling, excessive agency, supply-chain or poisoning risks, and resource abuse. |
|
NIST AI RMF |
Evidence organized across Govern, Map, Measure, and Manage, with tests for validity, safety, security, resilience, accountability, transparency, privacy, and harmful-bias risk. |
|
SOC 2 |
Technical readiness evidence aligned to the applicable Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy. |
|
HIPAA |
PHI and ePHI leakage, access boundaries, minimum-necessary behavior, integrity, availability, auditability, and administrative or technical safeguard validation relevant to the target. |
|
PCI DSS 4.0.1 |
Cardholder-data exposure, prompt, output, document, API, identity, logging, and security-control behavior within the assessed AI service and connected workflow. |
Each framework report records scope and framework version; requirement or control mapping; target, model, environment, and profile version; stable test ID and expected behavior; timestamped input and observed response; pass, fail, not tested, or not applicable status; severity and rationale; evidence or artifact reference; remediation owner; exception or compensating control; and retest result, residual risk, and reviewer field.
Figure 1 WhiteHaX validation and remediation loop
Target users include security and red teams, AI application developers, product owners, compliance and risk teams, MSSPs, and penetration-testing firms. For trials and current commercial terms, visit www.WhiteHaX.com or contact the WhiteHaX sales team.
Product source: https://ironsdn.com/whitehaxAIASM.html | Partner sources: https://ironsdn.com/mssp.html and https://ironsdn.com/pen_tester.html