×

Offer of Free-to-Use yearly license if available to select US businesses only. The Company reserves all rights to accept or reject requests.

WhiteHaX AI Attack Surface Management

Product Datasheet Version 2

WhiteHaX AI-ASM continuously tests deployed generative AI, LLM, RAG, agentic AI, and MCP services for security, compliance, resilience, response time, and cost-amplification risk. It combines adversarial test libraries, customer-specific test generation, repeatable execution, evidence analysis, readiness scoring, and remediation guidance in one operating model.


SecureAI and OptimalAI testing across the deployed AI attack surface

Service area

What WhiteHaX validates

Representative evidence

SecureAI testing

Prompt injection, jailbreaks, data leakage, malicious documents, model behavior, policy failures, API abuse, agent and RAG misuse, and MCP risks.

Failed inputs and outputs, category readiness, proof details, compliance gaps, remediation guidance.

OptimalAI testing

Average and tail response behavior, document and RAG processing, AI-specific load and DoS conditions, resource pressure, token abuse, and cost amplification.

Latency and throughput observations, resilience findings, failed stress cases, scaling and control recommendations.



Current Platform Capabilities

Capability

Version 2 coverage

Endpoint model

AI application or agentic API, first-party or third-party model, MCP server, and regulation-compliance endpoint patterns.

Profiles

Prompts and Docs, AI-specific DoS, AI Model Attack Surface, MCP Attack Surface, Response Time Optimization, and regulation-compliance workflows.

Custom generation

Generate red-team prompts, malicious documents, and regulation-compliance prompt files from approved seed material and example industry prompts.

MCP assurance

Protocol-aware safe checks plus approved intrusive testing. Supports Streamable HTTP, legacy HTTP with SSE, and local stdio transports in the protocol-aware harness.

Automation

Console, REST API, CLI, scheduled operation, and CI/CD patterns, including GitHub and GitLab security workflows.

Outputs

Readiness scores, test evidence, prioritized recommendations, PDF or HTML reporting, normalized JSON, and SARIF conversion for developer security tooling.



Published Scale and Deployment

Category

Specification

Management and execution

Cloud-hosted management with an on-premise WhiteHaX application for Windows, Linux, and macOS, as described on the product website.

Published attack library

1,000,000+ malicious prompts, 5,000+ malicious documents, and hundreds of testing scenarios. The local help reference also exposes a structured 4,648-case prompt-security dataset.

Published execution scale

Hundreds of thousands of unique test cases per hour per target system, subject to target capacity, test design, and authorized operating limits.

Customization

Customer test files, training inputs, request and response adapters, expected-result patterns, test parameters, and custom policy or regulatory cases.


Nine Validation Domains

Domain

Representative checks

Prompt injection and jailbreaks

Direct and indirect injection, hidden intent, backdoor triggers, model hijacking, multi-step attacks, and contextual drift.

Model and user behavior

Model drift, poisoning-style probes, bias and influence attempts, unsafe role changes, and coordinated malicious intent.

Data leakage and output integrity

PII and confidential-data exposure, toxic content, biased output, and unsafe disclosure patterns.

Malicious documents and RAG

Office, PDF, image, QR, embedded-content, metadata, malformed-file, and document-grounded prompt attacks.

LLM API misuse

Malformed requests, token or key abuse, access-right violations, anomalous access patterns, scraping, and exfiltration attempts.

AI-specific DoS and cost

Concurrency, service disruption, context and token overflow, memory pressure, rate-limit bypass, cost amplification, slow requests, burst attacks, and tool-execution abuse.

Policy and compliance

Framework-mapped validation for GDPR, the EU AI Act, OWASP GenAI LLM Top 10, NIST AI RMF, SOC 2, HIPAA, PCI DSS 4.0.1, and customer-defined controls.

Performance and responsiveness

Prompt and document response time, overall performance, response-time profiles, and trend-oriented regression tests.

MCP services

Initialization, discovery, schemas, transports, authentication, pagination, resources, prompts, tools, protocol errors, concurrency, rate limiting, injection, traversal, exfiltration, and abuse.



Regulation Compliance Validation

WhiteHaX executes versioned technical test packs and generates requirement-mapped evidence for the seven frameworks below. Coverage is tailored to the system, organization role, risk classification, jurisdiction, environment, and controls in scope; it supports compliance readiness and audit work but is not legal advice, regulatory approval, SOC 2 attestation, or PCI assessment certification.

Framework

Validation focus

GDPR

Privacy and personal-data handling: minimization, purpose and access boundaries, PII disclosure, retention or deletion behavior, and data-subject workflow tests.

EU AI Act

Role- and risk-class-aware tests supporting risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, and cybersecurity evidence.

OWASP GenAI LLM Top 10

Versioned coverage for the current OWASP GenAI LLM Top 10, including prompt injection, sensitive-data disclosure, unsafe output handling, excessive agency, supply-chain or poisoning risks, and resource abuse.

NIST AI RMF

Evidence organized across Govern, Map, Measure, and Manage, with tests for validity, safety, security, resilience, accountability, transparency, privacy, and harmful-bias risk.

SOC 2

Technical readiness evidence aligned to the applicable Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.

HIPAA

PHI and ePHI leakage, access boundaries, minimum-necessary behavior, integrity, availability, auditability, and administrative or technical safeguard validation relevant to the target.

PCI DSS 4.0.1

Cardholder-data exposure, prompt, output, document, API, identity, logging, and security-control behavior within the assessed AI service and connected workflow.


Evidence Report

Each framework report records scope and framework version; requirement or control mapping; target, model, environment, and profile version; stable test ID and expected behavior; timestamped input and observed response; pass, fail, not tested, or not applicable status; severity and rationale; evidence or artifact reference; remediation owner; exception or compensating control; and retest result, residual risk, and reviewer field.

Figure 1 WhiteHaX validation and remediation loop


Typical Operating Workflow

  1. Define the target endpoint and its request, response, and authentication mapping.
  2. Choose a profile and authorized test pack; separate smoke, safe, intrusive, and high-volume cases.
  3. Run from the console, REST API, CLI, schedule, or CI/CD pipeline.
  4. Review readiness, failed cases, response-time evidence, and remediation guidance.
  5. Fix the application, model, agent, RAG, MCP, API, or surrounding control; then retest and compare.

Target users include security and red teams, AI application developers, product owners, compliance and risk teams, MSSPs, and penetration-testing firms. For trials and current commercial terms, visit www.WhiteHaX.com or contact the WhiteHaX sales team.

Product source: https://ironsdn.com/whitehaxAIASM.html | Partner sources: https://ironsdn.com/mssp.html and https://ironsdn.com/pen_tester.html