OWASP LLM Top-10 coverage scorecard
Generated from the detectors your policy actually enables, per environment, not a static marketing claim.
Evidence & compliance
Not a claim in a datasheet. The scorecard is derived from the detectors your environment actually has enabled, so it changes when your policy changes, and it is exportable for questionnaires and CISO reviews.
| ID | Risk | Mapped detectors | Coverage | Status |
|---|---|---|---|---|
| LLM01 | Prompt Injection | jailbreak · retrieval_chunk_injection · tool_output_injection | Partial | |
| LLM02 | Sensitive Information Disclosure | pii · secrets · exfiltration · sensitive_business_data | Full | |
| LLM03 | Excessive Agency | excessive_agency · tools | Full | |
| LLM04 | Supply Chain | mcp_manifest_scanner · tools | Partial | |
| LLM05 | Data & Model Poisoning | retrieval_chunk_injection · memory_write_poisoning | Gap | |
| LLM06 | Unbounded Consumption | unbounded_consumption | Full | |
| LLM07 | Misinformation | hallucination · citation_integrity · numerical_consistency | Full | |
| LLM08 | Hidden Context Exposure | system_prompt_leakage · document_metadata_leakage | Partial | |
| LLM09 | Vector & Embedding Weaknesses | embedding_integrity · retrieval_chunk_injection | Full | |
| LLM10 | Improper Output Handling | structure · code_safety · malicious_url | Full |
Coverage reflects implemented detectors mapped to the OWASP Top 10 for LLM Applications (2026 edition). Partial entries indicate risks that ZNYX mitigates but which also depend on controls outside the runtime. LLM05 is a gap: training-data, fine-tune, and model-weight poisoning happen upstream of the runtime and are not addressed by a ZNYX control today.
Artifacts
Generated from the detectors your policy actually enables, per environment, not a static marketing claim.
Precision, recall, F1, AUROC, ECE, and per-language breakdowns for every detector in the bundle.
Fairness and bias model cards plus judge audit events, formatted for AI-governance review.
Every decision, policy version, and judge verdict written as an append-only event with retention controls.
FAQ
How the mapping is built, how coverage is scored, and what it is honest about.
Pull the open-source runtime, drop it into your stack, and start enforcing policy in minutes, free, forever. Add the hosted control plane when you want centralized policies, evidence, traces, and team workflows.