Full Platform Coverage

Full Platform Coverage

Every TrustTrace finding maps to OWASP LLM Top 10, the CoSAI threat taxonomy, and your compliance framework. Your security team always knows what to fix and why it matters.

Industry Framework

OWASP LLM Top 10 Aligned

TrustTrace maps every finding to the OWASP LLM Top 10, the definitive framework for AI and LLM security risk. Every rule in our library is tagged to its corresponding OWASP category so your security team always knows the risk context behind each finding.

View the OWASP LLM Top 10
Coverage Matrix

From capability to framework, mapped.

CapabilityRulesOWASP CategoriesCoSAIFrameworks
DiscoveryTT-DISC-001LLM03T11, IICSOC 2
Agent Posture33LLM01 to LLM10T1 to T3, T9, T10HIPAA, SOC 2
MCP Protocol14LLM01, 02, 03, 06, 08, 09T4, T7, T8, T11, T12CoSAI
Secrets & CredsTT-SEC-001LLM02T5HIPAA, SOC 2
Transport SecurityTT-SEC-002 / 003LLM08T7SOC 2
Supply ChainTT-MCP-013 / 014 / 021LLM03T11SOC 2
Continuous MonitoringScheduledAllAllAll
OWASP LLM Top 10

Full coverage of every category, with rules mapped per finding.

LLM018 rules

Prompt Injection

Direct and indirect injection via untrusted inputs and tool descriptions.

LLM026 rules

Sensitive Information Disclosure

Hardcoded secrets, PII exposure, and credential leakage in agent contexts.

LLM035 rules

Supply Chain

MCP server provenance, dependency integrity, and model artifact verification.

LLM043 rules

Data and Model Poisoning

Tool definition tampering and training data integrity checks.

LLM053 rules

Improper Output Handling

Unsanitized agent output reaching downstream systems.

LLM067 rules

Excessive Agency

Autonomy classification, tool scoping, and privilege boundary review.

LLM072 rules

System Prompt Leakage

System prompt extraction risk and disclosure of operational instructions.

LLM084 rules

Vector and Embedding Weaknesses

RAG injection, embedding inversion, and TLS for retrieval channels.

LLM093 rules

Misinformation

Hallucination guardrails, citation verification, and grounding controls.

LLM105 rules

Unbounded Consumption

Resource limits, cost controls, and denial-of-wallet detection.

Discovery

Agent and MCP Server Discovery

TrustTrace finds AI agents and MCP servers you did not know existed. The discovery scanner walks your codebase and identifies MCP configuration files, agent framework imports, tool definitions, and LLM instantiations across Python codebases. Discovered assets feed directly into the assessment pipeline so nothing is assessed in isolation.

Detected frameworks: LangChain, AutoGen, CrewAI, OpenAI Assistants, Anthropic agents, FastAPI agent patterns.

Detected config formats: mcp.json, claude_desktop_config.json, mcp-config.yaml, and 8 additional MCP configuration patterns.

Read the discovery docs
CoSAI Alignment

TrustTrace is aligned with the CoSAI January 2026 MCP Security whitepaper threat taxonomy, published by a working group including Anthropic, Google, IBM, Microsoft, and NVIDIA.

CoSAI MCP Security whitepaper

Framework Alignment

HIPAASOC 2OWASP LLM Top 10

Ready to map your AI security posture?