Comply · Global standards & industry frameworks
OWASP Top 10 for LLM Applications
The top security risks for LLM applications.
The OWASP Top 10 for LLM Applications catalogs the most critical security risks in large-language-model systems — including prompt injection, insecure output handling, training-data poisoning, sensitive-information disclosure, supply-chain vulnerabilities, excessive agency, and overreliance — as a practical checklist for securing AI applications.
Who it applies to
Anyone building, deploying, or securing LLM-powered applications and agents.
Key obligations
- Defend against prompt injection and insecure output handling
- Protect against sensitive-information disclosure and data poisoning
- Constrain excessive agency and tool permissions
- Secure the model supply chain and monitor for misuse
How Maetra maps agents to OWASP LLM Top 10
This is Maetra's Secure module directly: real-time scanning for prompt injection, data exfiltration, and privilege escalation, plus Govern's limits on agent agency for consequential actions.
In practice, Maetra:
- Scans and fingerprints each agent. Discover reads the agent’s code — its tools, data access and sensitivity, actions, model, and environment — into an evidence-backed profile tied to the exact file and commit.
- Decides what applies. That profile determines whether OWASP LLM Top 10 is in scope for the agent and which of its requirements apply.
- Auto-detects controls and surfaces gaps. Controls your code already satisfies are detected automatically from the scan; the rest become a clear list of gaps, each tied to the requirement and the evidence it still needs.
- Proves it and keeps it current. Close gaps with linked evidence or generated documents — reused across every framework the same control supports — and Maetra re-checks on each rescan and flags evidence that has gone stale.
Related frameworks
Prove OWASP LLM Top 10 compliance with Maetra
Classify your AI agents once and Maetra maps them to OWASP LLM Top 10 and every other framework it supports — generating the evidence and documentation, tracking gaps and deadlines, and sealing every decision in an immutable audit trail.