Free IDE extension for risk-free vibe coding — keep secrets out of AI.
SoterAI maps its controls to recognised AI and information-security frameworks so security reviewers can evaluate coverage quickly. These pages describe alignment and readiness. They are not certifications, and no external audit opinion is claimed on any page that does not link to a report.
Per-risk mapping from LLM01 prompt injection through LLM10 unbounded consumption, with the specific control that addresses each one.
MappedRead the mappingWhich Trust Services criteria the platform is built toward, and what remains outstanding before an audit opinion could exist.
Readiness onlyRead the mappingInformation-security management practices in place today, stated separately from certification status.
Readiness onlyRead the mappingThe full mapping, including the control behind each row, is on the OWASP LLM Top 10 page.
Input/output guardrails, document scanning, red-team regression tests, and policy enforcement.
PII and secret redaction, safe logs, webhook payload minimization, and audit exports.
Self-hosted deployment guidance, dependency audit checks, and vendor-risk documentation.
RAG quarantine, trust scoring, approved-source indexing, and feedback review.
Unsafe output detection, rewrite/block decisions, and downstream webhook safety.
Policy controls, authorized red-team scope, and integration payload redaction.
System prompt leak detection and persistence safeguards.
Tenant namespaces, ACL post-filtering, and retrieval audit logs.
Grounding guard, citation checks, and no-source fallback.
Rate limiting, quotas, billing controls, and admin overrides.