LLM applications fail on prompt injection, leakage, jailbreaks, and supply-chain components you did not write. OptimaTrust assessments target a stored HTTP API. Security and red-team labs (Garak, PyRIT, promptfoo, DeepEval, Giskard) run when installed. A marketing website is not a model API and is marked not applicable. Scores list deductions. Empty dimensions stay NOT_ASSESSED.
What you get
- OWASP LLM-aligned test classes
- Explainable eleven-dimension score
- Evidence hashed for auditors who will ask how you tested
