LLM security companies, products & suppliers

LLM security focuses on attacks against language-model applications: prompt injection, jailbreaks, insecure output handling and retrieval poisoning. It is a specialist slice of AI security for teams shipping chat, RAG or agents.

What is LLM security?

LLM security focuses on attacks against language-model applications: prompt injection, jailbreaks, insecure output handling and retrieval poisoning. It is a specialist slice of AI security for teams shipping chat, RAG or agents.

What problems does it solve?

Chat and RAG apps can be steered into leaking data or calling tools.

Typical business use cases

  • Pre-production red team
  • Runtime prompt filters
  • Output validation

Important capabilities

  • Jailbreak libraries
  • Policy
  • CI checks
  • Runtime

What buyers should evaluate

  • Attack coverage
  • App-layer vs model-layer
  • False positives

Risks and governance considerations

Only demo-prompt coverage, missing tool-calling attacks.

Procurement checklist

  • Scope of attacks
  • CI integration
  • Prompt data handling

Relevant AI Trustmark assurance

Independent testing still uses the live application, not only a vendor's LLM scanner.

Methodology · How verification works

Companies and providers

Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.

  • A10 offers application security and infrastructure solutions to help you build high-performance, AI-ready infrastructure for mission-critical apps and networks. A10 Networks publis

  • CalypsoAI markets LLM/AI security and control tooling for enterprises adopting generative AI safely. CalypsoAI is used for LLM security work. CalypsoAI is recorded in United States

  • Cisco is a worldwide technology leader powering an inclusive future for all. Learn more about our products, services, solutions, and innovations. Cisco publishes Galileo and Cisco

  • Secure AI agents with Giskard’s continuous AI red teaming. Detect vulnerabilities, improve LLM security, and safeguard your AI systems. Giskard publishes Giskard Guards, Giskard Hu

  • Secure your AI with HiddenLayer’s end-to-end platform that detects threats, protects models, and ensures safe, compliant AI adoption at scale. HiddenLayer, Inc. trades as HiddenLay

  • Knostic provides enterprise-grade governance, visibility, and real-time protection across users, data, and AI tools. Knostic is used for LLM security work. Knostic is recorded in U

  • The AI-native security platform to accelerate GenAI initiatives—trusted by Fortune 500s, backed by the world’s largest AI red team. Lakera publishes Lakera Guard as named AI produc

  • Lasso’s AI Security Platform gives enterprises visibility, control, and protection across AI models, agents, and apps. Lasso Security Ltd..security, LLM security. Lasso Security pu

  • Protect your AI Agents and Applications from attacks, hallucinations and data leakages with our AI native entreprise-grade cybersecurity solutions. NeuralTrust publishes TrustTest,

  • NVIDIA sells GPUs, CUDA software and AI enterprise stacks used for training and inference. Public pages cover data-centre, cloud and on-prem AI compute. NVIDIA publishes NVIDIA cuO

  • Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’

  • Open-source tools, research, analysis, and guidance to understand and respond to AI threats. Prompt Security publishes Prompt Security Automated AI Red Teaming and Prompt Security

  • Proofpoint helps protect people, data and brands against cyberattacks. Offering compliance and cybersecurity solutions for email, web, cloud and more. Proofpoint publishes Proofpoi

  • Protecto is the AI Data Control Plane for agentic AI. Detect, mask, and control sensitive data before it reaches any LLM, agent, or MCP tool. Protecto publishes Protecto AI as name

  • Straiker detects prompt injection, tool misuse, and runtime attacks across every AI agent you build or deploy, with 98.1% threat detection accuracy. Straiker publishes Straiker ASC

Products

Claimed products appear first. Ranking packs and payment do not change this list.

Also used in this category

These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.

Related categories

Relevant procurement and assurance guides

Frequently asked questions

Does this replace AppSec?

No. It complements it for LLM-specific failures.

What is LLM security?

LLM security focuses on attacks against language-model applications: prompt injection, jailbreaks, insecure output handling and retrieval poisoning. It is a specialist slice of AI security for teams shipping chat, RAG or agents.

How should prompt injection and tool-output attacks be controlled?

Agents that read untrusted content or tool output can be instructed to exfiltrate data or take writes. Buyers should ask what is treated as untrusted, whether tool output can change the plan, and what tests were run. Scanner marketing is not the same as independent testing.

What security testing evidence should buyers request for an AI product?

Ask what was tested, against which version, whether prompt-injection, data-exfiltration and tenant isolation were in scope, and where failed prompts were stored. A generic ISO certificate or a vendor scanner screenshot is not by itself an AI TrustMark assessment.

What model or provider changes should a buyer insist on being told about?

Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.

How should buyers verify where AI customer data is processed?

Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.

Does a TrustMark on one product cover the rest of the company?

No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.

What incident-handling evidence is useful for AI suppliers?

Buyers should see how AI-specific failures are detected, contained and notified — including unsafe outputs, data leakage and unauthorised agent actions. An incident policy that never mentions models, prompts or tools is incomplete for this class of product.