A djinn six® product

ProbeSix™

Sooner or later a regulator, an auditor or a customer will ask how you know your AI is behaving.

A pass or fail from a security tool is not an answer. ProbeSix™ gives you one: evidence of how your AI behaves under attack, mapped to the framework they audit against, in a report you can put on the table.

EU AI Act
ISO/IEC 42001
OWASP LLM Top 10
NIST AI RMF
MITRE ATLAS
DORA

What it costs to have no answer

The question does not go away when it goes unanswered. It gets asked again, by someone more senior.

  • A launch held

    Sign-off waits while someone looks for evidence that was never produced.

  • A finding on the audit

    “AI controls not evidenced” is a line nobody wants in the report to the board.

  • A law with a date on it

    From December 2027 the EU AI Act requires high-risk AI systems to be tested and evidenced before deployment and kept that way through their lifecycle.

  • The quiet one

    Not knowing yourself. Guardrails you have never tested are not evidence.

We were asked the same question

ProbeSix™ is a SaaS platform built by djinn six® after we were asked to provide LLM security assessments for an enterprise AI deployment. We reached for existing tools and found none of them built for the compliance depth the engagement required. ProbeSix™ is what we built instead.

It runs adversarial conversational attacks against your LLM endpoint, probing guardrails under sustained pressure and scores every finding against the exact clause of the framework you answer to: EU AI Act, ISO/IEC 42001, OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS or DORA. You get a security score, a governance posture score and a findings report you can hand to an auditor.

How an engagement runs

Five steps and who does each one. Our consultants do the work the platform cannot, starting with finding the AI you run in the first place.

  1. 1

    Map what you run

    We map the AI you actually run, with you. You cannot secure what you do not know about.

    Our consultants
  2. 2

    Set the target

    Point ProbeSix™ at your endpoint and pick the framework you answer to. It assembles the attack plan.

    Consultants and ProbeSix
  3. 3

    Attack it

    Attack it like a real adversary: single questions, full conversations and everything in between.

    ProbeSix
  4. 4

    Score it

    Score every result against the exact clause of the framework you answer to.

    ProbeSix
  5. 5

    Report and fix

    A report you can hand to your board, your auditor or your regulator. Our consultants work the fixes alongside your engineers.

    Consultants and ProbeSix
Connects to
AWS Bedrock
OpenAI
Anthropic
Meta Llama
Groq
and anything that answers over an HTTPS JSON API, with nothing to install.

What you put on the table

A report you can hand to your board, your auditor or your regulator. Every finding cites the clause it maps to and the report opens with what was tested and what was not. Click a picture to look closer.

The scoring page: overall score, pass and fail counts, vulnerability severities and the threat matrix.
A failed test: the attack prompt, the model's actual response and the evaluation.
The rerun: what regressed, what improved and what stayed the same after a change.

Why the answer holds up

See exactly what changed after a fix

Rerun the same assessment after remediation and the report sets the two runs side by side: what regressed, what improved and what stayed the same, test by test. The evidence is timestamped and usable in an audit.

Pressure that builds across a conversation

Most LLM security tools send single prompts. ProbeSix™ runs adversarial conversational attacks, holding sustained conversations with your model to test whether guardrails hold under real pressure. Guardrails that hold on the first prompt can erode across a session. If your controls degrade, you will see it in the report before your auditors do.

No new attack surface to justify

ProbeSix™ connects to AWS Bedrock, OpenAI, Anthropic, Meta Llama, Groq or anything that answers over an HTTPS JSON API. API keys are encrypted in AWS Secrets Manager and used only at scan time. On AWS Bedrock it assumes a role you grant in your own account so there is no key to hand over. In regulated industries a new credential management requirement is the objection that kills adoption. This removes it.

Next time they ask, hand them the report.

Go straight to probesix.ai or book a call and our consultants will run the first assessment with you.