# AI security self-audit

> Fifteen questions, about five minutes, and nothing leaves your browser. You get a score, a verdict and the fixes for whichever axes you scored worst on.

The checklist is free and there is no email gate: the result appears the moment the fifteenth question is answered. It runs entirely in the browser, so nothing is submitted anywhere unless you decide to get in touch afterwards.

## Five domains

The questions are grouped into data, model, prompt, access and response. Each domain is scored on its own as well as rolled into the overall number, because a system is usually strong on some axes and weak on others rather than uniformly good or bad.

## What it actually asks about

Data classification and PII masking before the model call. Hosting region and whether your contract excludes training. Version pinning against a moving `latest`. Injection testing against the OWASP LLM Top 10. Secrets in system prompts, server-side-only calls, per-user rate and token limits, per-user authorisation on retrieval, and validating responses on the way back out.

## What you get

A weighted score out of a hundred and one of four verdict bands, from critical to strong. Under that, a per-domain breakdown, and a list of next steps generated only for the questions you scored badly on, each labelled with the domain it belongs to.

## Where it stops

It is a self-assessment, so it covers roughly the first tenth of a real audit. It will not threat-model your system or build an eval harness against your own data. It will tell you which of the five axes to look at first, which is usually the question people actually have.

## What to take away

- Fifteen questions, five domains, about five minutes.
- Runs entirely in your browser. No email gate, nothing submitted.
- Scores each domain separately, because systems are rarely uniformly good.
- Covers the first tenth of a real audit, and says which axis to start on.

## Tags

AI security, OWASP LLM, Checklist, Free

## Read the full write-up

https://www.dfieldsolutions.com/tools/ai-security-audit

## We build this for clients

https://dfieldsolutions.com/en/services/cybersecurity

## More from the lab

- https://dfieldsolutions.com/en/lab/dependency-hygiene.md — Your thousand dependencies, audited in an afternoon
- https://dfieldsolutions.com/en/lab/prompt-injection-playbook.md — Prompt injection in production agents
- https://dfieldsolutions.com/en/lab/custom-software-cost.md — What custom software actually costs
- https://dfieldsolutions.com/en/lab/custom-vs-off-the-shelf.md — Custom software or off the shelf — the honest test

---

Source: https://dfieldsolutions.com/en/lab/ai-security-self-audit
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
