Fortivra
An AI security discovery and reporting toolkit that gives security leaders evidence-backed visibility into AI systems and the changes needed to secure them. The first release, Fortivra Discover, runs authorized, read-only collection from an approved workstation, jump host, or VPN. It identifies AI assets, data paths, identities, permissions, tool access, secrets exposure, deployment controls, and monitoring gaps, then produces an executive summary, technical findings, evidence, a coverage report, and a prioritized remediation roadmap.
The assessment roadmap uses the OWASP GenAI LLM Top 10 for 2026 as a risk taxonomy, not as a certification. Coverage is being built, evidence first, for prompt injection, sensitive information disclosure, excessive agency, supply chain, data and model poisoning, unbounded consumption, misinformation, hidden context exposure, vector and embedding weaknesses, and improper output handling. Each capability shows what evidence supports a finding, what remains unassessed, and where human review or authorization is required. A control is never reported as effective because configuration metadata exists.