Listing Thumbnail

    djinn six - AI Security & Compliance Assessment

     Info
    Sold by: djinn six 
    Independent security and compliance testing for generative and agentic AI systems running on AWS. We adversarially test your LLMs and AI agents against the OWASP LLM Top 10 and OWASP Agentic AI risks, then map the findings to the EU AI Act, ISO 42001 and NIST AI RMF. You receive a prioritised findings report, a reusable compliance evidence pack and a remediation plan, delivered by an AWS Partner on Amazon Bedrock.

    Overview

    Play video

    Independent AI security and compliance assurance

    djinn six is an AWS Partner specialising in the security, governance and compliance of AI systems. This professional services engagement gives you independent, evidence-based assurance that your generative and agentic AI systems behave within agreed security, governance and regulatory boundaries.

    Built for regulated sectors: designed for AI governance, security and compliance leads in financial services, gaming and other regulated industries who must demonstrate that their AI estate is safe, governed and defensible.

    How we test your AI

    We test your AI the way a real attacker would. Our adversarial assessment includes:

    • Single-turn prompt attacks targeting known vulnerability classes
    • Adaptive multi-turn conversational attacks that chain techniques across sessions
    • Full OWASP LLM Top 10 coverage including prompt injection, data leakage and insecure output handling
    • OWASP Agentic AI risks (ASI-01 to ASI-10) covering tool misuse, agent hijacking and privilege escalation

    Compliance mapping: test once, evidence many

    Findings are translated into compliance evidence mapped to:

    • EU AI Act: risk classification and conformity requirements
    • ISO 42001: AI management system controls
    • NIST AI Risk Management Framework: the govern, map, measure and manage functions

    Evidence is produced once and reused across every framework, so you do not run a separate assessment for each standard.

    What you receive

    • Prioritised findings report: vulnerabilities ranked by severity and exploitability
    • Reusable compliance evidence pack: mapped to all three frameworks, ready for auditors and regulators
    • Remediation plan: actionable guidance your engineering and governance teams can execute immediately

    Engagement lifecycle

    1. Scoping call: we define the AI systems in scope, agree boundaries and confirm access requirements
    2. Adversarial testing: automated and manual attack campaigns run against your AI systems
    3. Analysis and mapping: findings correlated across OWASP categories and mapped to regulatory frameworks
    4. Findings readout: live walkthrough of results with your security and governance stakeholders
    5. Deliverable handover: final report, evidence pack and remediation plan delivered

    AWS integration

    This service relates to AWS artificial intelligence and machine learning services, primarily Amazon Bedrock. We assess the generative and agentic AI workloads that customers run on AWS, including on Amazon Bedrock and Amazon SageMaker AI. The assessment itself is delivered by djinn six on Amazon Bedrock.

    Data safety

    We do not require access to your model weights, your training data or your customer data. We never touch your production data. Our testing interacts only with the inference endpoints you expose, so your production environment stays untouched throughout the engagement.

    Next steps

    To get started, contact the djinn six team through the support details on this listing to scope an assessment and receive a custom private offer.

    Highlights

    • Adversarial red teaming of your LLMs and AI agents: single-turn prompt attacks and adaptive multi-turn conversational attacks against the OWASP LLM Top 10 and OWASP Agentic AI risks (ASI-01 to ASI-10), covering prompt injection, data leakage, tool misuse and agent hijacking.
    • Findings mapped to the EU AI Act, ISO 42001 and the NIST AI Risk Management Framework. A reusable compliance evidence pack is produced once and reused across every framework. Test once and evidence many.
    • Delivered by an AWS Partner on Amazon Bedrock, with no access required to your model weights, training data or customer data. Independent AI security and compliance assurance without exposing your production environment.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Contact

    Support is provided directly by the djinn six team. Email: support@djinnsix.com 

    Response Times

    We respond to all enquiries within one business day, UK business hours (Monday to Friday). Questions about a private offer or proposal are answered within one business week.

    Engagement Support

    Once an engagement is agreed, you receive a named djinn six lead as your single point of contact for the entire assessment. Your lead supports you from the initial scoping call through to findings readout and remediation guidance.

    What Support Covers

    • Scoping and scheduling the assessment
    • Secure access and connectivity setup
    • Interpreting findings and compliance evidence
    • Remediation advice your engineering and governance teams can act on
    • Questions about deliverables, methodology or next steps

    Engagement Timeline

    The assessment follows a structured lifecycle: scoping call, adversarial testing, analysis and compliance mapping, findings readout, and final deliverable handover. Your named lead will confirm milestone dates during the scoping call so your governance and procurement teams can plan internal availability accordingly.

    Refunds and Disputes

    If you have concerns about the service or wish to discuss a refund, contact support@djinnsix.com  and your enquiry will be addressed within one business day.

    Software associated with this service