Testing your chatbot yourself vs. running a scan — the honest trade-off.
You genuinely can check most of the OWASP LLM Top 10 by hand, for free, this afternoon. This page tells you exactly what that buys you, what it doesn't, and the specific reason a buyer, auditor or investor usually wants more than "I tried some prompts and it seemed fine."
Check your inbox!
Your Starter Map is on its way. If it doesn't arrive in a minute, check spam.
What DIY testing gets you — and where it stops.
| DIY (by hand) | AI Sec Tester scan | |
|---|---|---|
| Cost | Free | $47 or $197, one-time |
| Time required | 30–90 minutes of your own time, per test round | Minutes, once approved and paid |
| Categories you can realistically self-test | Prompt injection, jailbreak, system-prompt leakage — the ones a normal person can probe by typing prompts | All 10 OWASP LLM Top-10 categories on the Advanced tier — including 3 that need internal/architecture review, not just chat probing |
| Repeatable evidence | None by default — a screenshot if you remember to take one | Evidence captured per finding (the probe and the response) in every report |
| Something to show a buyer, auditor or investor | No structured deliverable | Branded PDF, Pass/Fail scorecard, remediation notes |
| Requires security background | No — that's the point | No — plain-language remediation, no security background needed to act on it |
Do the DIY pass first. Seriously.
If you haven't run a single prompt-injection test on your own chatbot, start there — it's free, it takes under an hour, and it will catch the most obvious failures immediately. We wrote the exact copy-pasteable test list here. Don't pay for anything until you've done that.
Where DIY runs out of road
Three of the ten OWASP LLM Top-10 categories — supply chain risk (LLM03), training-data/model poisoning (LLM04), and vector/embedding weaknesses (LLM08) — aren't things you can probe by typing messages into a chat window. They're architecture and data-pipeline questions, and they need a structured review, not a clever prompt. That's the honest boundary of what DIY testing alone can cover.
The other gap is evidence. A DIY pass tells you what you found. It doesn't produce anything you can hand to a customer's security team, an auditor, or an investor doing diligence — no dated report, no captured evidence per finding, no scorecard. If you need a receipt, not just a personal check, that's what a scan buys you.
Can I really check the OWASP LLM Top 10 myself for free?
Most of it, yes. The prompt-injection, jailbreak and system-prompt-disclosure categories are testable by hand — see the copy-pasteable prompt list on our DIY page. The 3 categories that touch supply chain, training data and vector-store architecture need an internal review instead.
What does the scan add that DIY testing doesn't?
Structured coverage of all 10 categories (Advanced tier), captured evidence per finding, plain-language remediation, and a PDF report you can actually hand to someone else.
What's the price difference between tiers?
$47 (Normal) runs 5 core checks. $197 (Advanced) covers all 10 OWASP LLM Top-10 categories across 15 checks total. See the full breakdown on the cost page.
Run the free checklist. Scan when you need proof.
Normal $47 or Advanced $197, one-time. No charge until your request is reviewed and approved.