llmaudit.eu

LLM security audit · European Union

Scope an audit

About llmaudit.eu

Updated

llmaudit.eu covers one subject: the security audit of applications built on large language models. Chatbots, retrieval pipelines, copilots and tool-using agents. Readers make procurement and compliance decisions from pages like this one, so the provenance of the guidance is set out in full below.

Publisher

The site is published by SEQ SIA (registration No. 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a provider of penetration testing, red teaming and AI security assessments. Contact: support@offseq.com.

llmaudit.eu is not affiliated with the European Commission, the European AI Office, OWASP, MITRE or NIST. Nothing here is an official interpretation of the AI Act, and nothing here is legal advice.

Authorship

SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than a personal byline, because the testing methodology they describe is the team's methodology. Every guide lists its sources so a reader can check the basis for a claim instead of taking it on trust.

How the guidance is sourced

  • Regulatory statements cite the instrument itself. Dates and article text come from the Official Journal versions of Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 on EUR-Lex, cross-checked against European Commission implementation pages.
  • Risk identifiers come from the published catalogs: the OWASP Top 10 for LLM Applications 2025, the OWASP Top 10 for Agentic Applications 2026, and the MITRE ATLAS data set. We use the official identifiers so a claim of coverage can be checked.
  • Incidents are cited to a primary write-up or an NVD record, with the date and the score as the scoring party published them. Where a vendor and NVD disagree on a CVSS score, both are given.
  • Engagement descriptions are generalized from real work. No client, target environment or unremediated finding is identifiable from anything published here.
  • Numbers we could not verify are left out rather than rounded into a paragraph. There is no market-size statistic and no "average cost of a breach" figure on this site for that reason.
  • The "Updated" date moves only when the text changes. An automated content-hash ledger reverts any date bump the content did not earn.

Commercial interest

We sell the testing this site describes. That is a direct interest in you concluding that you need it, and it should color how you read every recommendation here.

  • Links to OffSeq are our own service links, not a market comparison. We do not rank, score or review competing providers.
  • No vendor, platform, model provider or tool pays for a mention. There is no advertising and no affiliate revenue.
  • Where a smaller engagement, or none, is the right answer, the pages say so. The scope-driver section exists to make an oversized proposal easy to spot, including one of ours.

What this site will not tell you

It will not tell you whether your specific system is high-risk under the AI Act; that is a legal classification that depends on facts we cannot see. It will not certify anything, because no certification scheme for LLM applications exists today. And it will not promise that an audited system cannot be manipulated: prompt injection has no patch, and any page that implies otherwise is selling something.

Corrections

If something here is wrong, out of date or unfair, write to support@offseq.com. Substantive corrections are made in the open and the page is re-dated.