Vulnerability Assessment for AI Security Testing
VAAST is the offensive-security platform for LLM-integrated applications. Map the surface, run the catalog, ship the findings.
Capabilities
Everything the attack surface demands.
Prompt Injection Catalog
Direct, indirect, and multi-turn variants with reproducible payloads. Covers system-prompt exfiltration, jailbreaks, and role-confusion attacks.
Tool-Call Surface Mapping
Enumerates every tool the agent can call, then probes parameter-injection and unauthorized state changes across them.
RAG Corpus Inspection
Walks ingestion paths, tests for poisoned documents, and verifies retrieval behavior under adversarial queries.
Agentic Pipeline Tracing
Models plan-and-execute loops and long-horizon agents, then surfaces failure modes unique to autonomous workflows.
Authenticated Scanning
Run the catalog behind API key, Bearer, or Cookie authentication so you can test what your users actually see.
Reproducible Findings
Every finding exports as a minimal script your engineering team can replay in CI. No black-box claims.
Workflow
How an engagement runs.
Define scope
Register the target application with written authorization. VAAST will refuse to run without it.
Enumerate surface
Map tool calls, retrieval sources, and agent pipelines. VAAST produces a surface graph you can export.
Probe and report
Run the vulnerability catalog. Every finding is triaged, tagged, and exportable as a CI-runnable script.
Demo
See it in action.
Real scans. Real findings. No setup required.

Pricing
Start free. Upgrade when you need depth.
Every tier includes the baseline payload library. Pro and Enterprise unlock live research sync, full report export, and authenticated scanning.
Kick the tires on VAAST.
- VAAST desktop app (Mac, Windows, Linux)
- Baseline payload library (15 checks)
- Prompt injection, tool-call, RAG, agentic categories
- Local scan history and workspaces
- JSON findings export
- Community research feed access
For individual practitioners.
- Everything in Free
- Live payload library sync (new research checks as published)
- Full report export (HTML + JSON)
- Authenticated scanning (API key, Bearer, Cookie)
- Direct email support
For teams running VAAST together.
- Everything in Pro
- Up to 10 seats under one org
- Centralized license management
- Team workspace sync
- CI/CD headless scan mode
- Onboarding call included