Howdy,
I’m building PromptBrake, an AI API security testing product for teams at any stage, from founders and security leaders to engineers shipping production systems.
PromptBrake is now live and ready to use: https://promptbrake.com
What it does today:
- Tests AI API endpoints with a fixed library of real attack patterns
- Covers prompt injection, indirect injection, data leakage, tool misuse, and safety bypass behavior
- Returns pass/warn/fail results with evidence and remediation context
How teams use it:
- Pre-release: catch issues before launch
- Post-release: re-test after model, prompt, tool, or config changes
Current scope (MVP):
- Endpoint-focused security testing
- Manual runs
- We’re actively hardening and maintaining reliability
Why I built it:
I kept seeing teams ship AI features fast, but security checks were inconsistent, hard to repeat, or too heavy for day-to-day engineering workflows.
Would value blunt feedback:
- Which failure modes are most painful in your environment?
- What’s the minimum needed for this to fit your release/security process?
- What would block you from trying it first?
Thanks.
Congrats on the launch — looks really solid!
If you’re thinking about validating your idea in a more real way, there’s an interesting setup where you can submit it into a live competition ($19 entry, winner gets a Tokyo trip, prize pool grows with entries).
Might be a fun way to test actual commitment vs just interest.
Great project! I'm also launching LinksWatcher today to help affiliates track 'Zombie Pages' via AI. It's a tough day at #139 but we're hanging in there! Good luck with your growth.
Thanks! Good luck with your journey, too!
Quick follow-up: we published a PromptBrake case study with real scan findings, what was fixed, and the before/after results. Sharing in case it helps anyone hardening LLM endpoints: https://promptbrake.com/case-study/promptbrake-remediation
Really needed, most teams I've talked to treat LLM security as an afterthought. What's been the biggest attack pattern you're seeing in testing so far?
Totally agree, most teams still treat LLM security as a post-launch problem, but it works much better when it’s part of the normal dev workflow from day one. That’s why we built this tool: to make practical LLM security testing easier before issues reach production.
The most common failure pattern is prompt injection escalating into over-permissioned tool use, with data leakage close behind. In practice, the strongest baseline controls are strict tool allowlists, least-privilege access, and server-side guardrails on every tool call.
If useful, we wrote a few practical guides on exactly this: common AI API vuln patterns, secure coding guardrails, and how teams can prioritize fixes without slowing releases
https://promptbrake.com/blog/top-10-ai-api-vulnerabilities
https://promptbrake.com/blog/secure-coding-checklist-for-ai-startups
https://promptbrake.com/blog/how-to-prioritize-ai-security-findings
https://promptbrake.com/blog/monthly-ai-security-review-template