Questions, answered
Know what happens before testing begins.
Clear answers about scope, access, evidence, reporting, timing, and the founding pilot.
Assessment basics
Assessment basics
What exactly does Aspexa test?
Aspexa tests the AI application layer around the model: instructions, retrieval, user roles, tools, memory, policies, and generated outputs. The exact lanes depend on the approved workflow.
Is this a traditional penetration test?
No. It is an authorized AI assurance assessment focused on AI-specific trust boundaries. Conventional web, API, infrastructure, or cloud testing is included only when it is explicitly scoped.
Do you only run automated scans?
No. Structured test packs expand coverage, but important findings are manually validated and rewritten with evidence, impact, mitigation, and retest criteria.
Can you test Arabic or bilingual systems?
Yes. Arabic, dialect, transliteration, bilingual instruction, and RTL/LTR cases can be added when they are relevant to the target system.
Scope & access
Scope & access
What access do you need?
A test account or API path is preferred. Roles, data boundaries, rate limits, exclusions, and testing windows are agreed before any testing begins.
Can you test a third-party AI system for us?
Only when the system owner has provided clear authorization and the test boundary is documented. Aspexa does not test public or third-party systems without permission.
Do you need our source code?
Not always. Many assessments can begin through a test account or API. Architecture details, logs, or source access may improve depth when the client chooses to include them.
Evidence & reporting
Evidence & reporting
What is included in the report?
The report includes an executive summary, validated findings, test inputs, observed responses, evidence, severity and confidence, business impact, mitigation guidance, and retest criteria.
Do findings map to OWASP guidance?
Applicable findings can be mapped to relevant OWASP LLM guidance as a reporting aid. A mapping is not a certification or a compliance guarantee.
Will the report expose your internal tools?
No. Client deliverables focus on tested behavior, evidence, risk, and remediation. Internal tooling is not part of the client-facing report.
Commercial
Commercial
How long does the pilot take?
The founding pilot is designed for five business days after access, scope, and authorization are ready. A larger or more complex boundary requires a separate timeline.
How much does the pilot cost?
The standard pilot starts at USD 5,000. Approved design partners receive a limited USD 2,500 rate. Final pricing depends on roles, integrations, access, and the approved test boundary.
Is a retest included?
Yes. The pilot includes one focused retest of agreed findings after the client has implemented the remediation.
