Developer docs
API playgroundTry for free, no card

Search company profiles

OWASP GenAI Security Project

Full company profile

uuid00qf3z8

Namestring
OWASP GenAI Security Project
Legal namestring
OWASP Foundation, Inc.
Websiteurl
genai.owasp.org
Company typeenum
Private
Founded yearint
2023
Descriptiontext

The OWASP GenAI Security Project is a global, open-source, community-driven initiative operated under the OWASP Foundation, a 501(c)(3) nonprofit. Founded in May 2023 as the OWASP Top 10 for LLM Application Security Project, it identifies, documents, and mitigates security and safety risks for Generative AI and LLM applications across the development, deployment, and management lifecycle. Its core deliverables are two peer-reviewed risk frameworks — the OWASP Top 10 for LLM Applications (updated annually, with a 2025 edition and an earlier 2023/24 edition) and the OWASP Top 10 for Agentic Applications 2026 — alongside a portfolio of 45+ publications including red teaming guides, incident response playbooks, the LLM Applications Cybersecurity and Governance Checklist, the State of Agentic AI Security and Governance report, and the AI Security Solutions Landscape. Supporting tooling includes the open-source AIBOM Generator (AI Bill of Materials), the Threat Defense COMPASS dashboard, the FinBot CTF training environment, and the AIUC-1 Crosswalk reference document.

The project's distribution model is entirely free: all content is published under Creative Commons Attribution-ShareAlike 4.0 and code under MIT/Apache 2.0/BSD licenses, delivered through the project website (genai.owasp.org), GitHub repositories, Slack workspace, YouTube channel, Beehiiv newsletter, Spotify/Apple podcasts, and presence at major security conferences including RSAC, Black Hat, Infosecurity Europe, and DEFCON. It serves security professionals, CISOs and executive leadership, AI/ML engineers and developers, and enterprises adopting generative AI, with secondary reach into policymakers and academic institutions. The project does not sell products or services; the sole revenue channel is corporate sponsorship at Gold and Silver tiers, which is explicitly stated not to influence project governance.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
51–100
akta.pro rankint
HeadquartersWakefield, United States
HQ citystring
Wakefield
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Keyword5 values
LLM security frameworks, AI security governance, Agentic AI security, AI red teaming, Generative AI risk management
Industry2 codes
1Threat Intelligence Services
CodeBPAEADACPrimaryYes
2Secure Model Deployment & Runtime Protection (sandboxing, isolation)
CodeHDAAAKAHPrimaryNo
NAICS code2 codes
  • Computer Systems Design and Related Services5415
  • Other Computer Related Services541519
SIC code1 code
  • Services-Prepackaged Software7372
Product category
AI Security Frameworks and Open-Source Guidance
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model1 record
1Sponsorship and Donations
TypeLicensing Royalties
Description

The OWASP GenAI Security Project is a non-profit volunteer effort. Revenue is generated through corporate sponsorship at Gold and Silver tiers, which helps cover resources, operations, outreach, and education costs. Sponsorship does not impact project governance, which remains open and unbiased. The OWASP Foundation provides operational resources but these are limited.

genai.owasp.org
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components6 values
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

The OWASP GenAI Security Project is an open-source initiative that produces peer-reviewed security frameworks, guides, tools, and threat intelligence for understanding and mitigating security and safety risks in Generative AI and LLM applications. Core deliverables include the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications risk frameworks, the AIBOM Generator open-source tool, the AI Security Solutions Landscape directory, the Threat Defense COMPASS, and various cheat sheets and red teaming guides — all distributed free of charge under open-source licenses.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 45+ publications produced covering AI security risks, mitigations, governance, and tooling
+3 more records
Product overview1 text field

The OWASP GenAI Security Project is a global, open-source community-driven initiative that produces freely available guidance, frameworks, tools, and resources for understanding and mitigating security and safety concerns for Generative AI applications. The portfolio is organized as a platform of interconnected resources anchored by the core OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications — peer-reviewed risk frameworks that serve as the foundation for all other offerings. Supporting these core products are specialized guides (GenAI Incident Response Guide, Securing Agentic Applications Guide, GenAI Red Teaming Guide), tools (OWASP AIBOM Generator, OWASP GenAI Security Project Threat Defense COMPASS, FinBot CTF Application), solution landscapes (AI Security Solutions Landscape), checklists (LLM Applications Cybersecurity and Governance Checklist), and threat intelligence resources. All outputs are open-source and licensed under Creative Commons Attribution-ShareAlike 4.0.

Product and service18 records
1OWASP Top 10 for LLM Applications
CategoryAI Security Framework
Description

Globally peer-reviewed framework documenting the most critical security risks for Large Language Model applications across the development, deployment, and management lifecycle.

2OWASP Top 10 for Agentic Applications
CategoryAI Security Framework
Description

Globally peer-reviewed framework identifying the most critical security risks facing autonomous and agentic AI systems.

3OWASP AIBOM Generator
CategoryOpen-Source Tool
Description

Open-source tool designed to enhance AI supply chain transparency and security by generating AI Bills of Materials (AIBOMs / AI SBOMs).

4AI Security Solutions Landscape
CategoryResource Directory
Description

Quarterly updated resource cataloging tools and frameworks for mitigating AI security risks, aligned to OWASP Top 10 risks and the LLMSecOps lifecycle.

5OWASP GenAI Security Project Threat Defense COMPASS
CategoryOpen-Source Tool
Description

Tool consolidating AI threats, vulnerabilities, defenses, and mitigations into a unified AI Threat Resilience Strategy Dashboard.

6LLM Applications Cybersecurity and Governance Checklist
CategoryGovernance Checklist
Description

Checklist for leaders across executive, tech, cybersecurity, privacy, compliance, and legal areas providing structured guidance for AI security programs.

7GenAI Incident Response Guide
CategoryGuide
Description

Comprehensive guide providing security practitioners with guidelines and best practices for responding to security incidents involving GenAI applications.

8Gen AI Red Teaming Guide
CategoryGuide
Description

Comprehensive guide outlining critical components of GenAI Red Teaming with actionable insights for cybersecurity professionals, AI/ML engineers, and Red Team practitioners.

9Securing Agentic Applications Guide
CategoryGuide
Description

Practical and actionable guidance for designing, developing, and deploying secure agentic applications powered by LLMs.

10State of Agentic AI Security and Governance
CategoryResearch Report
Description

Comprehensive report providing view of the landscape for securing and governing autonomous AI systems, exploring frameworks, governance models, and global regulatory standards.

11Agentic AI – Threats and Mitigations
CategoryReference Document
Description

Comprehensive documentation of threats and mitigations specific to agentic systems utilizing advanced frameworks (LangGraph, AutoGPT, CrewAI).

12OWASP GenAI Data Security Risks & Mitigations
CategoryGuide
Description

Forward-looking analysis of unique data security challenges posed by rapid adoption of Generative AI across enterprise environments.

13AIUC-1: Crosswalks OWASP Top 10 For Agentic Applications
CategoryReference Document
Description

Bidirectional mapping between AIUC-1 requirements and the OWASP Agentic Security Initiative's Top 10 risks for autonomous and agentic AI systems.

14FinBot CTF Application
CategoryTraining Tool
Description

Hands-on Capture-The-Flag environment built around a simulated financial services application for understanding and mitigating agentic AI risks.

15OWASP Vendor Evaluation Criteria for AI Red Teaming Providers & Tooling
CategoryEvaluation Framework
Description

Practical guide for organizations assessing vendors offering AI red teaming services or automated testing tools.

16CheatSheet – A Practical Guide for Securely Using Third-Party MCP Servers
CategoryCheat Sheet
Description

Detailed framework for safely deploying and managing external Model Context Protocol (MCP) servers.

17A Practical Guide for Secure MCP Server Development
CategoryGuide
Description

Actionable guidance for securing Model Context Protocol (MCP) servers — the critical connection point between AI assistants and external tools, APIs, and data sources.

18Agentic AI Security Initiative
CategoryInitiative / Research Program
Description

Initiative dedicated to securing autonomous AI systems and agent-based LLM applications, including frameworks, guides, and threat research.

Scale indicator9 records

Each record includes

Type, Value, Description, Source

Partnership8 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-04-17
Description

Co-development of the 'AI Vulnerability Storm' report with contributions from over 250 CISOs. The report warns that Anthropic's Mythos AI will significantly accelerate vulnerability discovery and exploitation. Provides risk registers, priority actions, and board briefing materials.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-04-17
Description

Co-development partner in the 'AI Vulnerability Storm' report. Contributes cybersecurity expertise and industry perspective to AI security risk analysis and recommendations.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-04-17
Description

Co-development partner in the 'AI Vulnerability Storm' report focused on AI security threats and organizational preparedness guidance.

Strategic tierMinorTypeGTM or Marketing PartnerAnnounced on2025-06-30
Description

Strategic partnership to advance application security and AI education across the cyber ecosystem. Joint efforts in educational content, webinars, and industry outreach.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Formal collaboration with MITRE on AI security research and framework alignment. MITRE's expertise in security standards contributes to the project's research rigor and alignment with industry needs.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Formal collaboration with NIST on AI security standards and research. NIST contributions include expert participation in reports like the 'AI Vulnerability Storm' analysis. Project maintains mappings between OWASP Top 10 and NIST frameworks.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Formal collaboration with UK government entities on AI security policy and guidance alignment. Supports the project's goal of regulatory alignment across jurisdictions.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Collaboration with various Linux Foundation projects on AI security standards and open-source security tooling. Ensures alignment with open-source ecosystem standards and practices.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

A multi-stakeholder nonprofit producing AI best practices, research, and safety guidance across industry, academia, and civil society. Operates as an open-source standards and research body with comparable scope to OWASP's governance and frameworks work.

TypeBroad incumbent
Description

The UK government's AI Safety Institute conducts AI security and safety evaluations and publishes research. A formal OWASP collaborator with regulatory authority and government backing for AI security standards.

TypeEmerging player
Description

A commercial AI security startup providing adversarial ML and LLM threat detection products. Both organizations work on AI/ML security threats, and HiddenLayer is an OWASP partner and sponsor operating in adjacent commercial territory.

TypeDirect peer
Description

CSA's AI Safety Initiative and related working groups produce open-source AI security frameworks, whitepapers, and training. CSA co-developed the 'AI Vulnerability Storm' report with OWASP, indicating direct coordination on AI security standards.

TypeOthers
Description

The parent nonprofit foundation that hosts the OWASP GenAI Security Project. While not a direct competitor, OWASP's broader portfolio (Top 10 Web, Top 10 API, Top 10 Mobile) shares the same community-driven, open-source security standards model and provides governance infrastructure.

6AI Incident Database
TypeDirect peer
Description

An open-source, community-driven database cataloging AI-related harms and incidents. Comparable in spirit to OWASP's threat intelligence efforts and serves as a complementary data source for AI security research and framework development.

TypeBroad incumbent
Description

EU's cybersecurity agency producing AI security guidance and frameworks including the EU AI Act implementation support. Comparable as a standards-producing body with broader regulatory influence than voluntary frameworks.

TypeEmerging player
Description

A GenAI security startup focused on LLM protection and compliance. Both address LLM security risks with overlapping audience (CISOs, security teams), and Lasso is an OWASP sponsor citing the Top 10 for LLMs in product literature.

TypeBroad incumbent
Description

NIST's AI RMF and related generative AI profile (NIST AI 600-1) provide authoritative AI risk guidance. As a US federal standards body, NIST carries regulatory weight that OWASP lacks, and the two maintain formal mapping relationships.

TypeDirect peer
Description

MITRE's Adversarial Threat Landscape for AI-Enabled Systems is a directly comparable knowledge base cataloging AI/ML threats, mitigations, and case studies. Both projects operate as open-source, expert-driven AI security references, and they maintain formal alignment collaborations.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers8 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment6 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature8 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles12 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

OWASP GenAI Security Project

AI Security Frameworks and Open-Source Guidancegenai.owasp.org

What OWASP GenAI Security Project does

The OWASP GenAI Security Project is a global, open-source, community-driven initiative operated under the OWASP Foundation, a 501(c)(3) nonprofit. Founded in May 2023 as the OWASP Top 10 for LLM Application Security Project, it identifies, documents, and mitigates security and safety risks for Generative AI and LLM applications across the development, deployment, and management lifecycle. Its core deliverables are two peer-reviewed risk frameworks — the OWASP Top 10 for LLM Applications (updated annually, with a 2025 edition and an earlier 2023/24 edition) and the OWASP Top 10 for Agentic Applications 2026 — alongside a portfolio of 45+ publications including red teaming guides, incident response playbooks, the LLM Applications Cybersecurity and Governance Checklist, the State of Agentic AI Security and Governance report, and the AI Security Solutions Landscape. Supporting tooling includes the open-source AIBOM Generator (AI Bill of Materials), the Threat Defense COMPASS dashboard, the FinBot CTF training environment, and the AIUC-1 Crosswalk reference document.

The project's distribution model is entirely free: all content is published under Creative Commons Attribution-ShareAlike 4.0 and code under MIT/Apache 2.0/BSD licenses, delivered through the project website (genai.owasp.org), GitHub repositories, Slack workspace, YouTube channel, Beehiiv newsletter, Spotify/Apple podcasts, and presence at major security conferences including RSAC, Black Hat, Infosecurity Europe, and DEFCON. It serves security professionals, CISOs and executive leadership, AI/ML engineers and developers, and enterprises adopting generative AI, with secondary reach into policymakers and academic institutions. The project does not sell products or services; the sole revenue channel is corporate sponsorship at Gold and Silver tiers, which is explicitly stated not to influence project governance.

OWASP GenAI Security Project firmographics

Firmographics
Name
OWASP GenAI Security Project
Legal name
OWASP Foundation, Inc.
Website
https://genai.owasp.org
Company type
Private
Founded year
2023
Operating status
Operating
Headcount range
51–100 employees
Ownership category
akta.pro rank

OWASP GenAI Security Project industry classification

Industry
Product category
AI Security Frameworks and Open-Source Guidance
NAICS
Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
SIC
Services-Prepackaged Software (7372)
akta.pro primary industry
Threat Intelligence Services (BPAEADAC)
akta.pro secondary industry
Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)

Keywords

  • LLM security frameworks
  • AI security governance
  • Agentic AI security
  • AI red teaming
  • Generative AI risk management

Where OWASP GenAI Security Project is headquartered

Location

Headquarters

HQ city
Wakefield
HQ country
United States
HQ region
North America

Markets served

OWASP GenAI Security Project business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others

Revenue model

  1. Sponsorship and Donations: The OWASP GenAI Security Project is a non-profit volunteer effort. Revenue is generated through corporate sponsorship at Gold and Silver tiers, which helps cover resources, operations, outreach, and education costs. Sponsorship does not impact project governance, which remains open and unbiased. The OWASP Foundation provides operational resources but these are limited.

Go-to-market motion2 records

Distribution channels3 records

Marketing channels9 records

OWASP GenAI Security Project product offering

Product offering

Core offering

The OWASP GenAI Security Project is an open-source initiative that produces peer-reviewed security frameworks, guides, tools, and threat intelligence for understanding and mitigating security and safety risks in Generative AI and LLM applications. Core deliverables include the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications risk frameworks, the AIBOM Generator open-source tool, the AI Security Solutions Landscape directory, the Threat Defense COMPASS, and various cheat sheets and red teaming guides — all distributed free of charge under open-source licenses.

Product overview

The OWASP GenAI Security Project is a global, open-source community-driven initiative that produces freely available guidance, frameworks, tools, and resources for understanding and mitigating security and safety concerns for Generative AI applications. The portfolio is organized as a platform of interconnected resources anchored by the core OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications — peer-reviewed risk frameworks that serve as the foundation for all other offerings. Supporting these core products are specialized guides (GenAI Incident Response Guide, Securing Agentic Applications Guide, GenAI Red Teaming Guide), tools (OWASP AIBOM Generator, OWASP GenAI Security Project Threat Defense COMPASS, FinBot CTF Application), solution landscapes (AI Security Solutions Landscape), checklists (LLM Applications Cybersecurity and Governance Checklist), and threat intelligence resources. All outputs are open-source and licensed under Creative Commons Attribution-ShareAlike 4.0.

Differentiator

Problem solved

Functional benefit

Products and services

  • OWASP Top 10 for LLM Applications Globally peer-reviewed framework documenting the most critical security risks for Large Language Model applications across the development, deployment, and management lifecycle.
  • OWASP Top 10 for Agentic Applications Globally peer-reviewed framework identifying the most critical security risks facing autonomous and agentic AI systems.
  • OWASP AIBOM Generator Open-source tool designed to enhance AI supply chain transparency and security by generating AI Bills of Materials (AIBOMs / AI SBOMs).
  • AI Security Solutions Landscape Quarterly updated resource cataloging tools and frameworks for mitigating AI security risks, aligned to OWASP Top 10 risks and the LLMSecOps lifecycle.
  • OWASP GenAI Security Project Threat Defense COMPASS Tool consolidating AI threats, vulnerabilities, defenses, and mitigations into a unified AI Threat Resilience Strategy Dashboard.
  • LLM Applications Cybersecurity and Governance Checklist Checklist for leaders across executive, tech, cybersecurity, privacy, compliance, and legal areas providing structured guidance for AI security programs.
  • GenAI Incident Response Guide Comprehensive guide providing security practitioners with guidelines and best practices for responding to security incidents involving GenAI applications.
  • Gen AI Red Teaming Guide Comprehensive guide outlining critical components of GenAI Red Teaming with actionable insights for cybersecurity professionals, AI/ML engineers, and Red Team practitioners.
  • Securing Agentic Applications Guide Practical and actionable guidance for designing, developing, and deploying secure agentic applications powered by LLMs.
  • State of Agentic AI Security and Governance Comprehensive report providing view of the landscape for securing and governing autonomous AI systems, exploring frameworks, governance models, and global regulatory standards.
  • Agentic AI – Threats and Mitigations Comprehensive documentation of threats and mitigations specific to agentic systems utilizing advanced frameworks (LangGraph, AutoGPT, CrewAI).
  • OWASP GenAI Data Security Risks & Mitigations Forward-looking analysis of unique data security challenges posed by rapid adoption of Generative AI across enterprise environments.
  • AIUC-1: Crosswalks OWASP Top 10 For Agentic Applications Bidirectional mapping between AIUC-1 requirements and the OWASP Agentic Security Initiative's Top 10 risks for autonomous and agentic AI systems.
  • FinBot CTF Application Hands-on Capture-The-Flag environment built around a simulated financial services application for understanding and mitigating agentic AI risks.
  • OWASP Vendor Evaluation Criteria for AI Red Teaming Providers & Tooling Practical guide for organizations assessing vendors offering AI red teaming services or automated testing tools.
  • CheatSheet – A Practical Guide for Securely Using Third-Party MCP Servers Detailed framework for safely deploying and managing external Model Context Protocol (MCP) servers.
  • A Practical Guide for Secure MCP Server Development Actionable guidance for securing Model Context Protocol (MCP) servers — the critical connection point between AI assistants and external tools, APIs, and data sources.
  • Agentic AI Security Initiative Initiative dedicated to securing autonomous AI systems and agent-based LLM applications, including frameworks, guides, and threat research.

Quantifiable outcome

  • 45+ publications produced covering AI security risks, mitigations, governance, and tooling
  • +3 more outcomes

Companies that use OWASP GenAI Security Project

Customer profile

Named customers8 records

Segments6 records

Ideal customer profiles4 records

OWASP GenAI Security Project technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature8 records

OWASP GenAI Security Project partnerships and signals

Strategic signal

Partnerships

Eight partnerships are on record, tiered core and minor.

  • SANS InstitutecoreStrategic or Co-development Partner · 17 April 2026Co-development of the 'AI Vulnerability Storm' report with contributions from over 250 CISOs. The report warns that Anthropic's Mythos AI will significantly accelerate vulnerability discovery and exploitation. Provides risk registers, priority actions, and board briefing materials.
  • Cloud Security AlliancecoreStrategic or Co-development Partner · 17 April 2026Co-development partner in the 'AI Vulnerability Storm' report. Contributes cybersecurity expertise and industry perspective to AI security risk analysis and recommendations.
  • [un]promptedcoreStrategic or Co-development Partner · 17 April 2026Co-development partner in the 'AI Vulnerability Storm' report focused on AI security threats and organizational preparedness guidance.
  • CyberRisk AllianceminorGTM or Marketing Partner · 30 June 2025Strategic partnership to advance application security and AI education across the cyber ecosystem. Joint efforts in educational content, webinars, and industry outreach.
  • MITREcoreStrategic or Co-development PartnerFormal collaboration with MITRE on AI security research and framework alignment. MITRE's expertise in security standards contributes to the project's research rigor and alignment with industry needs.
  • NIST (National Institute of Standards and Technology)coreStrategic or Co-development PartnerFormal collaboration with NIST on AI security standards and research. NIST contributions include expert participation in reports like the 'AI Vulnerability Storm' analysis. Project maintains mappings between OWASP Top 10 and NIST frameworks.
  • UK Government EntitiescoreStrategic or Co-development PartnerFormal collaboration with UK government entities on AI security policy and guidance alignment. Supports the project's goal of regulatory alignment across jurisdictions.
  • Linux Foundation ProjectscoreStrategic or Co-development PartnerCollaboration with various Linux Foundation projects on AI security standards and open-source security tooling. Ensures alignment with open-source ecosystem standards and practices.

Scale indicators9 records

Recent moves6 records

Expansion highlights6 records

OWASP GenAI Security Project competitors and assessment

Company assessment

Direct peers

  • Partnership on AI: A multi-stakeholder nonprofit producing AI best practices, research, and safety guidance across industry, academia, and civil society. Operates as an open-source standards and research body with comparable scope to OWASP's governance and frameworks work.
  • Cloud Security Alliance (CSA): CSA's AI Safety Initiative and related working groups produce open-source AI security frameworks, whitepapers, and training. CSA co-developed the 'AI Vulnerability Storm' report with OWASP, indicating direct coordination on AI security standards.
  • AI Incident Database: An open-source, community-driven database cataloging AI-related harms and incidents. Comparable in spirit to OWASP's threat intelligence efforts and serves as a complementary data source for AI security research and framework development.
  • MITRE ATLAS: MITRE's Adversarial Threat Landscape for AI-Enabled Systems is a directly comparable knowledge base cataloging AI/ML threats, mitigations, and case studies. Both projects operate as open-source, expert-driven AI security references, and they maintain formal alignment collaborations.

Broad incumbents

  • AI Security Institute (UK): The UK government's AI Safety Institute conducts AI security and safety evaluations and publishes research. A formal OWASP collaborator with regulatory authority and government backing for AI security standards.
  • ENISA (EU Agency for Cybersecurity): EU's cybersecurity agency producing AI security guidance and frameworks including the EU AI Act implementation support. Comparable as a standards-producing body with broader regulatory influence than voluntary frameworks.
  • NIST AI Risk Management Framework (AI RMF): NIST's AI RMF and related generative AI profile (NIST AI 600-1) provide authoritative AI risk guidance. As a US federal standards body, NIST carries regulatory weight that OWASP lacks, and the two maintain formal mapping relationships.

Emerging players

  • HiddenLayer: A commercial AI security startup providing adversarial ML and LLM threat detection products. Both organizations work on AI/ML security threats, and HiddenLayer is an OWASP partner and sponsor operating in adjacent commercial territory.
  • Lasso Security: A GenAI security startup focused on LLM protection and compliance. Both address LLM security risks with overlapping audience (CISOs, security teams), and Lasso is an OWASP sponsor citing the Top 10 for LLMs in product literature.

Others

  • OWASP Foundation: The parent nonprofit foundation that hosts the OWASP GenAI Security Project. While not a direct competitor, OWASP's broader portfolio (Top 10 Web, Top 10 API, Top 10 Mobile) shares the same community-driven, open-source security standards model and provides governance infrastructure.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks6 records

Key highlights6 records

Customer concentration

OWASP GenAI Security Project social profiles

Digital presence

OWASP GenAI Security Project financial estimates

Financial estimate

Revenue estimate

Valuation estimate

OWASP GenAI Security Project leadership team

Management profile

Number of profiles

Profiles12 records

OWASP GenAI Security Project funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

OWASP GenAI Security Project M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about OWASP GenAI Security Project

What does OWASP GenAI Security Project do?

The OWASP GenAI Security Project is an open-source initiative that produces peer-reviewed security frameworks, guides, tools, and threat intelligence for understanding and mitigating security and safety risks in Generative AI and LLM applications. Core deliverables include the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications risk frameworks, the AIBOM Generator open-source tool, the AI Security Solutions Landscape directory, the Threat Defense COMPASS, and various cheat sheets and red teaming guides — all distributed free of charge under open-source licenses.

Is OWASP GenAI Security Project a public or private company?

OWASP GenAI Security Project is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was OWASP GenAI Security Project founded?

OWASP GenAI Security Project was founded in 2023. It employs 51 to 100 people.

Where is OWASP GenAI Security Project based?

OWASP GenAI Security Project is headquartered in Wakefield, United States, in the North America region.

How does OWASP GenAI Security Project make money?

One revenue line is on record: sponsorship and Donations.

Who are OWASP GenAI Security Project's main competitors?

Direct peers on record are Partnership on AI, Cloud Security Alliance (CSA), AI Incident Database and MITRE ATLAS. Broad incumbents are AI Security Institute (UK), ENISA (EU Agency for Cybersecurity) and NIST AI Risk Management Framework (AI RMF). Emerging players are HiddenLayer and Lasso Security. OWASP Foundation is listed as an others.

Does OWASP GenAI Security Project have an API?

No public API is recorded for OWASP GenAI Security Project.

What industry is OWASP GenAI Security Project in?

OWASP GenAI Security Project's product category is AI Security Frameworks and Open-Source Guidance. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation). Its NAICS code is 5415 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Security BoulevardOWASP LLM Top 10 2026: Every Move Points the Same DirectionThe OWASP LLM Top 10 2026 reorders eight of ten entries, with Excessive Agency rising to LLM03 and Unbounded Consumption to LLM06. System Prompt Leakage was renamed Hidden Context Exposure, broadening its scope. The changes reflect a shift toward runtime risks in agentic applications.Third NewsOWASP GenAI Security Project Unveils 2026 Top 10 for LLM Applications with New Security StandardsOn September 2, 2026, OWASP GenAI Security Project released its 2026 Top 10 for LLM Applications, a guide for security threats in large language model apps. The project, with over 30,000 members and new sponsors, saw over 10,000 downloads in 48 hours. It also introduced the Agent Control Standard for runtime security enforcement in agentic AI.PR NewswireOWASP GenAI Security Project Releases 2026 Top 10 for LLM Applications, Debuts Agent Control Standard and New Resources for Securing Generative and Agentic AIOWASP GenAI Security Project released its 2026 Top 10 for LLM Applications and a new Agent Control Standard, with F5, WitnessAI, Evoke Security, and Mondoo as new sponsors. The project surpassed 30,000 members, and the Top 10 exceeded 10,000 downloads in 48 hours.Security BoulevardApplying the OWASP Top 10 for LLM Applications in productionA security guidance article explains how to apply the OWASP Top 10 for LLM applications to production systems, treating the framework as a prioritisation tool rather than a compliance checklist. It covers prompt injection, data exposure, insecure tool use, output validation, least privilege, logging, testing and governance, with a checklist for UK SMEs.Security BoulevardLLM security testing: how to pentest LLMs and MCP serversThe article outlines a repeatable loop for pentesting LLM applications and Model Context Protocol servers, mapping attacks to OWASP's LLM01 through LLM07 and showing how tool descriptions and responses become injection channels. It provides a Python proof-of-concept that runs a local model against a vulnerable FastMCP server, measuring hit rates across ten runs, and a promptfoo-based regression test wired into CI.VentureBeatPrompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.OWASP project leaders Kyriakos Lambros and Steve Wilson published an exploratory arXiv study on August 18 comparing their OWASP Top 10 for LLM Applications ranking against 6,639 labeled incidents, finding prompt injection at No. 12 versus No. 1. Cohen's kappa was 0.20, showing weak agreement. The authors say prompt injection hides inside model input, leaving no CVE for scanners to find.LinkedInOWASP GenAI Security ProjectThe OWASP GenAI Security Project, launched in 2023, is a rapidly expanding open-source community focused on developing frameworks and resources for AI security, particularly for large language models and agentic AI systems.Help Net SecurityPrompt injection still drives most agentic AI security failures in productionThe OWASP GenAI Security Project's State of Agentic AI Security and Governance report (v2.01) documents real-world security incidents, CVEs, and breach reports tied to agentic AI systems, marking a shift from the prior year's catalog of plausible threats. Prompt injection remains the dominant attack vector, mapped to six of OWASP's Top 10 categories for agentic applications, with coding agents driving most new attack data due to their dominant enterprise adoption. A March 2026 supply chain attack compromised LiteLLM—a language-model gateway used by CrewAI, DSPy, and Microsoft GraphRAG—on PyPI, delivering an autonomous attack bot named hackerbot-claw to approximately 47,000 downloads over three hours, exploiting a stolen publishing token from a compromised Aqua Security GitHub Actions setup.ZawyaSANS Institute, Cloud Security Alliance, [un]prompted, and OWASP GenAI Security Project release emergency strategy briefingSANS, CSA, [un]prompted, and OWASP released a free briefing on AI-driven vulnerability discovery, built by 60+ contributors and reviewed by 250+ CISOs. It cites AI tools like Mythos generating 181 working exploits and a 72% success rate, with mean time to exploitation under one day in 2026. The briefing urges immediate AI agent deployment and a permanent Vulnerability Operations function within 12 months.GlobeNewswireSANS Institute, Cloud Security Alliance, [un]prompted, and OWASP GenAI Security Project Release Emergency Strategy Briefing as AI-Driven Vulnerability Discovery Compresses Exploit Timelines from WeeksSANS Institute, Cloud Security Alliance, [un]prompted, and OWASP GenAI Security Project released a strategy briefing on AI-driven vulnerability discovery. The briefing cites Anthropic's Claude Mythos generating 181 working exploits against Firefox vulnerabilities with a 72% success rate, and notes the mean time from disclosure to exploitation fell to under one day in 2026.