OWASP GenAI Security Project
- Company typePrivate
- Founded2023
- HeadquartersWakefield, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What OWASP GenAI Security Project does
The OWASP GenAI Security Project is a global, open-source, community-driven initiative operated under the OWASP Foundation, a 501(c)(3) nonprofit. Founded in May 2023 as the OWASP Top 10 for LLM Application Security Project, it identifies, documents, and mitigates security and safety risks for Generative AI and LLM applications across the development, deployment, and management lifecycle. Its core deliverables are two peer-reviewed risk frameworks — the OWASP Top 10 for LLM Applications (updated annually, with a 2025 edition and an earlier 2023/24 edition) and the OWASP Top 10 for Agentic Applications 2026 — alongside a portfolio of 45+ publications including red teaming guides, incident response playbooks, the LLM Applications Cybersecurity and Governance Checklist, the State of Agentic AI Security and Governance report, and the AI Security Solutions Landscape. Supporting tooling includes the open-source AIBOM Generator (AI Bill of Materials), the Threat Defense COMPASS dashboard, the FinBot CTF training environment, and the AIUC-1 Crosswalk reference document.
The project's distribution model is entirely free: all content is published under Creative Commons Attribution-ShareAlike 4.0 and code under MIT/Apache 2.0/BSD licenses, delivered through the project website (genai.owasp.org), GitHub repositories, Slack workspace, YouTube channel, Beehiiv newsletter, Spotify/Apple podcasts, and presence at major security conferences including RSAC, Black Hat, Infosecurity Europe, and DEFCON. It serves security professionals, CISOs and executive leadership, AI/ML engineers and developers, and enterprises adopting generative AI, with secondary reach into policymakers and academic institutions. The project does not sell products or services; the sole revenue channel is corporate sponsorship at Gold and Silver tiers, which is explicitly stated not to influence project governance.
OWASP GenAI Security Project firmographics
Firmographics- Name
- OWASP GenAI Security Project
- Legal name
- OWASP Foundation, Inc.
- Website
- https://genai.owasp.org
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Ownership category
- akta.pro rank
OWASP GenAI Security Project industry classification
Industry- Product category
- AI Security Frameworks and Open-Source Guidance
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industry
- Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)
Keywords
Where OWASP GenAI Security Project is headquartered
LocationHeadquarters
- HQ city
- Wakefield
- HQ country
- United States
- HQ region
- North America
Markets served
OWASP GenAI Security Project business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others
Revenue model
- Sponsorship and Donations: The OWASP GenAI Security Project is a non-profit volunteer effort. Revenue is generated through corporate sponsorship at Gold and Silver tiers, which helps cover resources, operations, outreach, and education costs. Sponsorship does not impact project governance, which remains open and unbiased. The OWASP Foundation provides operational resources but these are limited.
Go-to-market motion2 records
Distribution channels3 records
Marketing channels9 records
OWASP GenAI Security Project product offering
Product offeringCore offering
The OWASP GenAI Security Project is an open-source initiative that produces peer-reviewed security frameworks, guides, tools, and threat intelligence for understanding and mitigating security and safety risks in Generative AI and LLM applications. Core deliverables include the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications risk frameworks, the AIBOM Generator open-source tool, the AI Security Solutions Landscape directory, the Threat Defense COMPASS, and various cheat sheets and red teaming guides — all distributed free of charge under open-source licenses.
Product overview
The OWASP GenAI Security Project is a global, open-source community-driven initiative that produces freely available guidance, frameworks, tools, and resources for understanding and mitigating security and safety concerns for Generative AI applications. The portfolio is organized as a platform of interconnected resources anchored by the core OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications — peer-reviewed risk frameworks that serve as the foundation for all other offerings. Supporting these core products are specialized guides (GenAI Incident Response Guide, Securing Agentic Applications Guide, GenAI Red Teaming Guide), tools (OWASP AIBOM Generator, OWASP GenAI Security Project Threat Defense COMPASS, FinBot CTF Application), solution landscapes (AI Security Solutions Landscape), checklists (LLM Applications Cybersecurity and Governance Checklist), and threat intelligence resources. All outputs are open-source and licensed under Creative Commons Attribution-ShareAlike 4.0.
Differentiator
Problem solved
Functional benefit
Products and services
- OWASP Top 10 for LLM Applications Globally peer-reviewed framework documenting the most critical security risks for Large Language Model applications across the development, deployment, and management lifecycle.
- OWASP Top 10 for Agentic Applications Globally peer-reviewed framework identifying the most critical security risks facing autonomous and agentic AI systems.
- OWASP AIBOM Generator Open-source tool designed to enhance AI supply chain transparency and security by generating AI Bills of Materials (AIBOMs / AI SBOMs).
- AI Security Solutions Landscape Quarterly updated resource cataloging tools and frameworks for mitigating AI security risks, aligned to OWASP Top 10 risks and the LLMSecOps lifecycle.
- OWASP GenAI Security Project Threat Defense COMPASS Tool consolidating AI threats, vulnerabilities, defenses, and mitigations into a unified AI Threat Resilience Strategy Dashboard.
- LLM Applications Cybersecurity and Governance Checklist Checklist for leaders across executive, tech, cybersecurity, privacy, compliance, and legal areas providing structured guidance for AI security programs.
- GenAI Incident Response Guide Comprehensive guide providing security practitioners with guidelines and best practices for responding to security incidents involving GenAI applications.
- Gen AI Red Teaming Guide Comprehensive guide outlining critical components of GenAI Red Teaming with actionable insights for cybersecurity professionals, AI/ML engineers, and Red Team practitioners.
- Securing Agentic Applications Guide Practical and actionable guidance for designing, developing, and deploying secure agentic applications powered by LLMs.
- State of Agentic AI Security and Governance Comprehensive report providing view of the landscape for securing and governing autonomous AI systems, exploring frameworks, governance models, and global regulatory standards.
- Agentic AI – Threats and Mitigations Comprehensive documentation of threats and mitigations specific to agentic systems utilizing advanced frameworks (LangGraph, AutoGPT, CrewAI).
- OWASP GenAI Data Security Risks & Mitigations Forward-looking analysis of unique data security challenges posed by rapid adoption of Generative AI across enterprise environments.
- AIUC-1: Crosswalks OWASP Top 10 For Agentic Applications Bidirectional mapping between AIUC-1 requirements and the OWASP Agentic Security Initiative's Top 10 risks for autonomous and agentic AI systems.
- FinBot CTF Application Hands-on Capture-The-Flag environment built around a simulated financial services application for understanding and mitigating agentic AI risks.
- OWASP Vendor Evaluation Criteria for AI Red Teaming Providers & Tooling Practical guide for organizations assessing vendors offering AI red teaming services or automated testing tools.
- CheatSheet – A Practical Guide for Securely Using Third-Party MCP Servers Detailed framework for safely deploying and managing external Model Context Protocol (MCP) servers.
- A Practical Guide for Secure MCP Server Development Actionable guidance for securing Model Context Protocol (MCP) servers — the critical connection point between AI assistants and external tools, APIs, and data sources.
- Agentic AI Security Initiative Initiative dedicated to securing autonomous AI systems and agent-based LLM applications, including frameworks, guides, and threat research.
Quantifiable outcome
- 45+ publications produced covering AI security risks, mitigations, governance, and tooling
- +3 more outcomes
Companies that use OWASP GenAI Security Project
Customer profileNamed customers8 records
Segments6 records
Ideal customer profiles4 records
OWASP GenAI Security Project technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature8 records
OWASP GenAI Security Project partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- SANS InstitutecoreCo-development of the 'AI Vulnerability Storm' report with contributions from over 250 CISOs. The report warns that Anthropic's Mythos AI will significantly accelerate vulnerability discovery and exploitation. Provides risk registers, priority actions, and board briefing materials.
- Cloud Security AlliancecoreCo-development partner in the 'AI Vulnerability Storm' report. Contributes cybersecurity expertise and industry perspective to AI security risk analysis and recommendations.
- [un]promptedcoreCo-development partner in the 'AI Vulnerability Storm' report focused on AI security threats and organizational preparedness guidance.
- CyberRisk AllianceminorStrategic partnership to advance application security and AI education across the cyber ecosystem. Joint efforts in educational content, webinars, and industry outreach.
- MITREcoreFormal collaboration with MITRE on AI security research and framework alignment. MITRE's expertise in security standards contributes to the project's research rigor and alignment with industry needs.
- NIST (National Institute of Standards and Technology)coreFormal collaboration with NIST on AI security standards and research. NIST contributions include expert participation in reports like the 'AI Vulnerability Storm' analysis. Project maintains mappings between OWASP Top 10 and NIST frameworks.
- UK Government EntitiescoreFormal collaboration with UK government entities on AI security policy and guidance alignment. Supports the project's goal of regulatory alignment across jurisdictions.
- Linux Foundation ProjectscoreCollaboration with various Linux Foundation projects on AI security standards and open-source security tooling. Ensures alignment with open-source ecosystem standards and practices.
Scale indicators9 records
Recent moves6 records
Expansion highlights6 records
OWASP GenAI Security Project competitors and assessment
Company assessmentDirect peers
- Partnership on AI: A multi-stakeholder nonprofit producing AI best practices, research, and safety guidance across industry, academia, and civil society. Operates as an open-source standards and research body with comparable scope to OWASP's governance and frameworks work.
- Cloud Security Alliance (CSA): CSA's AI Safety Initiative and related working groups produce open-source AI security frameworks, whitepapers, and training. CSA co-developed the 'AI Vulnerability Storm' report with OWASP, indicating direct coordination on AI security standards.
- AI Incident Database: An open-source, community-driven database cataloging AI-related harms and incidents. Comparable in spirit to OWASP's threat intelligence efforts and serves as a complementary data source for AI security research and framework development.
- MITRE ATLAS: MITRE's Adversarial Threat Landscape for AI-Enabled Systems is a directly comparable knowledge base cataloging AI/ML threats, mitigations, and case studies. Both projects operate as open-source, expert-driven AI security references, and they maintain formal alignment collaborations.
Broad incumbents
- AI Security Institute (UK): The UK government's AI Safety Institute conducts AI security and safety evaluations and publishes research. A formal OWASP collaborator with regulatory authority and government backing for AI security standards.
- ENISA (EU Agency for Cybersecurity): EU's cybersecurity agency producing AI security guidance and frameworks including the EU AI Act implementation support. Comparable as a standards-producing body with broader regulatory influence than voluntary frameworks.
- NIST AI Risk Management Framework (AI RMF): NIST's AI RMF and related generative AI profile (NIST AI 600-1) provide authoritative AI risk guidance. As a US federal standards body, NIST carries regulatory weight that OWASP lacks, and the two maintain formal mapping relationships.
Emerging players
- HiddenLayer: A commercial AI security startup providing adversarial ML and LLM threat detection products. Both organizations work on AI/ML security threats, and HiddenLayer is an OWASP partner and sponsor operating in adjacent commercial territory.
- Lasso Security: A GenAI security startup focused on LLM protection and compliance. Both address LLM security risks with overlapping audience (CISOs, security teams), and Lasso is an OWASP sponsor citing the Top 10 for LLMs in product literature.
Others
- OWASP Foundation: The parent nonprofit foundation that hosts the OWASP GenAI Security Project. While not a direct competitor, OWASP's broader portfolio (Top 10 Web, Top 10 API, Top 10 Mobile) shares the same community-driven, open-source security standards model and provides governance infrastructure.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
OWASP GenAI Security Project social profiles
Digital presenceOWASP GenAI Security Project financial estimates
Financial estimateRevenue estimate
Valuation estimate
OWASP GenAI Security Project leadership team
Management profileNumber of profiles
Profiles12 records
OWASP GenAI Security Project funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
OWASP GenAI Security Project M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about OWASP GenAI Security Project
What does OWASP GenAI Security Project do?
The OWASP GenAI Security Project is an open-source initiative that produces peer-reviewed security frameworks, guides, tools, and threat intelligence for understanding and mitigating security and safety risks in Generative AI and LLM applications. Core deliverables include the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications risk frameworks, the AIBOM Generator open-source tool, the AI Security Solutions Landscape directory, the Threat Defense COMPASS, and various cheat sheets and red teaming guides — all distributed free of charge under open-source licenses.
Is OWASP GenAI Security Project a public or private company?
OWASP GenAI Security Project is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was OWASP GenAI Security Project founded?
OWASP GenAI Security Project was founded in 2023. It employs 51 to 100 people.
Where is OWASP GenAI Security Project based?
OWASP GenAI Security Project is headquartered in Wakefield, United States, in the North America region.
How does OWASP GenAI Security Project make money?
One revenue line is on record: sponsorship and Donations.
Who are OWASP GenAI Security Project's main competitors?
Direct peers on record are Partnership on AI, Cloud Security Alliance (CSA), AI Incident Database and MITRE ATLAS. Broad incumbents are AI Security Institute (UK), ENISA (EU Agency for Cybersecurity) and NIST AI Risk Management Framework (AI RMF). Emerging players are HiddenLayer and Lasso Security. OWASP Foundation is listed as an others.
Does OWASP GenAI Security Project have an API?
No public API is recorded for OWASP GenAI Security Project.
What industry is OWASP GenAI Security Project in?
OWASP GenAI Security Project's product category is AI Security Frameworks and Open-Source Guidance. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation). Its NAICS code is 5415 and its SIC code is 7372.