StepX · AI Agent Platform
Security Compliance Certificate

StepX Agent Platform

Confirming the defensive capability of the StepX platform, fully mapped against the OWASP Top 10 for LLM Applications (2025) risk framework.
10/10OWASP LLM
This document certifies that the StepX Agent Platform has implemented corresponding security controls for all 10/10 risk categories in the OWASP LLM Top 10 (2025) framework, reviewed through automated testing and internal assessment. The report describes protection capability to support security evaluation for customers and partners.
OWASP LLM Top 10 · 2025
Full mapping of all 10/10 items
Layered defense
Defense-in-Depth · 6 layers
Multi-tenant isolation
Multi-Tenant Isolation
Least privilege
Least-Privilege Access
Output sanitization
XSS-Safe Output
Personal data protection
Privacy-Aware · PII
10/10
OWASP items protected
6
Independent defense layers
0
Uncontrolled risks

Mapping against OWASP LLM Top 10 (2025)

Defense status for each risk category · updated after the 06/2026 security hardening (Phase 5–6).
CodeRisk category & protection measuresStatus
LLM01
Prompt Injection
Refuses manipulation from inputs; documents & history are tagged as "data", with a system > user > data priority order; spoofed delimiters are stripped.
Protected
LLM02
Insecure output handling
Malicious-code screening on inputs (extended to scripts/SVG/executable links) and HTML/script sanitization on every response — even when streaming — before display.
Protected
LLM03
Training data poisoning
We do not train models ourselves; only verified models from reputable providers are used, so the risk is eliminated at the source.
Protected
LLM04
Resource exhaustion attacks
Limits on request rate, input length, response size and the number of supplementary document retrievals per turn.
Protected
LLM05
Supply chain risk
We integrate only reputable AI services & infrastructure providers; dependencies are centrally managed and reviewed periodically.
Protected
LLM06
Sensitive information disclosure
Per-organization session isolation; only user-facing fields (allow-list) are exposed and internal signals are masked before being included in answers.
Protected
LLM07
Insecure plugin/extension design
Document retrieval goes through two independent control layers (scoped to the current conversation + organization ownership verification), read-only mode, and call limits.
Protected
LLM08
Excessive agency
Impactful actions run only per approved configuration & allow-list; the document-retrieval tool is read-only, with no out-of-scope write/delete.
Protected
LLM09
Overreliance on AI
Confidence is assessed for each response, with a fallback plan when confidence is low and a mechanism to flag and hand off to a human.
Protected
LLM10
Model theft
Access limits curb mass extraction; attempts to extract the assistant's internal configuration through conversation are prevented.
Protected

Layered defense architecture

Six independent, complementary protection layers across the entire processing pipeline.

1 · Input screening

Removes anomalous content, malicious code and abusive input before processing.

2 · Multi-tier safety classification

Assesses content safety with automatic fallback when a tier is overloaded.

3 · Per-organization rules

Each customer defines warnings and blocks to fit their own needs.

4 · Per-session & per-organization data isolation

Data is never mixed across sessions or across organizations.

5 · Document retrieval control (2 layers)

Retrieves only the relevant scope, re-verifying organization ownership.

6 · Output sanitization

Neutralizes HTML/script & masks sensitive information before returning.

Certificate information

Document IDSTX-SEC-OWASP-2026-06Reference frameworkOWASP LLM Top 10 (2025)Scopechat-service · pipeline v2MethodSelf-assessment + automated testingIssue date01/06/2026Review validity6 months

Endorsement

StepX Engineering & Security Team
Security Engineering · StepX AI Platform
10 / 10 · PASS
Result of mapping against the OWASP LLM Top 10 framework
© 2026 StepX AI Platform · Security defense report — a high-level orientation document, not a detailed implementation disclosure.
This is an internal self-assessment mapped against the OWASP Top 10 for LLM Applications (2025) framework; it does not replace certification by an independent third-party auditor.