Skip to main content

Overview

Rogue automatically maps red team findings to multiple industry compliance frameworks. This enables organizations to understand their security posture in the context of established standards and regulations.

Supported Frameworks

The OWASP Top 10 for LLM Applications 2025 covers the most critical security risks in LLM systems.
The MITRE Adversarial Threat Landscape for AI Systems provides a comprehensive taxonomy of AI-specific attacks.
The NIST AI Risk Management Framework addresses governance, technical, and ethical considerations.
The ISO/IEC 42001 AI Management System standard for organizational AI governance.
The European Union Artificial Intelligence Act regulatory framework.
The General Data Protection Regulation for data protection and privacy.
The OWASP API Security Top 10 for API-related vulnerabilities.
A minimal security baseline for essential checks.

Compliance Scoring

Rogue calculates compliance scores for each framework based on tested vulnerabilities:

Score Interpretation

Framework Coverage Cards

Rogue generates coverage cards showing compliance status:

Default Framework Selection

Frameworks are automatically selected based on scan type:

Using Frameworks

In Configuration

Accessing Framework Data

Report Generation

Compliance reports include:
  1. Compliance Score: Overall percentage for each framework
  2. Vulnerability Breakdown: Per-vulnerability pass/fail status
  3. Recommendations: Prioritized remediation guidance
  4. Framework Mapping: Which controls are affected

Adding Custom Frameworks

Custom frameworks can be defined with vulnerability mappings: