Nuvrix AI Security Review
Nuvrix Pty Ltd · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
**Overview**
The Nuvrix AI Security Review is a fixed-scope engagement that assesses the security of your AWS-hosted AI systems. It covers the application layer, the model layer, and your cloud security posture, giving you a complete picture of where your AI systems are exposed and what to do about it.
Show the rest of the publisher’s description (14 more lines)
Most organisations running GenAI workloads on AWS have tested their models for accuracy and performance. Very few have tested them for jailbreaks, prompt injection, data leakage, multi-turn attacks, or the infrastructure misconfigurations that leave model outputs and training data exposed. This engagement covers all of it.
**What we test**
We run automated red-teaming against your GenAI endpoints using industry-standard tooling covering attack probe types including jailbreaks, encoding attacks, and data leakage scenarios. We scan your AWS environment for misconfigurations - IAM, network exposure, logging gaps, and Bedrock Guardrails configuration - using security tooling with mappings to CIS, ISO 27001, etc and AWS Foundational Technical Review controls. For regulated clients, we include multi-turn attack chain testing.
**What you receive**
- Red-team findings report with validated, triaged results
- Cloud posture findings mapped to your compliance obligations (Essential Eight, CPS 234, ISO 27001 etc as applicable)
- Bedrock Guardrails configuration review
- Prioritised remediation backlog with effort estimates
- Findings workshop with your technical team and executive sponsor
- Retainer proposal to maintain the security posture we establish
**Who it's for**
Organisations running GenAI workloads on AWS - particularly those in financial services, healthcare, or government where AI security obligations are explicit. Also suited to any team about to launch a customer-facing AI product and wanting assurance before go-live.
**How it works**
The engagement runs over two weeks. We conduct a scoping call to confirm the AI systems in scope, deploy our collection tooling using read-only access to your AWS environment, and run red-teaming against the endpoints you nominate. We triage all findings - removing false positives and ranking by exploitability and blast radius - before delivering a draft report. We close with a findings workshop and a retainer proposal.
Highlights
Highlighted by the publisher on AWS Marketplace.
120+ attack probe types - automated red-teaming covers jailbreaks, encoding attacks, prompt injection, and data leakage across your GenAI endpoints before a real attacker finds them first.
Findings mapped to your obligations - cloud posture results mapped to Essential Eight, CPS 234, and ISO 27001 so your compliance team has evidence, not just a list of technical findings.
Triage included, not optional - every finding is reviewed, false positives removed, and results ranked by exploitability and blast radius. You get 6 findings that matter, not 40 that don't.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

