What AI risks does Tumeryk test for?
Explore how Tumeryk evaluates AI risk across security, privacy, reliability, safety, transparency, and excessive agency, including the CSA RiskRubric™ v2 methodology.
umeryk evaluates AI systems using automated adversarial testing, risk simulation, and evidence-based assessment to identify technical weaknesses that can affect enterprise AI trust.
Rather than evaluating only how capable an AI model or application is, Tumeryk examines how the system behaves under conditions designed to reveal security, privacy, reliability, safety, transparency, and agentic risks.
Risk assessment across six pillarsTumeryk’s assessment approach can evaluate AI across the six risk pillars used by the Cloud Security Alliance (CSA) RiskRubric™ v2 methodology:
Security
Testing can identify AI-specific security weaknesses such as:
- Prompt injection
- Jailbreak resistance
- System-prompt leakage
- Sensitive-information disclosure
- Other adversarial behaviors that can compromise intended AI controls
Privacy
Testing can evaluate whether an AI system exposes or mishandles sensitive information, including risks associated with:
- Privacy leakage
- Sensitive-data exposure
- Inappropriate disclosure of information
Reliability
Tumeryk evaluates AI behavior for reliability-related issues including:
- Hallucination
- Response completeness
- Response consistency
- Behaviors that may reduce confidence in AI-generated outcomes
Safety & Societal Impact
Assessments can examine whether AI systems generate unsafe, harmful, or otherwise undesirable outputs under relevant testing conditions.
Transparency
Transparency forms part of the broader assessment of whether AI behavior provides sufficient visibility and evidence to support effective risk and governance decisions.
Excessive Agency
For AI agents and increasingly autonomous systems, Tumeryk can evaluate risks associated with excessive agency and agentic boundary violations.
These risks become particularly important when agents can access enterprise data, invoke tools or APIs, interact with other agents, and execute actions across business systems.
Tumeryk’s broader Agentic AI Governance capabilities complement assessment with Agent Access Control, Agent Observability, Human Permission Enforcement, Runtime Guardrails, and continuous governance.
CSA RiskRubric™ v2 and AI Trust Score™Tumeryk worked with the Cloud Security Alliance on RiskRubric™ v2, an open, evidence-based methodology for evaluating AI risk.
Tumeryk helps operationalize this methodology through automated testing and AI Trust Score™, translating technical assessment evidence into a standardized 0–1000 measure of AI trust.
This enables organizations to move beyond questionnaires and self-attestation toward measurable evidence of how an AI system performs against relevant risk scenarios.
Because AI behavior can change as models, prompts, retrieval sources, applications, permissions, and configurations evolve, assessments can be repeated to monitor changes in AI risk posture over time.
Learn more:
CSA RiskRubric™: https://riskrubric.ai/