Evidence-Graded Risk Mapping for AI Security
Vendors claim their tools mitigate AI security risks. Yuntona publishes the method for grading each claim's strength, mapped against the OWASP LLM and Agentic Top 10.
Status: draft, published before results, deliberately. No tool has been mapped against a named risk under this specification yet. Zero gold labels exist, no calibration has been fitted, and no threshold has been set. Publishing the method first means the mapping can be checked against a standard that was fixed before the results were known, and that any later finding can be argued with on the method, not just on the conclusion.
The register
Each specification is versioned independently. The status shown is the state of the published text.
Evidence-Graded Risk Mapping
An open, versioned specification for mapping graded evidence to the AI security risks it claims to mitigate.
12 sections: Scope boundary · Evidence classes · Risk signal and polarity · Confidence is derived, not asked for · What calibration actually is · Thresholds and published tolerance · Blind review and anchoring · The invisible failure · Nothing expires by default · Entity resolution · Taxonomy versioning · Review discipline
Read the specification →