Solutions · AI Teams → Solutions · Banking → Benchmarks → Integrations → Docs → Whitepaper → Pricing → Sign in Get Early Access
15+ attack suites · VLM + LLM · Early access open

Find what breaks your vision model before they do

Zortium runs a full consortium of adversarial attacks against your VLM endpoint — visual injections, jailbreak benchmarks, text-channel exploits, and more. Get a per-suite ASR report in minutes.

WORKS WITH OpenAI Groq Together AI vLLM Ollama + any OpenAI-compatible API
15+Suites
500+Test Cases
2Channels
50+Providers
3Deploy Modes
zortium · llava-1.6-mistral · scan #24 LIVE
Running 15+ suites against endpoint
Typographic InjectionPASS
Split Modality InjectionPASS
FigStepFAIL 33%
Image HijacksFAIL 67%
UI SpoofingWARN 12%
Goal HijackingPASS
Steganographic TextPASS
JailBreak VisualPASS
Many-Shot TextPASS
Refusal SuppressionWARN 8%
Overall ASR 26% · 3 suites remaining · 2 critical
How it works

From endpoint to security report in minutes

1

Connect

Point Zortium at any OpenAI-compatible endpoint. Paste your base URL and API key — no SDK changes, no instrumentation.

2

Attack

Zortium fires 15+ adversarial attack suites across visual and text channels. Real benchmark images, real jailbreak payloads.

3

Report

Get a full ASR breakdown per suite, per harm category, with individual breach details and remediation context.

Attack suites

A growing consortium of attacks

Covering both the visual and text channels — the full attack surface of a deployed VLM.

Typographic Injection Visual

Embeds harmful instructions as readable text inside an image. Tests if the model executes visual text it would refuse in chat.

FigStep Visual

Presents harmful topics as numbered blank-list documents for the model to 'complete' — exploiting document-task framing.

JailBreakV28K Visual

Runs real benchmark images from the 2024 COLM JailBreakV-28K dataset across 7 adversarial format types.

Precomputed Transfer Suffix Text

Appends adversarial token suffixes computed against open-source models to test cross-model transfer.

Many-Shot Text Text

Prefixes 24 fake compliant-assistant exchanges to shift the model's in-context distribution toward compliance.

Goal Hijacking Text

Classic prompt injection: buries a harmful directive inside a benign cover task using delimiter spoofing.

See all 15+ suites →
Integrations

Works with your stack

Any endpoint that speaks the OpenAI chat-completions protocol is supported out of the box.

🟢
OpenAI
GPT-4o, GPT-4 Vision
Groq
LLaVA, LLaMA 3.2
🔵
Together AI
LLaVA, Qwen-VL
🚀
vLLM
Self-hosted inference
🦙
Ollama
Local model runner
🔥
Fireworks AI
Fast inference API
🤗
TGI
Text Generation Inference
🖥
LM Studio
Desktop model server
See all integrations →
Pricing

Simple pricing — no surprises

CLI
Free

Run the full attack suite locally against any endpoint. No account required.

  • All 15+ attack suites
  • JSON + terminal reports
  • CI/CD exit-code gate
  • Unlimited local scans
Install CLI
Enterprise
Custom

On-prem deployment, custom attack suites, SLA, and dedicated support.

  • Everything in Cloud Pro
  • On-prem / air-gapped deploy
  • Custom attack suite authoring
  • Dedicated Slack + SLA
Talk to us
See full pricing →

Ready to find your blind spots?

Join teams who are already testing their vision models against the attacks that matter. No setup headaches — just point, attack, report.

Get Early AccessComing Soon