DVARA · Free self-assessment · OWASP LLM & MCP
An AI agent production-readiness self-assessment. Fifteen questions, about five minutes.
A free self-assessment from DVARA covering the AI you run, what it costs, proving what happened, and where your data goes. It shows where your own answers point to gaps — it does not test whether a control works, whether it covers every path, or whether you meet any law or framework.
How it scores: Fifteen questions, each weighted equally. Answering "yes" counts as coverage; "no" and "not sure" both count as gaps, because a control nobody can confirm is one you could not evidence either. A lower gap count is better. The result reflects what you reported — it is self-reported control coverage, not a test of whether any control works.
Knowing what AI you run
— / 3Whether you can list the AI in use across the company, and tell who or what made any given request.
Related OWASP risks: MCP07 Insufficient Authentication & Authorization · MCP09 Shadow MCP Servers
Could you list every app, service and AI agent in your company that uses AI today, and which AI model each one uses?
When something calls AI, can you tell which app or team it was — not just that it came from somewhere inside the company?
When one AI agent asks another agent or a tool to do something, is that request checked and approved, or does it simply go through?
Controlling what it costs
— / 3Whether spending is stopped as it happens, rather than reported to you afterwards. AI providers charge per use, and an agent stuck in a loop keeps spending.
Related OWASP risks: LLM10 Unbounded Consumption
Is there a spending limit that actually stops AI usage when it is reached, rather than an alert that tells you afterwards?
Can you set a budget per team, product or agent — not just one total for the whole company?
If an AI agent gets stuck repeating itself, does something stop it automatically, or do you find out from the bill?
Proving what happened
— / 3Whether you could show a regulator, a customer or an auditor what the AI did, who allowed it, and that the record has not been changed since.
Related OWASP risks: MCP08 Lack of Audit and Telemetry
Do you keep a record of what your AI did — which model, who asked, what it cost, what came back — that would show if someone had edited it afterwards?
For something the AI did last month, could you show who approved it and what it was allowed to do at the time?
Are those records kept somewhere the team being asked about cannot quietly change them?
Limiting what it can do
— / 3What an AI agent is able to do when it is wrong. Software that takes actions carries different consequences from software that writes text.
Related OWASP risks: LLM06 Excessive Agency · MCP02 Privilege Escalation via Scope Creep
Does each AI agent have only the access it needs for its job, rather than access that also lets it move money, change records or delete things?
Does a person have to approve before AI does something serious — a payment, a message to a customer, a change to real data?
If an AI agent went wrong, is there a limit built in on how much damage it could do before anyone noticed?
Knowing where your data goes
— / 3Whether you know what data reaches an AI provider and where in the world it is processed. These are questions about your own visibility, not about whether any particular law is met.
Related OWASP risks: LLM02 Sensitive Information Disclosure · MCP01 Token Mismanagement & Secret Exposure · MCP10 Context Injection & Over-Sharing
Do you know when customer or regulated data is sent to an AI provider, and which country it is processed in?
Are your AI account keys and sensitive data held by you, rather than sitting in another company's systems under their rules?
If a regulator or a large customer asked how you control AI, could you answer from something you already have, rather than starting from scratch?
What this assessment does not do
It records what you believe about your own controls. It does not examine them, test whether they hold under load or adversarial input, or check that they cover every path your traffic takes. Closing that gap means someone looking at the systems themselves.
The AI Agent Production-Readiness Audit is a separate paid engagement that does that work. It is run independently of the DVARA product, and where a gap is better closed by something other than DVARA — application design, identity, cloud configuration, a vendor review, or legal advice — that is what we will say. Book a scope call to hear what it covers and what it costs before committing to anything.
Book a 30-minute scope call →Independent of the DVARA product. Where DVARA would help, we'll say so plainly — you're never obligated to buy it. Prefer email? support@dvarahq.com.
Where these questions come from. Each area above relates to entries in the OWASP Top 10 for LLM Applications (2025) and the OWASP MCP Top 10 (2025), listed under each heading. Both are lists of risks, not rules you can comply with, so this is a relation and not a score: answering these questions tells you which risks your gaps relate to, and does not assess your position against OWASP or any other framework. What each entry means, and where a control can and cannot act on it, is set out in the OWASP LLM & MCP crosswalk.
What it does not cover. These fifteen questions touch three of the ten LLM entries and six of the ten MCP entries. Not asked about here: LLM01 Prompt Injection, LLM03 Supply Chain, LLM04 Data and Model Poisoning, LLM05 Improper Output Handling, LLM07 System Prompt Leakage, LLM08 Vector and Embedding Weaknesses, LLM09 Misinformation; MCP03 Tool Poisoning, MCP04 Software Supply Chain Attacks, MCP05 Command Injection, MCP06 Intent Flow Subversion.
Freshness. The MCP list is a beta release (v0.1) with a full release due October 2026, so these references are checked as at 29 August 2026 and will be re-checked then.
Your answers. They stay in this page. Nothing you answer is sent anywhere unless you enter an email to receive the results, in which case your address, your band and the number of gaps in each category are posted to DVARA so the summary can be sent — never the answers themselves. Analytics records that the sheet was started and finished, with none of your answers.
Common questions about the scorecard
What does the scorecard measure?
Fifteen questions across five areas — knowing what AI you run, controlling what it costs, proving what happened, limiting what it can do, and knowing where your data goes. Each asks whether a control actually sits in front of the AI, rather than being written down somewhere. It measures what you report, not what is verified: nothing here tests whether a control works, covers every path, or holds up under attack.
How is it scored?
Fifteen questions, each weighted equally. Answering "yes" counts as coverage; "no" and "not sure" both count as gaps, because a control nobody can confirm is one you could not evidence either. A lower gap count is better. The result reflects what you reported — it is self-reported control coverage, not a test of whether any control works. The result appears on the page as you answer — no email is required to see it.
What happens to my answers?
They stay in the page. Scoring runs locally and the text of your answers is never transmitted. If you ask for the results by email, DVARA receives your address, your band, and the number of gaps in each of the five categories — the gap map — so the summary can be sent, and nothing else. Analytics records that the sheet was started and finished, without any of your answers. The address is used to send the result and, if you reported three or more gaps, to offer the paid audit once; reply to any message to stop hearing from us.
Do I have to give an email to see my result?
No, and that is deliberate rather than an oversight. The band, the per-category gap map and the OWASP entries your gaps relate to are all on the page as you answer, free and without an address. Withholding the result until you hand over an email would convert better and would make the number less believable, which is the opposite of what this is for. The email is a copy you can keep or forward, not a key to content held back.
What do I get at the end?
A coverage band, a per-category gap map showing where your no and not-sure answers cluster, and the OWASP LLM and MCP entries those gaps relate to — all on the page immediately, and by email if you want a copy to keep or forward. Use it to decide what to look into first: it is a directional starting list, and the order it implies is a suggestion rather than a ranking of risk.
Is this the same as an audit?
No. It records what you believe to be true about your own controls; it does not examine them. An audit tests whether controls operate, whether they cover every path, and whether the evidence stands up when someone external asks. The Production-Readiness Audit is a separate paid engagement, run independently of the DVARA product, and this assessment is useful without it.