By Jeffrey Schwartz • July 8, 2025
Published on Dark Reading
Startup Tumeryk’s AI Trust scorecard finds Google Gemini Pro 2.5 as the most trustworthy, with OpenAI’s GPT-4o mini a close second and DeepSeek and Alibaba Qwen scoring lowest.
SOURCE: WAVEBREAK MEDIA LTD VIA ALAMY STOCK PHOTO
Google’s new Gemini Pro 2.5 ranks as the most trustworthy artificial intelligence (AI) modeling platform, with OpenAI’s GPT 4o-mini coming in at a close second, according to an assessment of the leading large language model (LLM) environments published by startup vendor Tumeryk.
Platforms with the lowest AI trust scores were DeepSeek R1 and Alibaba’s Qwen, based on the company’s latest AI Trust Score. Tumeryk, which emerged from stealth last year, offers an AI vulnerability scanner as a component of its core product, LLM Security Studio.
“When we were dealing with the analytics platforms, I realized that there’s a lot of risk with AI,” says Rohit Valia, co-founder and CEO of Tumeryk. “That’s why the AI Trust Score is designed to really be able to help enterprises understand their risk from generative AI and the chat box and agentic AI systems that they’re deploying.”
As organizations are pushed to use generative AI (GenAI) tools to create virtual agents, accelerate information gathering, and automate routine processes, the AI models pose various security risks, many of which remain unchecked. According to Zscaler’s recently released “ThreatLabs 2025 Data@Risk Report,” AI tools like ChatGPT and Microsoft Copilot were responsible for 4.2 million data loss violations.
Valia previously spent five years as head of product for the FICO Platform at FICO, where he observed similarities between credit and debit card risk and the risks associated with AI.
Tumeryk’s LLM Security Studio is designed to contain them by securing, testing, and auditing LLMs for compliance during development and throughout their deployment life cycles. The AI vulnerability scanner is designed to detect the risk of prompt injections, jailbreaks, hallucinations, and data leakage.
Middleware for AI Security
Valia, who ran Sun Microsystems’ Java Enterprise Server product organization during the early 2000s, says LLM Security Studio is analogous to that popular platform in that it functions like middleware.
“Think of it as the middleware for generative AI to control and manage security and compliance,” Valia says. “You can set policies, rules, and flows in terms of how your chatbots and agentic applications can access each other and models, including vector databases.”
The LLM Security Studio features a policy simulator that enables developers and builders to test and refine the security parameters of the LLMs they are creating. It also protects against data exfiltration with its GenAI firewall, which is embedded with NVIDIA’s NeMo Guardrails and Meta’s Llama Guard to prevent jailbreaks and score hallucinations. The firewall enforces policies on how LLMs behave using role-based access control.
Tumeryk’s AI Trust Score, which was used to generate the “State of AI Trust with Foundational Models” report, is part of the LLM Security Studio. The scoring is designed to let organizations compare publicly available LLMs for their security and compliance. The assessments align with industry and regulatory standards, including the EU AI Trust Act, ISO 42001, the National Institute of Standards and Technology’s RMF 600.1, and the Open Web Application Security Project’s Top 10 LLMs.
Taking those risk factors into account, the trust scores are measured on a scale of 0 to 1,000, with the latter representing the most trustworthy. Gemini Pro 2.5, which Google describes as its most advanced LLM, scored 899 in the scorecard, with GPT-4o mini right behind it with a score of 869.
Monitoring Updates for New Risks
The scorecard also shows that just because one provider’s LLM ranks high, it doesn’t mean its updates are equally secure. For example, Tumeryk’s test showed that Anthropic’s new Claude 4 has a lower trust score than Claude 3.7. Claude 4.0 showed a higher risk of prompt injection, supply chain vulnerabilities, insecure output handling, and hallucinations. A significant factor leading to reduced trust is tied to concerns over Claude’s new whistleblower feature that will alert law enforcement when it detects wrongdoing, Valia says.
“Giving it a little bit of autonomy could be dangerous,” Valia says. “As we tell our clients, having a circuit breaker between the model and the agents is a critical aspect of safety.”
The so-called circuit breaker lets developers cut access to agents using any given LLM.
“It is able to protect the users from harm in case there is anything untoward with a specific model,” he adds.
IT consultancy SoftServe is one of the first to start using the LLM Security Studio, deploying it to help clients understand the security risks associated with their use of AI, says Keith Rozmus, president of North America sales. Many CIOs and CISOs are unaware of the issues that can arise when developing capabilities using AI models, he says.
“I think Tumeryk provides a very clean, understandable, verifiable way of understanding what potential holes that a client might have, and it’s very easy to understand them as well with the score,” Rozmus says.
Adding Encryption With DataKrypto Pact
While Tumeryk’s LLM Security Studio is designed to provide guardrails for an organization’s authorized users and report on external risks, it doesn’t secure the data. To address that, Tumeryk also recently announced a partnership with startup DataKrypto.
DataKrypto, which emerged from stealth in April at the RSAC Conference in San Francisco, offers a tool called FHEnom for AI. According to Luigi Caramico, founder, chairman, and CTO of DataKrypto, it combines fully homomorphic encryption (FHE) with trusted execution environments (TEEs) to provide real-time, always-on encryption, ensuring that only authorized users and authors of models can access them.
A tokenizer and embedding layers that run within a TEE enclave hold one sealed secret key that is fully encrypted.
“If you’re not authorized to use our technology, we’ll never be able to poison the model because you need to have access to the key to even be able to send a document,” Caramico says.
Notably, the tool uses FHE for encryption and decryption, resulting in only slight latency, he adds.
Tumeryk and DataKrypto have both agreed to integrate their respective offerings for their respective customers. Among the first is a pharmaceutical company that, like many, relies on AI to discover new drugs.
“For them, it is imperative that AI with all their knowledge is protected because if somebody is capable of accessing it all, two decades of research are lost in a minute,” Caramico says.
Tumeryk also integrates with other offerings from Datadog, Splunk, and Wiz.


