OWASP AISVS Panjabi Translation — Review Hub
Your feedback matters. You do not need a GitHub account to review this translation. Read the content below, then email your feedback to gurvinder@securityleader.ai with the subject line "AISVS Panjabi Review". Even a single correction or suggestion is valuable.
What Is This?
The OWASP AI Security Verification Standard (AISVS) is a community-driven catalogue of testable security requirements for AI-enabled systems — covering training data integrity, input validation, model lifecycle management, infrastructure, access control, supply chain, model behavior, memory/vector databases, agentic orchestration, MCP security, adversarial robustness, and monitoring/logging.
This is the first-ever translation of AISVS into Panjabi (ਪੰਜਾਬੀ), reaching 130+ million speakers worldwide, following the same bilingual methodology as the OWASP ASVS 5.0 Panjabi translation. The translation uses a bilingual format — English first, Panjabi (Gurmukhi script) immediately below — so readers can cross-reference for technical precision.
The translation has been submitted to the official OWASP AISVS repository as a proposed contribution (PR #1128 on GitHub).
What to Review
All eighteen bilingual documents are ready for review — the complete AISVS 1.0 translation. Read them in any order:
| Document | What It Contains | Link |
|---|---|---|
| Frontispiece (ਸਿਰਲੇਖ ਪੰਨਾ) | Project credits, copyright, license, contributors | Read |
| Preface (ਮੁਖਬੰਧ) | AISVS 1.0 introduction, principles, scope | Read |
| Using the AISVS (AISVS ਦੀ ਵਰਤੋਂ) | How to apply the standard, levels, verification | Read |
| C1 Training Data Integrity & Traceability (C1 ਸਿਖਲਾਈ ਡਾਟਾ ਅਖੰਡਤਾ ਅਤੇ ਟਰੇਸਯੋਗਤਾ) | Training data sourcing, tracking, and tamper protection | Read |
| C2 Input Validation (C2 ਇਨਪੁੱਟ ਪ੍ਰਮਾਣਿਕਤਾ) | Prompt injection defence and input handling requirements | Read |
| C3 Model Lifecycle Management & Change Control (C3 ਮਾਡਲ ਜੀਵਨ-ਚੱਕਰ ਪ੍ਰਬੰਧਨ ਅਤੇ ਤਬਦੀਲੀ ਨਿਯੰਤਰਣ) | Model versioning, change control, and lifecycle requirements | Read |
| C4 Infrastructure, Configuration & Deployment Security (C4 ਬੁਨਿਆਦੀ ਢਾਂਚਾ, ਸੰਰਚਨਾ ਅਤੇ ਤੈਨਾਤੀ ਸੁਰੱਖਿਆ) | Infrastructure hardening and secure deployment requirements | Read |
| C5 Access Control & Identity for AI Components & Users (C5 AI ਕੰਪੋਨੈਂਟਾਂ ਅਤੇ ਉਪਭੋਗਤਾਵਾਂ ਲਈ ਪਹੁੰਚ ਕੰਟਰੋਲ ਅਤੇ ਪਛਾਣ) | Identity and access control requirements for AI systems | Read |
| C6 Supply Chain Security for Models (C6 ਮਾਡਲਾਂ ਲਈ ਸਪਲਾਈ ਚੇਨ ਸੁਰੱਖਿਆ) | Model provenance and supply-chain integrity requirements | Read |
| C7 Model Behavior, Output Control & Safety Assurance (C7 ਮਾਡਲ ਵਿਵਹਾਰ, ਆਊਟਪੁੱਟ ਨਿਯੰਤਰਣ ਅਤੇ ਸਲਾਮਤੀ ਭਰੋਸਾ) | Output filtering and model-behavior safety requirements | Read |
| C8 Memory, Embeddings & Vector Database Security (C8 ਮੈਮੋਰੀ, Embeddings ਅਤੇ ਵੈਕਟਰ ਡਾਟਾਬੇਸ ਸੁਰੱਖਿਆ) | RAG and vector-store security requirements | Read |
| C9 Orchestration & Agentic Security (C9 ਆਰਕੈਸਟ੍ਰੇਸ਼ਨ ਅਤੇ ਏਜੰਟ-ਆਧਾਰਿਤ ਸੁਰੱਖਿਆ) | Multi-agent orchestration and agentic-action security requirements | Read |
| C10 Model Context Protocol (MCP) Security (C10 Model Context Protocol (MCP) ਸੁਰੱਖਿਆ) | MCP-specific security requirements | Read |
| C11 Adversarial Robustness (C11 ਵਿਰੋਧੀ ਮਜ਼ਬੂਤੀ) | Robustness against adversarial inputs and attacks | Read |
| C12 Monitoring, Logging & Anomaly Detection (C12 ਨਿਗਰਾਨੀ, ਲੌਗਿੰਗ ਅਤੇ ਅਸਧਾਰਨਤਾ ਪਛਾਣ) | Security logging and anomaly-detection requirements | Read |
| Appendix A: Glossary (ਅੰਤਿਕਾ A: ਸ਼ਬਦਾਵਲੀ) | AI-security terms with Gurmukhi translations | Read |
| Appendix B: AI Security Controls Inventory (ਅੰਤਿਕਾ B: AI ਸੁਰੱਖਿਆ ਨਿਯੰਤਰਣ ਇਨਵੈਂਟਰੀ) | Reference inventory of AI security controls | Read |
| Appendix C: AI-Assisted Secure Coding (ਅੰਤਿਕਾ C: AI-ਸਹਾਇਤ ਪ੍ਰਾਪਤ ਸੁਰੱਖਿਅਤ ਕੋਡਿੰਗ) | Guidance for using AI coding assistants securely | Read |
Who Should Review
You do not need to be both a Panjabi speaker AND a security expert — either qualification helps:
- Panjabi speakers: Does the translation read naturally, or does it feel like a forced word-for-word conversion? Are there better Gurmukhi equivalents for any term?
- AI security researchers: Is the English source meaning preserved? Do any translations introduce ambiguity that could affect an implementer's understanding?
- Gurmukhi linguists: Any Devanagari script contamination? Proper vowel signs (ਮਾਤਰਾ)? Clean Unicode?
Understanding the Glossary — Translation Approaches
Every translated term is classified by its translation approach (T/L/R/H):
| Category | When Used | Example |
|---|---|---|
| T — Translated | Concept has a natural Panjabi equivalent | Authentication → ਪ੍ਰਮਾਣੀਕਰਨ |
| L — Loan Word | Term is universally used in English | API → ਏ.ਪੀ.ਆਈ. |
| R — Retained | Acronym or proper noun, kept as-is | OWASP, LLM, MCP |
| H — Hybrid | Part translates, part stays in English | Prompt Injection → ਪ੍ਰੌਮਪਟ ਇੰਜੈਕਸ਼ਨ |
Timeline
| Phase | Content | Target |
|---|---|---|
| A (Complete) | Full translation — all 3 front-matter documents, 12 control-family chapters (C1–C12), and 3 appendices — drafted and submitted as OWASP AISVS PR #1128 | August 2026 |
| B | Community (sangat) review window — this hub | 2026 |
How to Send Feedback
Email (easiest): Send to gurvinder@securityleader.ai with subject "AISVS Panjabi Review"
Include any of the following:
- A term you think should be translated differently
- A Gurmukhi spelling or vowel sign correction
- A sentence that reads unnaturally and a suggested alternative
- General impressions of the bilingual format
GitHub (for Git-comfortable reviewers): Open PR #1128 and leave inline comments on any file in 1.0/pa-IN/.
Source Material
- Translation submission — PR #1128 on GitHub
- GeeksikhSecurity working copy
- ASVS Panjabi Review Hub — the sibling translation and methodology this follows
ਸੁਰੱਖਿਆ ਗਿਆਨ ਸਭ ਲਈ ਹੋਣਾ ਚਾਹੀਦਾ ਹੈ. — Security knowledge should be accessible to all.