NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

157Scenario files
8First-class tools
20Lab modules
15+ATLAS techniques

Lab modules

The labs are organized as a product, not a stash of experiments.

Module

AI Control Crosswalk

Unified framework navigation across OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, and ISO 42001 — with directional cross-framework mappings, evidence prompts, and scorecard bridges.

Cross-framework graph with directional mappings, confidence scores, and public-safe evidence links across 4 frameworks.

Public-safe lab lineOpen
Module

AI Trust Scanner

Public website trust intelligence for AI claims, legal clarity, security trust, governance evidence, and cross-page consistency.

ATG public scorecard contract, five public dimensions, required caveats, and a Savvy runtime boundary.

Public-safe lab lineOpen
Module

Scorecard Launch Surface

Launch into the public AI Security Scorecard and the organizational AIPSA scorecard when you need the maturity model.

Framework-backed remediation guidance and public-safe scorecard navigation.

Public-safe lab lineOpen
Module

Job Navigator

Career onboarding, role targeting, and live AI Security Engineering hiring-signal navigation in one Labs surface.

Thousands of job descriptions indexed and mapped to AI security archetypes, with local profile calibration for candidate navigation.

Public-safe lab lineOpen
Module

Career Explorer

Workforce framework navigation for AI security roles, KSAs, competencies, and career pathways.

Mapped to SP 800-181 (Career Explorer) with custom AI security extensions.

Public-safe lab lineOpen
Module

LLM Attack Range

Scenario execution, generation/media abuse tracking, and control-evidence readiness in one dedicated product surface.

The flagship product boundary with curated snapshots and public JSON endpoints.

Public-safe lab lineOpen
Module

Prompt Security Reviewer

Deterministic prompt policy review across 15 rules: injection resistance, identity anchoring, output handling, secret detection, and RAG context isolation. Includes KB/corpus scanner.

15 deterministic rules, 9-detector secret scanner, corpus scan over arbitrary document sets — no LLM calls.

Public-safe lab lineOpen
Module

RAG Security Analyzer

Paste a RAG pipeline JSON config and get instant findings across authorization gaps, tenant isolation failures, over-retrieval, document provenance, and sensitive context exposure.

10 rules covering OWASP LLM03 and LLM06 — authorization, tenant isolation, provenance, retrieval scope, and poisoning risks.

Public-safe lab lineOpen
Module

Agent Tool Permission Analyzer

Analyze agent tool configurations for overly broad scopes, missing human-approval gates, unsafe side effects, ambiguous tool descriptions, and privilege escalation paths.

Rules mapped to OWASP LLM06 (Excessive Agency) — write_broad, admin scopes, external transfers, code execution, and identity anchoring gaps.

Public-safe lab lineOpen
Module

Output Handling Safety Tester

Paste model output, select the sink type (HTML, Markdown, JSON, tool call, email, DB, code), and get deterministic safety analysis across injection, leakage, and side-effect risks.

8 sink types, 15 output rules mapped to OWASP LLM05 — script tags, event handlers, unsafe links, command fields, and hidden context leakage.

Public-safe lab lineOpen
Module

Prompt Injection Test Harness

A structured library of 12 attack probes across 10 categories. Record blocked/detected/degraded/passed outcomes per probe and export a full evidence session as JSON or Markdown.

12 probes: direct/indirect injection, system prompt exfiltration, role confusion, policy bypass, tool misuse, data exfiltration, multilingual and encoding bypasses, Markdown injection, multi-turn setup.

Public-safe lab lineOpen
Module

AI Supply Chain & Model Integrity Lab

Review model artifacts, dependency paths, provenance gaps, and poisoning scenarios. Identify integrity weaknesses using existing attack packs without rebuilding the artifact scanner.

Public-safe lab lineOpen
Module

Memory & Context Poisoning Lab

Analyze poisoned persistent memory, session history, and context influence in agentic systems. Trace how contaminated entries change downstream decisions.

Public-safe lab lineOpen
Module

Data Leakage & Cross-Tenant Exposure Lab

Review tenant data, prompt traces, PII fixtures, and retrieval behavior to identify AI-specific data exposure failures. Interactive evidence builder with localStorage persistence.

Public-safe lab lineOpen
Module

Multimodal Injection Lab

Study hidden instructions in images, SVGs, steganographic content, and document-derived context. Design test plans for vision-enabled AI systems.

Public-safe lab lineOpen
Module

AI Governance Evidence Lab

Convert AI policy claims, controls, and crawler signals into governance evidence. Build a control evidence matrix with public-safe language.

Public-safe lab lineOpen
Module

AI Inventory & System Boundaries Lab

Practice discovering AI providers, model dependencies, data flows, and shadow AI surfaces. Create an AI system inventory artifact for governance and product security.

Public-safe lab lineOpen
Module

AI Product Threat Modeling Lab

Use the existing Threat Canvas to produce an AI trust-boundary threat model. Place boundaries, find abuse paths, and assign controls for engineering review.

Public-safe lab lineOpen
Module

AI Logging & Forensics Lab

Review AI trace, prompt, completion, retrieval, and tool-use logs. Identify telemetry gaps and produce a forensic evidence chain for AI abuse scenarios.

Public-safe lab lineOpen
Module

AI Incident Response & Abuse Operations Lab

Walk through an AI abuse incident, classify the event, preserve evidence, decide escalation, and produce an after-action plan using existing incident drill scenarios.

Public-safe lab lineOpen

Learning modules

Hands-on AI security labs.

Flagship products

Adversarial Range and Trust Scanner.

SecEng Adversarial Range

Scenario execution, attack-pack coverage, and control-evidence readiness in one dedicated product surface.

157 scenarios15+ ATLAS mappings15 attack packs

SecEng Trust Scanner

Public website trust intelligence for AI companies, security buyers, and governance teams.

6 dimensions8 artifact types

Public assets

Curated data bundle.

Ready

Catalog snapshot

Versioned product catalog for the public labs shell.

Size: 1 JSON file

Ready

Scenario snapshot

Curated scenario rows and control-evidence rollups.

Size: 157 scenario rows

Ready

Overview snapshot

Status, scope, caveat, run window, and data endpoints.

Size: versioned overview

Ready

Metric bundle

Public-safe scorecards and range metrics.

Size: 4 metric cards

Ready

Generation / media rollup

Monthly synthetic-media and prompt-abuse tracking.

Size: 8 monthly rows

Ready

ATG sample scorecard

Public-safe AI Trust and Governance scorecard sample with required caveat.

Size: 1 JSON file

Roadmap

The lab product expands into repeatable validation tracks.

Lab track

Prompt Injection and RAG Security Lab

Direct and indirect prompt injection, retrieval poisoning, context leakage, source attribution, access control, and evidence capture.

Direct prompt injectionIndirect prompt injectionRetrieval poisoningContext leakageEvidence capture

Lab track

Agent Security Control Lab

Tool-call authorization, sandboxing, approval gates, telemetry, rollback, audit trails, and blast-radius management.

Tool authorizationApproval flowsTelemetryRollbackAudit trails

Lab track

Governance Evidence Lab

Map AI RMF, ISO 42001, OWASP LLM, MITRE ATLAS, and internal policy to engineering artifacts.

Control mappingEvidence registryRisk registerAudit trailReport generator

Lab track

Model Supply Chain Security Lab

Model provenance, registry controls, artifact integrity, model signing, weights protection, and deployment gates.

ProvenanceArtifact integritySigningDeployment gatesModel cards

Lab track

Hiring Calibration Lab

Role decomposition, JD rewrite, interview scorecards, lab-based screens, and skill matrix design.

Role architectureJD rewriteInterview loopsSkills validationCandidate rubric

Live · controlled environment

Threat Canvas, SecEng Adversarial Range, and Trust Scanner are open for threat modeling, testing, and evidence capture