NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

Products / SecEng Workbench

Workbench instruments behind every assessment, red-team, hardening, and evidence pack.

SecEng Workbench instruments used behind AI product security assessments, adversarial testing, hardening, buyer evidence, and governance program work. Services are paid consulting engagements; products are the delivery engine.

Map

Map instruments

Open Map pillar
Map

SecEng Threat Canvas — Trust Boundary Mapper

Identify AI systems, data flows, trust boundaries, abuse-path hypotheses, and evidence gaps before deeper testing.

Used by services

AI Product Security Assessment, AI Security Maturity Benchmark

Helps produce

AI Security Discovery / Intake Pack, AI Architecture Review, AI Control Gap Assessment

AttackDefendengagement-only
Map

SecEng Surface Scanner

Find AI vendors, SDKs, widgets, runtime signals, shadow AI, and exposed routes, model touchpoints, scripts, forms, and AI-adjacent attack surface.

Used by services

AI Product Security Assessment, AI Security Maturity Benchmark

Helps produce

AI System Inventory / Application Register, AI Control Gap Assessment

Evidenceearly access
Map

Local-first AI Security Scorecard

Runs in your browser. Keeps inputs local. Produces a practical risk, control, and evidence gap view — the public product-led entry point to AI security assessment.

Used by services

AI Security Maturity Benchmark, AI Governance & Security Program Build

Helps produce

AI Security Maturity Scorecard, AI Control Gap Assessment, AI Security Remediation Roadmap

Evidencelive demo

Attack

Attack instruments

Open Attack pillar
Attack

SecEng Authority Graph — Agent Blast-Radius Map

Map what agents can read, write, send, execute, approve, and trigger across connected systems. Score blast radius and flag dangerous compositions.

Used by services

Agentic Workflow Abuse Review, Agentic Workflow Security & Hardening

Helps produce

Agent Tool Inventory / Tool BOM, Agent Tool Permission Matrix, Agent Abuse Scenario Register

MapDefendlive demo
Attack

SecEng RAG Test Harness — XPIA Lab

Test retrieval authorization, XPIA (indirect prompt injection), RAG poisoning, stale permissions, source provenance, context leakage, and tool-context abuse.

Used by services

AI Product Security Assessment, AI Red Team & Adversarial Testing, AI Guardrails & Evals Review

Helps produce

RAG Authorization Review, RAG & XPIA Security Test Plan, AI Red-Team Findings Register

MapDefendlive demo
Attack

SecEng Adversarial Range

Run reproducible adversarial scenarios for prompts, RAG, agents, tools, policy bypass, and model misuse.

Used by services

AI Red Team & Adversarial Testing, Agentic Workflow Abuse Review

Helps produce

AI Red-Team Scope Document, AI Red-Team Findings Register, AI Red Team Assessment Executive Summary

DefendEvidencelive demo
Attack

SecEng Artifact Analyzer

Analyze artifacts for capability, authority, provenance, and evidence signals during adversarial review.

Used by services

AI Red Team & Adversarial Testing, Agentic Workflow Abuse Review

Helps produce

AI Red-Team Findings Register, AI Red-Team Remediation Roadmap

Evidenceengagement-only

Defend

Defend instruments

Open Defend pillar
Defend

SecEng Runtime Proxy — Trace, Replay, Evidence Export

Capture AI runtime traces, replay behavior for adversarial testing, and export redacted evidence packs for policy observations and audit.

Used by services

Agentic Workflow Security & Hardening, AI Guardrails & Evals Review, AI Security Sales Enablement

Helps produce

AI Release Gate Checklist, AI Security Remediation Roadmap, Enterprise AI Security Evidence Pack

AttackEvidencelive demo
Defend

Program Blueprint Kit

Turn controls, owners, release gates, evidence requirements, and remediation into tool-native program work.

Used by services

AI Governance & Security Program Build, AI Guardrails & Evals Review

Helps produce

Control Ownership Matrix, Evidence Lifecycle Plan, Program Roadmap

Evidenceengagement-only

Evidence

Evidence instruments

Open Evidence pillar
Evidence

AI Control Crosswalk — Framework Mapping Engine

A public-safe control mapping engine for translating AI security work into buyer, auditor, and governance language. Maps to OWASP, NIST AI RMF, MITRE ATLAS, ISO 42001, SOC 2, and EU AI Act.

Used by services

AI Security Sales Enablement, AI Governance & Security Program Build

Helps produce

AI Governance Evidence Matrix, AI Control Mapping Summary, Framework Crosswalk

Defendlive demo
Evidence

SecEng Trust Scanner

Review customer-facing AI and security claims for unsupported promises, evidence gaps, and safer caveated wording.

Used by services

AI Security Sales Enablement, AI Governance & Security Program Build

Helps produce

Publication & Claim-Readiness Matrix, AI Buyer FAQ, Enterprise AI Security Questionnaire Answer Bank

Maplive demo
Evidence

Evidence Library — Buyer-Ready Artifact System

Control mappings, buyer artifacts, residual-risk notes, and remediation records — reusable across questionnaires, RFPs, trust centers, and board review.

Used by services

AI Security Sales Enablement, AI Governance & Security Program Build

Helps produce

Enterprise AI Security Evidence Pack, AI Governance Evidence Matrix, Model Provider Boundary Statement

MapDefendengagement-only