SecEng Workbench · Map
Surface Scanner — Live Demo
Repo scan · acme-corp/acme-assistant-platform
112
Signals found
9
Vendors resolved
84
Adoption score
62
Security score
6
Risks flagged
2
Shadow AI
Vendor catalog resolution
6 vendors resolved from 112 signals
OpenAI
LLM provider
LangChain
Agent framework
Pinecone
Vector store
Guardrails AI
Guardrails
HuggingFace
Model hub
LiteLLM
LLM proxy
RAG boundary analysis · from surface signals
SecEng RAG Test Harness
RAG Boundary Lens
Boundary planning, testcase generation, and evidence classification rendered from the same public-safe trace fixture.
classifyRagEvidence
Evidence scorecard
AuthZ pass
Retrieval gates are mostly aligned.
Context leaks
No leak-shaped signals surfaced.
Policy violations
Policy language needs stronger enforcement.
Poisoned chunks
No poisoned chunk patterns detected.
PII / secret hits
Redaction surfaced one or more hits.
Source provenance
Source attribution and retrieval lineage need follow-up.
Missing boundaries
What still needs to be enforced
Top 3 tests
Highest-priority harness checks
Pipeline map
planRagBoundaries → generateRagTestcases → classifyRagEvidence
Suggested tests
Controls found
Affected paths
The lens is public-safe and directional. It uses job-description intelligence and trace fixture signals to show where RAG boundaries need reinforcement, without exposing raw documents or private payloads.
Ready to scan your own surface?
Run Surface Scanner against your product estate — browser, repos, and VS Code workspaces.