Authorization first. Every time.
We perform real adversarial actions against submitted AI systems. That only happens with explicit authorization — never against a live third party you haven't told us you own or are cleared to test.
Consent-based testing only
Every submission requires explicit attestation that you own the system or hold clear authorization to have it tested. We log the timestamp, IP address, and submitted content of every request as part of that authorization record. See our Terms of Service for the full policy.
MITRE ATLAS-mapped findings
Every technique maps to an official MITRE ATLAS or ATT&CK technique ID, cross-checked live against the published framework — not a subjective in-house severity label.
Live NVD/CVE cross-reference
Where a finding relates to a known vulnerability class, we cross-reference live against the National Vulnerability Database rather than relying on a static, potentially stale internal list.
Methodology stays protected
Customer-facing reports show what was found and how severe it is — not the exact payload or reproduction steps. That protects both your system (no exploit recipe left lying around) and our methodology.
Minimal retention, no resale
We don't sell submitted data. Submission content and results are retained only as long as needed to deliver the service and maintain the authorization record. Full detail in our Privacy Policy.
Access-controlled by design
Every table backing this platform runs with row-level security enabled and no public policies — all access goes through server-side, service-role-gated routes. There is no direct client-side path to raw data.
We rely on the submitter's attestation, but that attestation isn't a blank check — if we receive a good-faith claim from a system owner that their system was submitted without authorization, or a valid legal request, we will provide the logged submission record (timestamp, IP, content) and take the claim seriously. False attestation carries real liability for the person who submitted it — see Section 3 of our Terms of Service.
Questions about authorization, data handling, or compliance for your specific use case? Talk to us.
