Attack a real AI agent inside an isolated test organisation. Watch what your security stack catches, and what it lets through. No sales call.
We use your work email to name the tenant and send the evidence bundle afterwards. That is the whole reason we ask.
No card. No call. No calendar link. The tenant lives for 60 minutes and is destroyed with everything in it. Attacks run only against the synthetic organisation you pick above, never against anything you own.
A real agent estate, a real detection platform in front of it, and a real attack engine pointed at both.
Discovery records configuration observations, each with a stated source. It does not sniff your
network and it does not test anything. Every one of the eleven properties per asset is required, and
a property the source does not state is stored as unknown, never as a blank, a dash, or a
flattering default. record_provenance
on every row here is fixture: these
assets came from a specification document, not from an observation of a running estate, and the
product says so rather than implying otherwise.
None of the three states is coloured. Green means prevention on our surfaces and red means proven attack success, and a conjunction state is neither. Meets is a reason to look first, not a finding. Fails on stated value is one leg stated false, not a clean bill of health.
ordering_state = declined · rank_position = null on every row, at every set size.
Every member of the returned set satisfies the same three legs, the conjunction is the only permitted
discriminator, and it is uniform within the set by construction. So no member is first, highest or top
ranked. A caller looking for a rank finds a null and this reason, not an arbitrary element.
Unsanctioned first. Click an asset to read its recorded properties and see which legs decided its state.
Unsanctioned · unregistered
NORTHWAY-FINANCIAL-fixture-spec.md v1.0, section 5.1
Recon characterises the detection surface, not your estate. It sends a graded ladder of five stimuli through the platform's inspection API and records where the active policy first reacts. It makes no model call and no database access, so it is cheap, deterministic and side-effect free. The result is frozen to disk and pinned, so the attack that follows is reproducible against a known surface. ATLAS: AML.T0056, AML.T0051.000, AML.T0043.
Five rungs, overtness rising with intensity. Deliberately less potent than the live payloads: the goal is to locate the detector threshold, not to maximise attack success.
What the resolver consumes. Pure function of these four fields.
Recon states what it could not measure, and why. These are declared, not silently omitted.
Same engine, same payloads we run in a paid engagement. Nothing is watered down for the sandbox.
Three stages, run in sequence.
Each stage is inspected on the way in and on the way out. Both results are shown.
Everything this tenant produced, signed and timestamped. Yours whether or not you buy anything.
Same engine. Your agents instead of ours.
You have now seen the product do the thing it claims to do, against an estate you did not have to expose. The only thing a call would add is a price, so here it is.
Four questions. You get an indicative number on screen, not a callback.
Link, email, sandbox, evidence, price. The buyer proves the product to themselves and never speaks to anyone until they want to.
This is what a sales call would have asked you. It takes about thirty seconds and you get an indicative band immediately, on this page, before anyone contacts you.
Indicative, not a quote. It is built from the same four inputs we would use on a call, so it should land close. A formal quote needs a look at your actual estate, which is the next step and the first point at which a human is involved at all.
You have run the product, seen the evidence, and got a number. This is the first point where a person is genuinely useful, because a formal quote needs someone to look at your real estate.
What we will not do. No drip sequence, no retargeting, no third party gets your address. If you never reply we send one follow-up and then stop.