Guides, references, and API docs for running Breach & Attack Simulation against your LLM applications.
Learn how to set up your first attack simulation against an LLM-integrated endpoint.
Defense lattice methodology, engine probes, and grading rubric — how the engine actually scores.
REST API reference for programmatic access to the simulation engine.
Understanding risk scores, severity levels, and confidence intervals.
How to export and share checksum-verified evidence packs from eligible Starter+ runs with your auditors.
Understand the planned tenant webhook delivery contract and the limits of the current release.
One controlled run of probes against an allowed target — what gets sent, how it's graded, and what comes back.
How attacker personas drive probe selection and why the same target can produce different findings across personas.
From a finding to a prioritized remediation action: which controls close which probes, traced back to the run.
How DoesItDefend maps probes to the OWASP LLM Top 10 — what each category covers and how scoring rolls up.
The grading lattice (covered / partial / gap / untested) and why aggregating across paraphrases matters.
How matched literal and paraphrased probes can reveal wording sensitivity — and why the value remains N/A without a paired evaluation.
Wire the CLI / GitHub Action into a repo so every PR runs the gate against the changed prompt files.
How findings translate to NIST AI RMF, EU AI Act, SOC 2 and ISO 27001 controls in the evidence pack.
Sandbox-only public score badge for READMEs and landing pages. SVG + JSON endpoints, embed in two lines.
How the gate decides PROMOTE / HOLD on a pull request from the diff alone — the data path from PR to verdict.
DNS TXT challenge to prove you control a target before any probe touches it. CFAA / Marco Civil layer.
Author scenarios from your own attack templates and run them like any built-in catalogue entry.
SAML 2.0 and OIDC for tenant logins. Metadata storage, enforced-domain routing, and what's not implemented yet.
How active-user seats work, how invites consume the quota, and how the gate re-checks at accept time.
Understand the planned tenant delivery boundary and the integrations available in this release.
Cron-style cadence (hourly / daily / weekly) on a saved RunRequest template. Continuous defense validation, hands-off.
Diff two evidence-compatible runs by canonical score and finding lifecycle, with explicit evidence coverage. The replay surface for scoped change validation.
Install once, gate every PR. The App listens to pull_request events and posts a Check Run + comment with the verdict.
Common questions about pricing, scoring, tenancy, audit posture, and sandbox usage — all in one place.
Coordinated attack chains, not parameterized scripts. Four-phase pipeline, finding-based routing, and what 'adaptive' means in practice.