Short answers to the questions we hear most often. Open the docs or contact us if you need more depth.
DoesItDefend simulates real attacks against your web apps and AI systems, then scores how well your defenses hold up against OWASP Top 10 + OWASP LLM Top 10. Eligible Starter+ runs add checksum-verified evidence packs for auditors and security teams.
Register, generate an API token, register your first target, and POST /v1/runs with the `quick` profile. The quickstart guide walks through it end-to-end in under ten minutes.
Yes — every new tenant starts on the Free plan with up to 150 runs per month and access to the built-in scenario catalogue. No credit card required to start.
Three scan profiles: `quick` (≈5 minutes, smoke coverage), `standard` (≈15 minutes), and `deep` (≈30 minutes, full OWASP LLM Top 10 + paraphrasing). Pair any profile with a built-in or custom scenario catalogue.
You can compare two completed runs at /runs/compare?a=A&b=B. Numeric score and finding deltas appear only when the API confirms matching scope and decision-grade evidence; this is a two-run operational comparison, not a statistical A/B test.
Quick: 3–7 minutes. Deep: 25–40 minutes. Custom: depends on scenario count; the engine reports an ETA in the run dashboard.
Yes — Pro and Enterprise tenants can save a validated, tenant-scoped RunRequest template through the scenario API. Custom executable grader uploads are not part of this workflow.
Scenarios are derived from public OWASP LLM Top 10 reference probes, MITRE ATT&CK techniques, and incident reports. The full methodology — probe corpus and graders — is documented internally.
Free: 150 runs/month with the built-in catalogue. Starter: 200 runs/month. Pro: 500 runs/month plus custom scenario authoring. Enterprise: capacity as defined in your contract.
Free, Starter, Pro, and Enterprise. Free is a sandbox-only tier; Starter and Pro are self-serve (monthly or yearly); Enterprise is quote-only. Current pricing is on the /pricing page.
Yes — on-prem deployment, dedicated VPC, custom SLAs, and dedicated support. Contact hello@doesitdefend.ai.
GitHub PR integration is available today. Tenant-subscribed signed webhooks, Slack, PagerDuty, Jira, Linear, and SIEM connectors are on the roadmap; none should be treated as a native connector today.
Tenant-subscribed webhooks are not available in this release. Use the GitHub PR integration today, or contact us to discuss an integration requirement.
Encryption in transit (TLS 1.2+) and at rest (provider-managed KMS). Eligible Starter+ evidence packs include a SHA-256 checksum manifest; access is scoped per-tenant; audit log captures every state change.
We follow LGPD (Brazil), GDPR (EU), and align with the EU AI Act. Full posture is documented in the privacy and terms pages.
Still have a question?
Contact us