product
Red Team
Adversarial tests on your systems.

customers
ubicloudevry healthdotenvxfirecrawlcapchasenangomastrapaperclip
why
scanners list known cves. this tries to break the thing you actually run.
a finding includes the repro and the payload that worked.
modalities
agent
black-box tests against a deployed agent, over a browser ui.
model
an http or websocket api. you describe the contract; we send the attack prompts.
web app
browser-driven dast on a public url. no source. the public surface only.
repo
a security agent clones the github repo into a sandbox and chains exploit paths. gray-box.
package
we follow your install instructions in a sandbox, then try to break the installed software.
how it works
three steps
01 pick a target. a repo, a live app, an agent, a model api, or a package.
02 start a report. we attack it. findings land on the report page as the run finishes.
03 read the findings. repro steps and the payload that worked, on each one.
get started
free for open source.
the whole suite, on any public repo. private repos are paid — contact us and we'll set you up.