product

Red Team

Adversarial tests on your systems.

Agent red team report with live browser preview and attack logs

customers

ubicloudevry healthdotenvxfirecrawlcapchasenangomastrapaperclip

why

scanners list known cves. this tries to break the thing you actually run.

a finding includes the repro and the payload that worked.

modalities

agent

black-box tests against a deployed agent, over a browser ui.

model

an http or websocket api. you describe the contract; we send the attack prompts.

web app

browser-driven dast on a public url. no source. the public surface only.

repo

a security agent clones the github repo into a sandbox and chains exploit paths. gray-box.

package

we follow your install instructions in a sandbox, then try to break the installed software.

how it works

three steps

01 pick a target. a repo, a live app, an agent, a model api, or a package.

02 start a report. we attack it. findings land on the report page as the run finishes.

03 read the findings. repro steps and the payload that worked, on each one.

get started

free for open source.

the whole suite, on any public repo. private repos are paid — contact us and we'll set you up.