FAQ

Frequently asked questions

The assessment service and the AI Security Simulator have different purposes. Questions are separated below.

ASSESSMENT FAQ

About the assessment service

What does the assessment evaluate?
It does not benchmark general knowledge or writing quality. It tests whether the AI agent respects user, data, action, tool/API, and communication boundaries using execution results and evidence.
Can it be performed in production?
Yes when scope, stop conditions, recovery procedures, timing, and dedicated accounts are agreed in advance. Test or mock environments are preferred.
Do we need to provide production data or API keys?
Mock or anonymized data, dedicated assessment accounts, and short-lived credentials are preferred. Excess data disclosure is not a prerequisite.
Are RAG, MCP, SaaS, and external APIs included?
Yes. Connected data sources, tools, APIs, SaaS services, and communication paths can be included within the agreed scope.
What are the deliverables?
Depending on scope: boundary maps, results, conditions for reproduction, evidence, and prioritized remediation guidance.
SIMULATOR FAQ

About the AI Security Simulator

Is the Simulator a diagnostic tool?
No. It is a controlled demo and experimental environment for running an Attack Agent and a Defense Agent and observing exploration, detection, blocking, strategy changes, and evidence. It does not judge the security of a customer environment.
Why was the Simulator built?
Because the final answer alone does not show what the agent tried after denial or when the defensive side recognized abnormal behavior. The Simulator makes that sequence visible.
Does it attack real systems?
No. It uses a fictional enterprise, mock data, and Safe Mock Tools in a closed local environment.
What can the demo show?
Attack/Defense decision streams, exploration maps, security scoring, before/after comparison, and Evidence/Audit views.
Can we see it remotely?
Yes. We can join your usual Teams, Google Meet, Webex, or Zoom meeting and demonstrate the local system through screen sharing.