Minimum necessary information
Collect only configuration, authorization, APIs, test data, and logs needed for the agreed purpose.
For customer assessments, scope, stop conditions, data, accounts, and storage are agreed in advance. The Simulator is operated separately as a controlled local environment.
Mock or anonymized data and dedicated assessment accounts are preferred. Production data and credentials are minimized whenever the objective can be achieved without them.
Collect only configuration, authorization, APIs, test data, and logs needed for the agreed purpose.
Use fictional or anonymized data when it can satisfy the assessment objective.
Customer information is not sent to external generative-AI services without approval.
Use agreed devices and storage locations and avoid unnecessary cloud synchronization.
Prefer dedicated accounts and short-lived credentials with minimum privilege.
Retain decision and execution evidence while masking sensitive content when appropriate.
The AI Security Simulator uses a fictional enterprise, mock data, and Safe Mock Tools. It is operated separately from customer assessment environments.
Agents do not directly control the real OS, arbitrary files, the open Internet, or production services.
The demo does not require customer credentials or production API keys.
Product information, shared workspaces, web applications, APIs, RAG, and similar paths are represented as controlled mock targets.