SECURITY POLICY

Handle important information
only to the extent required.

For customer assessments, scope, stop conditions, data, accounts, and storage are agreed in advance. The Simulator is operated separately as a controlled local environment.

ASSESSMENT POLICY

How assessment information is handled

Mock or anonymized data and dedicated assessment accounts are preferred. Production data and credentials are minimized whenever the objective can be achieved without them.

01

Minimum necessary information

Collect only configuration, authorization, APIs, test data, and logs needed for the agreed purpose.

02

Prefer mock or anonymized data

Use fictional or anonymized data when it can satisfy the assessment objective.

03

No unapproved external AI submission

Customer information is not sent to external generative-AI services without approval.

04

Controlled storage and access

Use agreed devices and storage locations and avoid unnecessary cloud synchronization.

05

Short-lived least privilege

Prefer dedicated accounts and short-lived credentials with minimum privilege.

06

Preserve only necessary evidence

Retain decision and execution evidence while masking sensitive content when appropriate.

SIMULATOR SAFETY

The Simulator is a closed environment for observing AI attack and defense without putting production systems at risk.

The AI Security Simulator uses a fictional enterprise, mock data, and Safe Mock Tools. It is operated separately from customer assessment environments.

No direct production-system operation

Agents do not directly control the real OS, arbitrary files, the open Internet, or production services.

No production credentials required

The demo does not require customer credentials or production API keys.

Safely reproduce security boundaries

Product information, shared workspaces, web applications, APIs, RAG, and similar paths are represented as controlled mock targets.