NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

SECENG WORKBENCH

Browser, Repo, IDE & Surface Discovery

Find AI systems, data paths, and tool boundaries before they become attack surfaces.

SecEng Surface Scanner inventories AI apps, model calls, prompts, RAG paths, agents, MCP servers, browser extensions, IDE plugins, and external tool boundaries so teams know what exists before they assess, harden, or evidence it.

WHAT AI DO WE HAVE?

Vendor Registry

Resolve model providers, SDKs, agent frameworks, widgets, and runtimes from one canonical catalog.

Browser Snapshot Input

Accept live browser snapshots with HTML, DOM, globals, storage, network, and header signals.

Signal Breadth

Trace DOM markers, script URLs, runtime globals, cookies, URL hints, and API endpoints.

Public-Safe Output

Export confidence, family summary, evidence hits, and catalog version for downstream automation.

SecEng Surface Scanner — AI surface radar map showing detected vendors, SDKs, browser signals, widgets, and runtime fingerprints

1,000+

AI technologies across vendors, SDKs, tools, and runtimes in the embedded catalog

10

signal families evaluated per browser snapshot

23

detection families spanning model providers to commerce AI

1

shared source of truth across WASM, routes, and UI

Core capabilities

What SecEng Surface Scanner does.

AI Vendor & Runtime Detection

Detect model providers, inference runtimes, coding assistants, voice AI, document extraction, commerce AI, generative media, and enterprise copilots from the same catalog — over 1,000 entries across 23 detection families.

SDK, Widget, and Framework Classification

Classify LangChain, LangGraph, LlamaIndex, Semantic Kernel, AutoGen, CrewAI, Haystack, Dify, Flowise, Botpress, Voiceflow, Intercom Fin, Botsonic, Ada, Crisp, Zendesk AI, Gorgias, and hundreds of similar embedded surfaces.

Browser Runtime Fingerprinting

Use HTML, DOM, globals, cookies, storage, URL, network, and script-path heuristics to find AI surfaces that do not self-report cleanly.

Snapshot-Native Analysis

Accept live browser snapshots from crawlers or extension-based capture and return ai_matches, ai_family_summary, snapshot_summary, and catalog_version in one payload.

Public-Safe Inventory Export

Export a structured inventory with confidence, family labels, evidence hits, public_safe flags, and canonical vendor metadata for downstream reporting.

Live Scan Harness

Use the browser harness and snapshot route to iterate against real pages, DOM captures, and local fixtures without forking the detection logic.

Evidence & signals

What you get out of the box.

Detected Families

  • Model Providers
  • SDKs & Frameworks
  • Inference Runtimes
  • Vector Databases
  • Guardrails & Evals
  • Developer Tools & Coding AI
  • Voice & Meeting AI
  • Document & OCR AI
  • Commerce & Personalization AI
  • Generative Media & Avatars
  • Analytics & Experimentation AI
  • Support & Enterprise Copilots

Signal Sources

  • HTML
  • Scripts
  • DOM
  • Globals
  • Headers
  • Cookies
  • Storage
  • URLs
  • Network

Output Fields

  • ai_matches
  • ai_family_summary
  • catalog_version
  • snapshot_summary
  • public_safe
  • confidence

Red team + Blue team

Built for both sides of the security equation.

Red Team Use

  • Find hidden attack surface: undocumented AI endpoints, embedded widgets, runtime globals, and SDK bundles
  • Identify shadow AI providers and tool calls before they spread across the product estate
  • Trace browser-level signals that a vendor never documented but still ships in production

Blue Team Use

  • Produce an AI asset register with vendor, family, confidence, public-safe flag, and evidence hits
  • Generate evidence bundles for product security, governance, and executive reporting
  • Keep the WASM, route, and browser harness aligned to one shared catalog and schema

How teams use it

Surface inventory turns into RAG boundary plans, threat models, and governance evidence.

Shared component

Trace, Chrome, and Surface now use the same RAG lens

The demo keeps the public story honest: the Surface page shows the discovery layer, and the RAG lens shows how those signals turn into boundary plans, testcases, and evidence classification.

Discovery

Surface map

Boundary

Scorecard flow

Output

Harness bundle

Public-safe fixture scope

seceng-rag/seceng-rag.config.jsonseceng-rag/identities.jsonseceng-rag/documents.jsonseceng-rag/tests.jsonseceng-rag/fixture-plan.md

The lens exposes the artifact names, control paths, and test intent without publishing raw documents, raw answers, or private payloads.

SecEng RAG Test Harness

RAG Boundary Lens

Boundary planning, testcase generation, and evidence classification rendered from the same public-safe trace fixture.

RAG detectedClaim-ready preview
72boundary
Boundary score
72/100
RAG detected
Yes
Affected paths
3
Top tests
3

AuthZ pass

Pass
green

Retrieval gates are mostly aligned.

Context leaks

0
green

No leak-shaped signals surfaced.

Policy violations

2
amber

Policy language needs stronger enforcement.

Pipeline snapshot

5
Surface inventoryBoundary planningTestcase generationEvidence classificationHarness export

Suggested tests

3
Cross-tenant namespace escape regressionPoisoned chunk provenance rejectionContext leak after redaction and rerank

Controls found

3
packages/governance/policies.tsdocs/ai/trace-runbook.mdapps/web/app/api/assistant/route.ts

Affected paths

2
packages/rag/index.tspackages/rag/vector-store.ts

Missing boundaries

Priority gaps

Tenant-scoped retrieval authorizationChunk provenance taggingPoisoned context quarantine

Top tests

Harness checks

1Tenant boundary enforcement on retrieval
2Provenance-preserving answer assembly
seceng-rag/seceng-rag.config.json
seceng-rag/identities.json
seceng-rag/documents.json
seceng-rag/tests.json

The lens is public-safe and directional. It uses job-description intelligence and trace fixture signals to show where RAG boundaries need reinforcement, without exposing raw documents or private payloads.

SECENG WORKBENCH

Map the AI surface before it becomes an attack surface.

Scope a Workbench-backed review to inventory AI apps, providers, SDKs, browser signals, RAG paths, agents, tools, and evidence gaps.