PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

AI SECURITY WORKBENCH · MAP

Browser, Repo, IDE & Surface Discovery

Find the AI surface before you model the system.

Surface Discovery inventories AI applications, model providers, SDKs, prompts, retrieval systems, agents, MCP servers, browser and IDE surfaces, runtime signals, tools, and external boundaries so the system can be modeled, tested, hardened, and evidenced against an explicit inventory.

WHAT AI DO WE HAVE?

Technology resolution

Resolve model providers, SDKs, agent frameworks, widgets, services, and runtimes through a maintained catalog.

Browser and runtime snapshots

Accept approved snapshots containing HTML, DOM, globals, storage, network, script, URL, and header signals.

Multi-source discovery

Correlate browser, repository, IDE, configuration, package, endpoint, and runtime indicators where supported.

Structured discovery output

Return detected technologies, family labels, confidence, evidence references, catalog version, and disclosure state for downstream use.

Surface Discovery view showing detected providers, SDKs, browser signals, widgets, and runtime fingerprints

1,000+

AI technologies across vendors, SDKs, tools, and runtimes in the embedded catalog

10

signal families evaluated per browser snapshot

23

detection families spanning model providers to commerce AI

1

shared source of truth across WASM, routes, and UI

Core capabilities

What Surface Discovery does.

AI technology detection

Detect model providers, inference runtimes, coding assistants, agent frameworks, retrieval systems, developer tools, embedded AI services, and product-facing AI surfaces.

Framework and SDK classification

Classify the frameworks, orchestration layers, widgets, runtimes, and third-party services contributing to the AI application.

Browser and runtime fingerprinting

Use approved HTML, DOM, script, global, storage, cookie, URL, network, and header signals to identify AI surfaces that do not report themselves cleanly.

Snapshot analysis

Normalize discovery signals into structured technology, family, confidence, evidence, and catalog-version records.

Inventory export

Produce an inventory suitable for Threat Canvas, ownership review, technical assessment, evidence planning, and partner workflows.

Discovery harness

Use shared detection logic across approved crawlers, snapshots, fixtures, and Workbench interfaces.

Evidence & signals

What you get out of the box.

Detected Families

  • Model Providers
  • SDKs & Frameworks
  • Inference Runtimes
  • Vector Databases
  • Guardrails & Evals
  • Developer Tools & Coding AI
  • Voice & Meeting AI
  • Document & OCR AI
  • Commerce & Personalization AI
  • Generative Media & Avatars
  • Analytics & Experimentation AI
  • Support & Enterprise Copilots

Signal Sources

  • HTML
  • Scripts
  • DOM
  • Globals
  • Headers
  • Cookies
  • Storage
  • URLs
  • Network

Output Fields

  • ai_matches
  • ai_family_summary
  • catalog_version
  • snapshot_summary
  • public_safe
  • confidence

Red team + Blue team

Built for both sides of the security equation.

Adversarial planning

  • Identify undocumented AI endpoints, widgets, SDKs, runtimes, and tool surfaces.
  • Find shadow AI providers and external dependencies that change the test scope.
  • Contribute target and boundary context for bounded adversarial scenarios.

Security and governance use

  • Produce an AI technology and application inventory with confidence and evidence references.
  • Assign owners and identify unsupported or unreviewed providers.
  • Contribute system entities and boundaries to Threat Canvas and later evidence.

Retrieval security follow-on

From discovered retrieval signals to a bounded test plan.

Bounded handoff

Retrieval security follow-on

When retrieval technologies are discovered, those signals can feed RAG Security Testing to define authorization, provenance, tenant-boundary, poisoned-content, and context-integrity tests.

Discovery

Surface map

Boundary

Scorecard flow

Output

Bounded test plan

AI SECURITY WORKBENCH

Discover the AI surface before the review begins.

Use Surface Discovery to establish the technology, provider, framework, prompt, retrieval, agent, tool, and external-boundary inventory that later mapping and testing depend on.