AI SECURITY WORKBENCH · MAP
Browser, Repo, IDE & Surface Discovery
Find the AI surface before you model the system.
Surface Discovery inventories AI applications, model providers, SDKs, prompts, retrieval systems, agents, MCP servers, browser and IDE surfaces, runtime signals, tools, and external boundaries so the system can be modeled, tested, hardened, and evidenced against an explicit inventory.
Technology resolution
Resolve model providers, SDKs, agent frameworks, widgets, services, and runtimes through a maintained catalog.
Browser and runtime snapshots
Accept approved snapshots containing HTML, DOM, globals, storage, network, script, URL, and header signals.
Multi-source discovery
Correlate browser, repository, IDE, configuration, package, endpoint, and runtime indicators where supported.
Structured discovery output
Return detected technologies, family labels, confidence, evidence references, catalog version, and disclosure state for downstream use.
1,000+
AI technologies across vendors, SDKs, tools, and runtimes in the embedded catalog
10
signal families evaluated per browser snapshot
23
detection families spanning model providers to commerce AI
1
shared source of truth across WASM, routes, and UI
Core capabilities
What Surface Discovery does.
AI technology detection
Detect model providers, inference runtimes, coding assistants, agent frameworks, retrieval systems, developer tools, embedded AI services, and product-facing AI surfaces.
Framework and SDK classification
Classify the frameworks, orchestration layers, widgets, runtimes, and third-party services contributing to the AI application.
Browser and runtime fingerprinting
Use approved HTML, DOM, script, global, storage, cookie, URL, network, and header signals to identify AI surfaces that do not report themselves cleanly.
Snapshot analysis
Normalize discovery signals into structured technology, family, confidence, evidence, and catalog-version records.
Inventory export
Produce an inventory suitable for Threat Canvas, ownership review, technical assessment, evidence planning, and partner workflows.
Discovery harness
Use shared detection logic across approved crawlers, snapshots, fixtures, and Workbench interfaces.
Evidence & signals
What you get out of the box.
Detected Families
- Model Providers
- SDKs & Frameworks
- Inference Runtimes
- Vector Databases
- Guardrails & Evals
- Developer Tools & Coding AI
- Voice & Meeting AI
- Document & OCR AI
- Commerce & Personalization AI
- Generative Media & Avatars
- Analytics & Experimentation AI
- Support & Enterprise Copilots
Signal Sources
- HTML
- Scripts
- DOM
- Globals
- Headers
- Cookies
- Storage
- URLs
- Network
Output Fields
- ai_matches
- ai_family_summary
- catalog_version
- snapshot_summary
- public_safe
- confidence
Red team + Blue team
Built for both sides of the security equation.
Adversarial planning
- Identify undocumented AI endpoints, widgets, SDKs, runtimes, and tool surfaces.
- Find shadow AI providers and external dependencies that change the test scope.
- Contribute target and boundary context for bounded adversarial scenarios.
Security and governance use
- Produce an AI technology and application inventory with confidence and evidence references.
- Assign owners and identify unsupported or unreviewed providers.
- Contribute system entities and boundaries to Threat Canvas and later evidence.
Retrieval security follow-on
From discovered retrieval signals to a bounded test plan.
Bounded handoff
Retrieval security follow-on
When retrieval technologies are discovered, those signals can feed RAG Security Testing to define authorization, provenance, tenant-boundary, poisoned-content, and context-integrity tests.
Discovery
Surface map
Boundary
Scorecard flow
Output
Bounded test plan
AI SECURITY WORKBENCH
Discover the AI surface before the review begins.
Use Surface Discovery to establish the technology, provider, framework, prompt, retrieval, agent, tool, and external-boundary inventory that later mapping and testing depend on.
Continue through the Workbench
Continue through the Workbench
Threat Canvas
Turn discovered components and boundaries into a reviewable system and flow model.
Continue through the Workbench
Prompt Asset Scanner
Inventory the prompts and instructions shaping application behavior.
Continue through the Workbench
Tool Analyzer
Classify callable capabilities, permissions, authentication, and side effects.
Continue through the Workbench
Code Scanner
Analyze the implementation and produce AI-specific findings and code-risk paths.