AI SECURITY WORKBENCH
One connected security model from architecture to evidence.
Model the AI application, trace its workflows and authority, analyze code and findings, test realistic failure modes, validate consequential paths, change the controls that matter, and preserve the evidence through one connected engineering environment.
Purpose-built system modeling, static analysis, adversarial testing, runtime tracing, path analysis, remediation, and evidence infrastructure for AI applications and agents.
One workflow. Four engineering stages.
MAP
Build the connected system model.
Inventory applications, models, prompts, APIs, retrieval systems, agents, tools, identities, credentials, permissions, trust boundaries, controls, and intended flows.
ATTACK
Test the flows and qualify the paths.
Find code-risk paths, exercise adversarial scenarios, capture runtime traces, analyze authority, and determine which supported findings and relationships form consequential paths.
DEFEND
Change the controls that alter the outcome.
Constrain authority, redesign trust boundaries, add approvals and policy, prioritize remediation chokepoints, and define the conditions required to retest the original path.
EVIDENCE
Preserve what supports the conclusion.
Carry stable finding identity, provenance, relationship context, claim state, remediation, retest results, and reviewed outputs through reusable formats.
Primary access points
Use selected products directly. Keep OEM paths where they exist.
Start with the experience that matches the immediate problem. Each access point contributes to the same connected security workflow without requiring adoption of the full catalog.
Code Scanner
AI-specific static analysis and code-risk-path correlation for LLM applications, RAG, agents, MCP, prompts, tools, data, and consequential actions.
Explore Code ScannerAdversarial Range
Replayable testing for prompt, retrieval, agent, tool, multimodal, workflow, authority, and policy failure conditions.
Open Adversarial RangeAI Security Program Scorecard
A program baseline for ownership, control coverage, evidence gaps, priorities, and follow-on work.
Open ScorecardConnected Workbench experiences
Technology used inside our delivery and platform workflows.
These are not all separate products. They are the analysis, control, and evidence capabilities behind Map, Attack, Defend, and Evidence.
Threat Canvas
Model the application, trust boundaries, data flows, external dependencies, controls, and candidate abuse scenarios before testing begins.
Open Threat CanvasAuthority Graph
Trace how agents, identities, credentials, tools, permissions, approvals, and downstream actions compose into effective authority.
Open Authority GraphAdversarial Range
Exercise realistic failure flows and preserve reproducible outcomes.
Open Adversarial RangeAttack Path Analysis
Correlate supported findings, relationships, traces, and system context into candidate, supported, validated, reproduced, rejected, or residual attack paths while preserving evidence grounding, explicit inference, and remediation chokepoints.
Explore Attack Path AnalysisRuntime Trace
Capture and reconstruct prompts, retrieval, model calls, tools, identities, approvals, outputs, policy decisions, and side effects.
Open Runtime TraceEvidence System
Preserve stable identity, provenance, claim state, remediation, retest, analyst decisions, and reusable outputs.
Open Evidence SystemOEM Engine
Expose selected Workbench capabilities through bounded APIs, SDKs, schemas, partner profiles, projections, and lifecycle contracts.
Explore the OEM EngineExperimental runtime controls
Early model-routing, redaction, provider-policy, fallback, logging, and spend-control capabilities. Not a primary Workbench product.
Integrations & Connectors
Security evidence should land where the work already happens.
Connected security work should return to the systems where engineering, remediation, partner workflows, and evidence decisions already happen. Separate shipping connectors, supported exports, reference adapters, and planned mappings instead of describing all registry entries as equivalent integrations.
Native security connectors
0
Registry entries
40
No native Workbench security connector has shipped yet. The Burp Suite and OWASP ZAP entries below are example fixtures that demonstrate an integration pattern; they are not working or supported connectors. Academy/LMS delivery packages are documented on Academy and Workforce Platform pages, not here.
Reference adapter
Evidence Connector for Burp Suite
Burp Suite extension using the Montoya API to capture HTTP traffic and send findings to the sidecar.
Reference adapter
Evidence Connector for OWASP ZAP
ZAP add-on providing a passive scan rule to detect AI traffic and integrate with the sidecar.
Reference adapter
Evidence Connector for Metasploit
Metasploit auxiliary modules for discovering and fingerprinting AI infrastructure and services.