PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

OP-04

Attack Engine and Evidence Plane

The partner keeps attack generation and operator workflow while the OEM Engine adds context, qualification, evidence, and defensible return objects.

comparison

BEFOREPartner attack engineGenerate or orchestrate attacksOperator workflow and UXExecution and observed behaviorCustomer relationship and productcontextAFTEROEM Engine context and evidence planeArchitecture and authority contextEvidence and sequencequalificationShared weaknesses and chokepointsStructured partner-return objectQUALIFIED INTOOWNERSHIP BOUNDARYThe partner keeps its attack engineNo claim that the partner only producesisolated attacksPartner-native return remains a pilotobjective until proven

About this figure

This comparison frames a split architecture for offensive work: the partner retains the attack engine, operator workflow, and product-native execution loop, while the OEM Engine contributes the context layer that qualifies what was run, what was observed, and how it should be interpreted. The partner continues to generate or orchestrate attacks and own the customer relationship, UX, and operational flow; the OEM Engine adds architecture and authority context, evidence capture, and sequence qualification so results are defensible and reusable. The boundary is deliberate: the partner keeps its attack engine, but the return path is enriched with structured evidence rather than isolated attack outputs. That makes the shared chokepoints explicit and keeps the partner-native return object as a pilot objective until it is proven.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/partners/offensive-platforms-expansion.dsl.md" figureId="OP-04" />

Citation

Attack Engine and Evidence Plane (OP-04). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/OP-04