AI security research
AI security research, shipped as products
We research AI attack surfaces in the open and turn the findings into the Agent Security API — stopping injection, privilege abuse and leaks before each agent step.
Focus
Where we look
- 01Agents & tool use
- How an agent is steered into calls its user never asked for.
- 02Prompt injection
- Instructions hidden in the content a model is asked to read.
- 03Multimodal
- Attacks carried in images, audio and documents.
- 04Embodied AI
- What changes when the model can move things in the world.
From research
What the research became
Agent securityAgent Security API The attacks we publish, checked before each agent step: allow, review or block.Content provenanceProvenance Inspector Reads the C2PA credentials and IPTC tags AI vendors embed, to show where an image came from and whether it declares AI generation. No declaration, no verdict — it never guesses.
Principles
How we do research
- Responsible disclosure
- Affected vendors hear first; details go public once a fix ships. Disclosure policy →
- Reproducible
- Every study ships with its reproduction steps and test conditions.
- Verifiable evidence
- Key findings carry hashes and the original evidence, so readers can check them.
Newsletter