Managed offensive testing service

Offensive AI
Red Team Testing

Attack Before They Do.™

Attack your AI before deployment. Get reproducible findings, a Fix Plan, full-target retesting, and evidence your security stakeholders can review. DefendML uses scenario-based offensive testing selected for the active scan profile. Executed scope is recorded in each assessment.

Free account creation is self-service. Production and custom organization access is reviewed separately.

50/100/160
Base Profile Prompt Budgets
2/5/9
Base Profile Attack Stages
7
Evidence Frameworks
24hr
Evidence-Delivery Target

Why DefendML is Different

We find vulnerabilities. Your runtime security controls address them.

⚔️

Offensive-First Approach

Purpose-built for pre-deployment offensive red team testing. Runtime monitoring and enforcement remain separate security-control responsibilities.

Built for the Frontier AI Era

Up to 9 specialized attack stages apply adaptive pressure against your AI endpoint and preserve execution evidence for review.

🛠️

Built by Practitioners

Founder-led by a practitioner with 20 years in IT operations and security, including four SOC 2 audits.

🤖

Evidence-Linked Fix Plan Guidance

Maps recommended fixes to recorded findings using attack category, evidence, and finding context. DefendML does not apply fixes automatically.

Offensive AI Red Team Testing as a Service

DefendML ATTACKS AI systems, AI agents, and agentic workflows to find vulnerabilities. Pure offensive testing.

⚔️

Adaptive Attack Library

Execute authorized attacks drawn from a maintained library of scenario-based offensive tests. The active scan profile uses 2, 5, or 9 specialized attack stages.

  • Tests for harmful CBRN and dual-use assistance
  • Jailbreak + prompt injection resistance
  • Tests for PII leakage and data exfiltration
  • Tests for harmful cybersecurity assistance
  • Multi-turn attack sequences — simulates real attacker behavior
  • Custom objectives on approved advanced scan profiles
🤖

Evidence-Linked Fix Plan Guidance

Recorded findings can include recommended fixes derived from attack category, retained evidence, and finding context.

  • Recommended fixes mapped to findings
  • Layer interpretation distinguished from observed evidence
  • Priority-ranked remediation guidance
📊

Evidence-Ready Reports

Generate evidence-ready reports with findings mapped to OWASP, NIST, MITRE, ASL-3, SOC 2/ISO, and EU AI Act where applicable. PDF is complete evidence; CSV and JSON are summaries.

  • Complete PDF report plus CSV / JSON summaries
  • Decision rationale + timestamps
  • Mapping across 7 frameworks where applicable
🤖

Agentic AI Attack Testing

Agentic-risk scenarios sent through supported HTTP AI application endpoints. Responses do not independently verify native tool execution or downstream effects.

  • Scenarios for agent-to-agent trust boundaries
  • Scenarios for non-human identity misuse
  • Prompt-injection scenarios in autonomous workflows
  • Scenarios for agentic supply-chain risk
🎯

Adaptive Scan Selection

Scan selection responds to the configured target, objective, and recorded execution profile. Base scan profiles budget 50, 100, or 160 prompts; actual execution varies, and each assessment records what ran. Scout can direct additional pressure toward identified weak spots during execution. Ambiguous responses are evaluated semantically and shown with supporting evidence.

Scan Your AI for Free

How It Works

Three steps to offensive AI security testing and evidence-ready reporting.

1

Connect Your AI Target

Connect a supported HTTP AI application endpoint you own or are authorized to test. Confirm the testing scope through Review & Run. Organization-scoped portal access controls apply.

2

Run Offensive Red Team Scans

Run scenario-based tests selected for the active scan profile. Scan scope and actual execution can vary; each assessment records what ran and the evidence retained. A scan is not a guarantee of complete coverage or safety.

3

Export Evidence + Guidance

Review findings and advisory Fix Plan guidance, then run a full-target retest after changes. Organizations with an export entitlement can download the complete PDF evidence report and CSV/JSON summaries. Evidence-delivery target: 24 hours, not a guaranteed turnaround.

Built for accountable AI security work

From Authorized Target to Reproducible Evidence

DefendML gives security and AI teams a shared workflow for pre-deployment testing, prioritized remediation, retesting, and evidence review.

CISO & VP SecurityAppSec & Product SecurityAI-platform & ML engineeringGRC & audit stakeholders
  1. 1Register an authorized Target
  2. 2Confirm testing authority
  3. 3Run offensive testing
  4. 4Review findings and Fix Plan
  5. 5Run a full-target retest
  6. 6Export complete PDF evidence

Tenant-isolated access

Customer Targets, findings, and Reports remain separated by organization.

Write-only credentials

Credentials and custom-header values are excluded from browser-safe responses and evidence.

Truthful declarations

Agent and MCP declarations distinguish customer-declared facts from observed evidence. Missing declaration data remains UNKNOWN.

Human accountability

Testing authority, release decisions, finding interpretation, and customer claims remain accountable to a named human owner.

Explore the Evidence Workflow

See how an attempted action becomes a verified result

Follow one public-safe example from reviewed authorization through retained evidence, remediation, and retesting.

Synthetic example — no customer data and not a live assessment.

Evidence stage 1 of 8User controlled

Step 1

Authorized scope

State: CONFIRMED

Testing scope and authority were confirmed for this synthetic example.

The organization remains responsible for establishing its authority. DefendML records the reviewed scope before an assessment can proceed.

Product provenance

Review & Run authorization

Truth rule

When evidence cannot support a stronger conclusion, the state remains UNKNOWN.

Evidence, Not Claims

DefendML retains attack prompts, observed response evidence, semantic classifier interpretations, and final finding verdicts for security review.

📈

Authenticated Evidence Portal

Review authorized targets, retained scan results, severity, block rates, and recorded timestamps in the authenticated portal.

📄

Purpose-Built Exports

PDF carries the complete evidence report. CSV and JSON provide intentionally scoped summaries for analysis and automation.

🎯

7-Framework Mapping

Findings can map to OWASP LLM Top 10, OWASP Agentic Top 10, NIST AI RMF, MITRE ATLAS, and additional configured frameworks where applicable. The library includes ASL-3-aligned dual-use and CBRN testing coverage without an absolute percentage claim.

Findings mapped across 7 security and governance frameworks where applicable

OWASP LLM Top 10OWASP Agentic Top 10NIST AI RMFMITRE ATLASASL-3SOC 2 / ISO 27001EU AI Act

Two distinct access paths

Start free or request reviewed production access

Anyone can create a Free account and run the available Free scan workflow. Production and custom organization access is reviewed separately for qualified AI-first startups and SaaS teams.

Self-Service Free Access

$0

No approval required to create an account

  • Run the available Free Scout scan workflow
  • View real findings in the portal
  • See evidence, severity, category, risk summary, and recommended fixes
  • Self-service account creation
Start Your Free Scan
Available

Report Export

Available

For organizations with an export entitlement

  • Complete PDF evidence Report
  • Summary CSV export
  • Summary JSON export
  • Reproducible findings and evidence
  • Executive summary
Open Reports

Reviewed Production / Custom Access

Contact

Separate review for qualified organizations

  • Scope-reviewed Targets and scan allowance
  • Complete PDF evidence Report
  • Summary CSV and JSON exports
  • Fix Plan and full-target retesting
  • Named onboarding and agreed review cadence
Discuss Production Access

No automatic conversion or charging

Live paid billing and public paid pricing are not enabled. Creating a Free account does not request or automatically grant reviewed Production / Custom access.

Frequently Asked Questions

Try it now. Scan your AI app for free.

Review findings in the portal. Organizations with an export entitlement can download complete PDF evidence Reports and summary CSV and JSON exports.