The person behind the proof.
Provael is built and maintained by Sattyam Jain - an agentic-AI architect and tech lead, not a security engineer by trade, who has built security tooling for AI agents before this. The whole product rests on one promise: every number is measured, sourced, and honestly caveated. Here’s who stands behind that.
Not a security engineer by trade - an architect who builds the tooling
Sattyam is an agentic-AI architect and tech lead with 6+ years shipping production AI across fintech, AI-training, and GenAI startups - leading delivery on enterprise systems spanning insurance, healthcare, legal, geospatial, and industrial software. He is not an AI-security engineer by background. What he brings instead is the habit of building the security layer himself: agent-airlock, a deny-by-default contract layer for AI-agent tool calls, and agent-audit-kit, a static scanner for MCP-connected agent pipelines that reports in SARIF.
He created pyAGI, an autonomous-agent Python framework, in 2023. It was acquired in 2025 by Kyle Morris (co-founder of banana.dev and a member of AGI House) and Jeffrey.
His work centres on the parts of AI that are hardest to trust - agentic-AI governance, security, and observability - and on mapping AI systems to the frameworks regulators and auditors actually cite (EU AI Act, NIST AI RMF, OWASP, ISO). Provael is where that expertise meets robotics.
Text-layer red-teaming stops at the sentence. Robots don’t.
Every AI-security tool today scans what a model says. But a vision-language-action policy turns language and perception into motion - so the failure isn’t a toxic paragraph, it’s a trajectory across a keep-out line. That action layer is the part text-only tools structurally can’t reach, and no security framework fully covers it yet - OWASP’s own Agentic Top 10 has a documented physical-actuation gap.
Provael exists to measure that layer honestly: an attack-success rate with a 95% confidence interval and a benign control, published nulls and all. Not “we broke it once” - a reproducible number you can file with a regulator, hand an insurer, or gate a build on.
Verified, or it doesn’t ship
Provael publishes negative results as loudly as positive ones. When an attack does not transfer to a real policy, the site says so - plainly, in the same sentence as the number. That discipline is the whole brand: the value of a security measurement is its honesty.
See what Provael measures.
Run it yourself, or read the one real result - published with its confidence interval and its honest nulls.