Get evidence you can file.
Book an Embodied-AI Red-Team Assessment of your VLA policy and receive an evidence pack you can file. Transparent scope, published methodology, and a redacted sample so you know exactly what you get.
Deliverables
Measured findings
Attack-success rate with 95% Wilson confidence intervals and a benign false-positive control - declared, defensible metrics on your policy.
Narrated attack chains
Each finding with a reproducible proof-of-concept and per-trial trace.
SARIF + CI gate
Machine-readable findings that drop into GitHub code scanning, plus a red-team gate for your pipeline.
Compliance crosswalk
Mapped to EU AI Act Art. 15, EU Machinery Reg, ISO 10218:2025, NIST AI RMF, IEC 62443.
Free retest
One retest after you remediate, so the evidence reflects the fixed policy.
Data handling
Runs in your environment; you keep the data. Authorized-use-only, with a rules-of-engagement letter.
Five ways to work with us.
Transparent tiers, identical evidence. Start free on a public checkpoint, or scope a full engagement on your own policy. The design-partner rate is a founding-customer discount, traded for a co-branded case study.
See the full pricing ladder - open core, fleet-CI, and the compliance report →
Or set up a continuous, per-checkpoint red-team gate in CI →
Not ready to scope a call? The fixed-price Checkpoint Report, in detail →
A fixed-scope red-team of one checkpoint of yours, delivered in 5 business days. The fee credits in full against a later assessment, so it is the cheapest way to find out whether the rest of this is worth buying.
Start a Checkpoint ReportA red-team of the public checkpoint closest to your stack (a paid assessment runs against your own policy), in simulation. Scorecard + SARIF. No NDA, no IP touched.
Request a free scanA 2-3 week engagement. In exchange for the rate, permission to publish a co-branded, anonymized-if-needed case study.
Apply as a design partnerThe same 2-3 week scope and deliverables, with no co-marketing requirement.
Book a scoping callA CI red-team gate review, quarterly retest, and new-attack-family coverage. Contact for scope.
Contact for scope- Measured ASR with 95% Wilson confidence intervals and a benign false-positive control
- Narrated attack chains, each with a reproducible proof-of-concept and per-trial trace
- SARIF findings + a CI red-team gate for your pipeline
- Compliance crosswalk: EU AI Act Art. 15, EU Machinery Reg, ISO 10218:2025, NIST AI RMF, IEC 62443
- One free retest after you remediate, so the evidence reflects the fixed policy
- Runs in your environment; you keep the data. Evidence, not certification.
Transparent engagement
Provael is built and maintained by one person. That is a real dependency for anything you rely on, so it is stated here rather than left to the About page: the tool is Apache-2.0 and forkable, every result is reproducible from a committed recipe, and no evidence you already hold stops being valid if this project does. What a single maintainer cannot offer is a service level, and none is published for that reason.
Security review before you can book? The pre-answered questionnaire, sub-processor list, DPA and rules-of-engagement templates are at /trust — including the four answers that are "No".
A typical engagement is scoped at roughly two to three weeks. Methodology is published and mapped to MITRE ATLAS, OWASP, and NIST SP 800-115. Every engagement runs under a written rules-of-engagement / authorization-to-test letter - Provael is an offensive-security tool for systems you own or are permitted to assess.
Prefer to try before you talk? Run Provael yourself - it is Apache-2.0 and CPU-first - then bring the results to the assessment.
Request a scoping call
A 30-minute scoping call. Tell us what you are deploying and what you need the evidence to show; we come back with times.
Request a scoping call →or email [email protected]