Start free. Pay when you need it signed.
The tool that red-teams your policy is free and open-source, and it always will be. You pay only for the operated work a solo tool can't do for you: an independent, human-run assessment, a continuous gate on your fleet, and a signed evidence pack a buyer, insurer, or certifier can review. Everything runs in simulation. Evidence, not certification.
Install the CLI, run every attack family against your policy, read an attack-success rate with a benign control, and gate CI on it. No sales call, no GPU to start.
~2,500 downloads/month on PyPI (PyPI counts include mirrors and CI, so a weak signal).
For robotics & humanoid teams →Get an independent, reproducible measurement - mapped to the EU Machinery Regulation, ISO 10218:2025, IEC 62443 and NIST AI RMF - that your diligence, insurer, or certifier can actually work from.
For certifiers & insurers →Pricing tiers
Open core
Run the full red-team yourself. Every attack family, the ASR with its benign control, SARIF and local attestation are in the free tool.
- The CLI and every attack family
- Attack-success rate with a 95% Wilson CI + benign control
- SARIF + the GitHub Action CI gate
- The Embodied AI Security Top 10 + local Ed25519 attestation
Checkpoint Report
A fixed-scope red-team of one checkpoint, no scoping call. Credited in full against a later assessment.
- One checkpoint of yours, one suite, every attack family
- Measured ASR with 95% Wilson CIs, a benign control, and a clean-task-success control
- The full evidence pack: SARIF + a signed, offline-verifiable attestation
- Delivered in 5 business days; the fee credits in full against a later assessment
Embodied-AI Red-Team Assessment
An independent, human-led red-team of your policy in simulation, with an evidence pack you can file.
- A human red-teamer operating on your own policy, not a public proxy checkpoint
- The keep-out predicate calibrated to your declared safety envelope
- Narrated attack chains + a filable evidence pack (SARIF, OSCAL, ML-BOM)
- One free retest after you remediate, plus the signed attestation included
Continuous assurance retainer
Standing evidence for a moving policy: re-run the red-team each release and hold the line in CI.
- Quarterly retest + new-attack-family coverage
- A rolling per-checkpoint regression baseline
- CI gated on your attack-success-rate threshold
- Priority triage when a result regresses
Team / fleet-CI
The continuous CI security gate as a subscription: every checkpoint red-teamed on every release, across the fleet.
- Per-checkpoint continuous red-team in CI
- The GitHub Action gate, synced across your fleet
- A fleet-wide ASR view + regression alerts
- Shared thresholds and evidence history
Compliance & attestation report
An evidence pack for insurer and certifier review: the assurance views over a real run, signed and verifiable.
- ISO 10218-2 / IEC 62443 SL2 / insurer assurance views
- OSCAL assessment-results + a CycloneDX ML-BOM
- Ed25519-signed attestation (verifies offline)
- The honest per-family transfer statement
Before you compare tiers, read the deliverable. Every paid tier produces the same artifact, and it is published in full at the sample evidence pack - the real one, not a mock-up. The founding-cohort rate and exactly what it trades for are on design partners.
Provael is built and maintained by one person. That is a real dependency for anything you rely on, so it is stated here rather than left to the About page: the tool is Apache-2.0 and forkable, every result is reproducible from a committed recipe, and no evidence you already hold stops being valid if this project does. What a single maintainer cannot offer is a service level, and none is published for that reason.
Procurement diligence — the answered security questionnaire, sub-processors, DPA and rules-of-engagement templates, and what the tool never receives — is at /trust. Distribution figures, measured rather than illustrated, are at /adopters.
Pricing is a scoped starting range, not a fixed quote - an assessment is a one-time engagement sized to your policy and fleet. Everything Provael runs is defensive and simulation-only, against systems you own or are authorized to assess. A Provael report is candidate evidence toward an assessment, not a certificate and not a notified-body opinion. The Embodied AI Security Top 10 is an independent community framework, not affiliated with OWASP.Evidence, not certification.
Run it free today, or book a scoping call.
Install the open-core tool and read your own attack-success rate in an afternoon - then bring us in when you need an independent, signed result for a milestone, a raise, or an audit gate.