STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
SECURITY & CONFORMANCE READINESS · PV-READINESS

How ready is your robot fleet for the 2027 clock?

Two minutes, six questions. Score your vision-language-action policies against the Embodied AI Security Top 10 and the compliance deadlines that are already arriving, and get an honest gap snapshot. Nothing leaves your browser until you choose to send it.

Evidence, not certificationMachinery Reg · 20 Jan 2027ISO 10218:2025 cyberDefensive · sim-only
Why this matters

In our own tests, a single reworded instruction redirected a real SmolVLA policy out of its benign envelope 88% of the time (44/50, 95% task-clustered CI [72-100% CI]) against a 4% benign baseline. A task-success metric never sees that. The two families that did not transfer we report as 0% too. See the measured result.

What runs the robot?

Your vision-language-action policy family.

Where do you evaluate it?

The simulator or suite you run today.

Have you adversarially tested the policy?

Not task success. Attacks: does a reworded instruction or a perturbed observation redirect it?

Which risks have you actually tested?

The Embodied AI Security Top 10 (the 8 a policy red-teamer can reach). Pick all you have measured.

Where does it ship, and who underwrites it?

Determines which compliance clocks apply. Pick all that apply.

How far along is deployment?

Sets the stakes: exposure rises faster than readiness.

No account. No tracking. Scored in your browser.
How an engagement works

From a self-check to signed evidence

The tool is free. If you need a defensible number an auditor or insurer can work from, this is the path. Pricing is a scoped starting range, not a fixed quote.

Embodied-AI Red-Team Assessment
scoped engagementby engagement

A red-team of your policy in simulation: an attack-success rate with a 95% confidence interval and a benign control, mapped to the EAI Top 10, with a SARIF report and a conformity-evidence dossier (candidate evidence, not certification).

Book a scoping call →
Continuous assurance retainer
ongoingquarterly

Re-run the red-team each release, gate CI on the attack-success rate, and hold a rolling per-checkpoint regression baseline. Standing evidence for a moving policy.

Talk to us →
Open-core, self-serve
freeApache-2.0

The CLI, every attack family, an attack-success rate with a benign control, SARIF, the GitHub Action and local attestation are free and always will be. Run it yourself: pip install provael.

Get the tool →
Compliance evidence report
add-onper engagement

An insurer- and notified-body-facing dossier: the assurance views (ISO 10218-2 / IEC 62443 SL2 / insurer summary) with the honest per-family transfer statement. Evidence, not certification.

See the crosswalk →