ATR
Govern provenance, licensing, applicability and usage of adversarial items, and turn confirmed vulnerabilities into mandatory regression assets for future releases.
Product flow
DESIGNED FOR
Organizations that need to manage prompt injection, hijacking and jailbreak risk as a continuous defensive regression program rather than a one-off test
OUTCOMES
Start with customer change, not a feature list
Verified live-site capabilities and current product sources are reframed around the customer workflow and operating outcome.
Stop rebuilding test sets
Accumulate adversarial tests that were previously scattered by product into a registry with common schema, taxonomy and provenance.
Separate discovery from recurrence
Run new-sample generalization and mandatory retesting of confirmed vulnerabilities under distinct rules.
Keep attack content contained
Restrict access to operational attack prompts and expose only approved aggregates to general users and partners.
CAPABILITY SYSTEM
The capabilities that make the product work
These are product-level capabilities customers can adopt and operate—not isolated buttons or controls.
Item registry
Manage item IDs, taxonomy, dependencies, provenance, license and lifecycle state together.
Applicability
Select only items applicable to country, industry, company, service, brand, product, revision and evaluation purpose.
Generalization track
Sample deterministically from the unused pool and prevent reuse for the same product and purpose.
Regression track
Promote human-confirmed vulnerabilities into product regression suites and force their inclusion in future releases.
Campaign & manifest
Fix item, product, model, judging criteria and execution revisions in a manifest for reproducibility.
Human verdict & reporting
Use automated judging as input, require human confirmation for promotion and produce aggregate-safe reports.
OPERATING FLOW
How it works after adoption
- 01
Intake, register and normalize
Register human red-team, approved external and generated items under one contract.
- 02
Hygiene, rights and applicability
Validate duplicates, licenses, permitted use and target applicability.
- 03
Run generalization or regression
Choose the appropriate track and execute the campaign with a fixed manifest.
- 04
Verdict, promotion and report
Use human verdicts to update consumed or regression state atomically and publish aggregate results.
TRUST & DEPLOYMENT
The operating environment and responsibility boundary are part of the product.
On-premises operations portal
Provide a read-only portal for QA and service experts to review data rights, lifecycle and campaign status.
Raw-content isolation
Keep attack and response payloads out of general web projections and enforce purpose limitation and access control.
Product-specific adapters
Validate chatbot, agent and copilot defenses through adapters bound to approved endpoints and revisions.
VERIFIED SCOPE
Evidence and boundaries behind the public copy
- A two-track contract separating generalization consumption from mandatory regression replay
- Item-level provenance, licensing, permitted use and export controls
- Regression promotion requires a human-confirmed verdict, not an automated judge alone