AI red teaming, made simple.

Generate attacks, run them against your models, apps and guardrails, judge every response and tune your defenses — in one repeatable chain.

  1. Arsenal
  2. Strike Lists
  3. Run
  4. Evaluations
  5. Optimize
  • Forge generates new attacks
  • Dynamic Attacks adapt to every answer
  • Easy, guided UI
  • Repeatable test sets
  • Built-in integrations

Find the weak spots before anyone else does. Fix them before launch.

  • Chatbots
  • RAG apps
  • Agentic systems
  • Prompt injection
  • Jailbreaks
  • Personal data leaks
  • System prompt leaks
  • Hidden instructions in documents
  • Tool and agent misuse
  • Role-play tricks
  • Encoded prompts
  • Multi-turn manipulation
  • Multilingual attacks
  • Adaptive attacks
  • And more…

Why red teaming

You can’t defend what you’ve never attacked.

Guardrails and AI firewalls are only a guess until something tries to break them. Invictus Red attacks first, so you know what holds before a real attacker finds out.

The platform

One platform. The whole red‑team loop.

Every step lives in one place, so you can run the same loop again for every model and every release.

  1. 01AttackReady-made, new and adaptive attacks
  2. 02TestYour models, apps and guardrails
  3. 03EvaluateEvery answer checked automatically
  4. 04AnalyzeSee exactly what fails
  5. 05HardenTune guardrails and prove the fix
  1. 01Attack
  2. 02Test
  3. 03Evaluate
  4. 04Analyze
  5. 05Harden
RepeatEvery model.
Every release.

01 · Attack

An arsenal that’s always up to date.

Ready-made attacks in many languages, mapped to the standards you follow.

  1. Advanced filters
  2. Forge
  3. Dynamic Attacks
  4. Strike Lists

Advanced filters

Find the right attack in seconds.

Stack filters for framework, category, severity, language, target type, attack surface and more. The count updates as you go, and every attack is mapped to the frameworks you report on.

  • OWASP LLM Top 10
  • MITRE ATLAS
  • NIST AI RMF
  • EU AI Act
  • ISO 42001
  • ISO 23894
  • KVKK

Forge

Create new attacks with Forge.

Pick the method that fits the job: a fixed prompt collection, template variations, prompts an AI model writes from your objective, or simulated multi-turn conversations. Review what Forge makes, then publish it to the library.

Dynamic Attacks

Attacks that adapt to every answer.

Dynamic attacks read each reply and change tactics, like a real attacker. Choose a technique such as TAP, PAIR, Crescendo or GOAT, or PAIR+, built for AI firewalls, and point it at your target.

Strike Lists

Group attacks by purpose. Rerun anytime.

Collect attacks into Strike Lists, like a release gate or a data leak suite, and run them again against one target or many at once. Every change is saved as a new revision, so results stay comparable.

02 · Test

Test every layer of your AI.

Your models, your own apps and your guardrails — tested side by side.

  1. Targets
  2. Workflow
  3. Processes

Targets

Models, apps and guardrails.

Connect model providers, the chatbots and APIs you built, and the guardrails and AI firewalls in front of them. Then send the same attacks to each.

  • OpenAI
  • Anthropic
  • Google Gemini
  • Azure OpenAI
  • OpenRouter
  • OpenAI-compatible APIs
New connectionAdd a target
Model provider
AI models
OpenAI, Anthropic, Gemini and more.
Your app
AI apps
The chatbots and AI apps you built.
Safety layer
Guardrails
Guardrails and AI firewalls.
  • Self-hosted models
  • AI Firewall
  • Invictus Blue
  • Custom guardrails
  • Your own APIs

Workflow

From attacks to results in one go.

Workflow carries your selection through every stage: Strike List, responses and evaluations. Each target gets its own path and runs on its own. Save a workflow and start it again with one click.

Processes

Long runs keep running.

Tests continue in the background after you close the tab. Follow every run in Processes and resume a stopped step where it left off.

03 · Evaluate

Every response, judged.

Every answer is checked automatically, so you know what got through.

  1. Evaluation methods
  2. Guardrail scoring
  3. Explained results

Evaluation methods

Two ways to judge every answer.

Read the guardrail’s own block or allow decision, with no AI model needed, or let an AI reviewer decide whether each attack succeeded, using a security rubric you can adjust. In a Workflow, every target gets the method that fits it.

Guardrail scoring

Missed blocks and false alarms, counted.

Every attack carries the behavior you expect. Each guardrail decision is scored against it: correct blocks, missed blocks, unnecessary blocks and correct allows, with accuracy, precision and recall on top.

Explained results

See why each answer passed or failed.

Open any result to read the explanation next to the prompt, the response and the expected behavior. Show only the incorrect ones, break results down by Strike List and export what you see as CSV.

04 · Analyze

Find exactly where it breaks.

Narrow results by app, attack type, language or risk. Every number follows.

  1. Filters
  2. Breakdowns
  3. Frameworks
  4. Drill down

Filters

Every number follows your filters.

Narrow results by target, evaluation, Strike List, attack type, language, severity or date. Attack success rate and every breakdown update together, and the link keeps your view, ready to share.

Breakdowns

Compare runs and see what fails most.

Group results by responses, evaluations, Strike Lists or evaluation method and compare attack success side by side. Rank the categories and techniques that fail most, then follow the attack tree down to a single technique.

  • Results by severity, from critical to low
  • Response times from median to p99, with the slowest answers

Frameworks

Results for the frameworks you report on.

See attack success rate per framework and per control for OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, EU AI Act, ISO 42001, ISO 23894 and KVKK, and find the controls that have no tests yet.

Drill down

From any chart to the exact answer.

Click a bar, a count or a control to open the results behind it, then any single result with its prompt, response, expected behavior and explanation.

05 · Harden

Stronger guardrails, proven.

Better policies are tried on your live guardrail. You promote the winner.

  1. Guardrail Optimization
  2. Policy Lab
  3. Real traffic

Guardrail Optimization

Your guardrail, tuned and proven.

Optimize starts from how your current policy performs, studies where it fails and proposes better candidates. Each one is compared on the same examples and checked on data it hasn’t seen.

  • Start it from any evaluation
  • Kept only if it blocks at least as much, with no new false alarms

Policy Lab

Compare, review and publish policies.

Every guardrail and policy on your AI firewall, in one place. Build from a shared library or templates, see what each change affects, then review and publish. The firewall is read back to confirm it matches.

  • Added, edited and removed policies are marked and can be undone
  • Invictus Blue policies are compared and uploaded the same way

Real traffic

Turn real traffic into new tests.

Review what your AI firewall saw in production and publish real prompts as new attacks, so the next run covers what people actually tried.

Inside the app

Built for daily work.

Jump between related records, give every team its own workspace, look up any framework and load-test your AI firewall.

  • Breadcrumb navigation

    Follow a run from Strike List to responses and evaluation. Switch to a sibling record from a searchable menu, or jump straight to the next step.

  • Workspaces

    Give each team or customer its own workspace: separate data, users and resource limits, on the same installation.

  • Resources

    A built-in wiki of security frameworks, controls and techniques and how they connect, plus a graveyard to review and restore archived records.

  • AI firewall load tests

    Measure successful requests per second, p95 latency and error rate. Run one load level or a concurrency sweep that stops itself at your limits.

Integrations

Connect your models, apps and guardrails.

Product names and logos are trademarks of their respective owners.

Models

  • OpenAI
  • Anthropic
  • Google Gemini
  • Azure OpenAI
  • OpenRouter
  • LiteLLM
  • Ollama
  • LM Studio
  • OpenAI-compatible APIs
  • Self-hosted models

Guardrails

  • AI Firewall
  • Invictus Blue
  • HTTP guardrails

Applications

  • Application APIs
  • LangChain
  • LangGraph
  • LlamaIndex
  • CrewAI
  • OpenCode
  • n8n

Ready to deliver

Enterprise-ready. Runs where you need it.

Deploy in your own environment, license offline, keep your data on your own installation.

  • On-prem or any cloud providerYour own isolated install. No shared servers, no shared data.

  • Offline licensingActivated without calling home.

  • Agent interfacesLet AI agents run tests for you.

  • Roles & permissionsControl who sees and runs what.

  • Secrets in a dedicated vaultKeys and credentials kept apart from app data.

invictus.red

Attack. Prove. Harden.

Automated red teaming for AI systems

Request a demo invictus.red