# Invictus Red — AI red teaming, made simple.

> Generate attacks, run them against your models, apps and guardrails, judge every response and tune your defenses — in one repeatable chain.

This is the Markdown version of <https://invictus.red/>. The web page carries the same content with animated product views and a 1:36 film.

[Request a demo](mailto:info@algoritmax.com?subject=Invictus%20Red%20demo%20request)

The chain: Arsenal → Strike Lists → Run → Evaluations → Optimize.

- Forge generates new attacks.
- Dynamic Attacks adapt to every answer.
- Easy, guided UI.
- Repeatable test sets.
- Built-in integrations.

Find the weak spots before anyone else does. Fix them before launch.

## What we test for

- Use cases: chatbots, RAG apps, agentic systems.
- Risks: prompt injection, jailbreaks, personal data leaks, system prompt leaks, hidden instructions in documents, tool and agent misuse, role-play tricks, encoded prompts, multi-turn manipulation, multilingual attacks, adaptive attacks — and more.

## You can't defend what you've never attacked.

Guardrails and AI firewalls are only a guess until something tries to break them. Invictus Red attacks first, so you know what holds before a real attacker finds out.

## One platform. The whole red-team loop.

Every step lives in one place, so you can run the same loop again for every model and every release.

1. **Attack:** ready-made, new and adaptive attacks.
2. **Test:** your models, apps and guardrails.
3. **Evaluate:** every answer checked automatically.
4. **Analyze:** see exactly what fails.
5. **Harden:** tune guardrails and prove the fix.

Then repeat: every model, every release.

## 01 · Attack — An arsenal that's always up to date.

Ready-made attacks in many languages, mapped to the standards you follow.

### Find the right attack in seconds.

**Advanced filters:** stack filters for framework, category, severity, language, target type, attack surface and more. The count updates as you go, and every attack is mapped to the frameworks you report on: OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, EU AI Act, ISO 42001, ISO 23894 and KVKK.

### Create new attacks with Forge.

**Forge:** pick the method that fits the job: a fixed prompt collection, template variations, prompts an AI model writes from your objective, or simulated multi-turn conversations. Review what Forge makes, then publish it to the library.

### Attacks that adapt to every answer.

**Dynamic Attacks:** dynamic attacks read each reply and change tactics, like a real attacker. Choose a technique such as TAP, PAIR, Crescendo or GOAT, or PAIR+, built for AI firewalls, and point it at your target.

### Group attacks by purpose. Rerun anytime.

**Strike Lists:** collect attacks into Strike Lists, like a release gate or a data leak suite, and run them again against one target or many at once. Every change is saved as a new revision, so results stay comparable.

## 02 · Test — Test every layer of your AI.

Your models, your own apps and your guardrails — tested side by side.

### Models, apps and guardrails.

**Targets:** connect model providers, the chatbots and APIs you built, and the guardrails and AI firewalls in front of them. Then send the same attacks to each.

### From attacks to results in one go.

**Workflow:** Workflow carries your selection through every stage: Strike List, responses and evaluations. Each target gets its own path and runs on its own. Save a workflow and start it again with one click.

### Long runs keep running.

**Processes:** tests continue in the background after you close the tab. Follow every run in Processes and resume a stopped step where it left off.

## 03 · Evaluate — Every response, judged.

Every answer is checked automatically, so you know what got through.

### Two ways to judge every answer.

**Evaluation methods:** read the guardrail’s own block or allow decision, with no AI model needed, or let an AI reviewer decide whether each attack succeeded, using a security rubric you can adjust. In a Workflow, every target gets the method that fits it.

### Missed blocks and false alarms, counted.

**Guardrail scoring:** every attack carries the behavior you expect. Each guardrail decision is scored against it: correct blocks, missed blocks, unnecessary blocks and correct allows, with accuracy, precision and recall on top.

### See why each answer passed or failed.

**Explained results:** open any result to read the explanation next to the prompt, the response and the expected behavior. Show only the incorrect ones, break results down by Strike List and export what you see as CSV.

## 04 · Analyze — Find exactly where it breaks.

Narrow results by app, attack type, language or risk. Every number follows.

### Every number follows your filters.

**Filters:** narrow results by target, evaluation, Strike List, attack type, language, severity or date. Attack success rate and every breakdown update together, and the link keeps your view, ready to share.

### Compare runs and see what fails most.

**Breakdowns:** group results by responses, evaluations, Strike Lists or evaluation method and compare attack success side by side. Rank the categories and techniques that fail most, then follow the attack tree down to a single technique.

- Results by severity, from critical to low.
- Response times from median to p99, with the slowest answers.

### Results for the frameworks you report on.

**Frameworks:** see attack success rate per framework and per control for OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, EU AI Act, ISO 42001, ISO 23894 and KVKK, and find the controls that have no tests yet.

### From any chart to the exact answer.

**Drill down:** click a bar, a count or a control to open the results behind it, then any single result with its prompt, response, expected behavior and explanation.

> Your defense is only as strong as the attacks it has survived. Turn what broke into what holds.

## 05 · Harden — Stronger guardrails, proven.

Better policies are tried on your live guardrail. You promote the winner.

### Your guardrail, tuned and proven.

**Guardrail Optimization:** Optimize starts from how your current policy performs, studies where it fails and proposes better candidates. Each one is compared on the same examples and checked on data it hasn't seen.

- Start it from any evaluation.
- Kept only if it blocks at least as much, with no new false alarms.

### Compare, review and publish policies.

**Policy Lab:** every guardrail and policy on your AI firewall, in one place. Build from a shared library or templates, see what each change affects, then review and publish. The firewall is read back to confirm it matches.

- Added, edited and removed policies are marked and can be undone.
- Invictus Blue policies are compared and uploaded the same way.

### Turn real traffic into new tests.

**Real traffic:** review what your AI firewall saw in production and publish real prompts as new attacks, so the next run covers what people actually tried.

## Inside the app — Built for daily work.

Jump between related records, give every team its own workspace, look up any framework and load-test your AI firewall.

### Breadcrumb navigation

Follow a run from Strike List to responses and evaluation. Switch to a sibling record from a searchable menu, or jump straight to the next step.

### Workspaces

Give each team or customer its own workspace: separate data, users and resource limits, on the same installation.

### Resources

A built-in wiki of security frameworks, controls and techniques and how they connect, plus a graveyard to review and restore archived records.

### AI firewall load tests

Measure successful requests per second, p95 latency and error rate. Run one load level or a concurrency sweep that stops itself at your limits.

## Integrations — Connect your models, apps and guardrails.

- **Models:** OpenAI, Anthropic, Google Gemini, Azure OpenAI, OpenRouter, LiteLLM, Ollama, LM Studio, OpenAI-compatible APIs and self-hosted models.
- **Guardrails:** AI Firewall, Invictus Blue and HTTP guardrails.
- **Applications:** application APIs, LangChain, LangGraph, LlamaIndex, CrewAI, OpenCode and n8n.

Product names and logos are trademarks of their respective owners.

## Enterprise-ready. Runs where you need it.

Deploy in your own environment, license offline, keep your data on your own installation.

- **On-prem or any cloud provider:** your own isolated install. No shared servers, no shared data.
- **Offline licensing:** activated without calling home.
- **Agent interfaces:** let AI agents run tests for you.
- **Roles & permissions:** control who sees and runs what.
- **Secrets in a dedicated vault:** keys and credentials kept apart from app data.

## Attack. Prove. Harden.

Automated red teaming for AI systems. [Request a demo](mailto:info@algoritmax.com?subject=Invictus%20Red%20demo%20request).

© 2026 Invictus Red · Powered by [algoritmax](https://www.algoritmax.com/)
