Security & trust

How we scope testing and handle evidence.

Understand the access, testing boundaries, and evidence handling for your assessment.

Independence

mace AI reports to the customer commissioning the assessment.

Findings are delivered to your team, with reproduction steps and remediation ownership, under the engagement terms.

Data handling

Agree the scope and access before testing.

For model red teaming, agent red teaming, and swarm-defense work, we agree the target, permitted actions, access, and evidence handling before testing.

Starting with Fisher

We may ask for tool descriptions, safety rules, and representative tasks. Production access, source code, and live customer data are not required to start.

Fisher deployment options →

Fisher assessment evidence

What the evidence contains.

Method
Reproducibility tiers
Confirmed behavior is replayed under the tested conditions and each finding records how often it repeated. A behavior observed once is recorded as observed once.
Method
Evidence bundles
Transcript and available tool-trace records, state deltas, and replay outcomes, with the artifacts and reproduction steps needed to replay each finding in the agreed test environment. Framework mapping by agreement.
Method
Judge-free proof
For the highest-stakes classes, a planted canary crossing the boundary is proof, not an opinion.
Compliance

Map findings to the frameworks your team uses.

Relevant findings can be mapped to agreed standards, frameworks, and regulatory requirements. Mapping supports internal review; it is not certification, legal advice, or a determination of compliance.

  • OWASP Top 10 for LLM Apps
  • OWASP Top 10 for Agentic Apps
  • NIST AI RMF
  • MITRE ATLAS
  • EU AI Act
  • ISO/IEC 42001
  • GDPR
  • HIPAA
  • GINA
  • FCC / CPNI
Architecture

Deep Model Trust

The architecture guiding mace AI’s research and product development.

Explore Deep Model Trust →

Our own trust surface

An assurance vendor should be easy to assess.

SOC 2 — In progress

mace AI is working toward SOC 2.

Trust Center →

Our public legal and policy documents:

Privacy Policy →  ·  Terms of Use →

Responsible testing

Disclosure.

All testing is authorized and scoped in the engagement record. Findings are delivered to the authorized customer team under the agreed engagement terms and are not published against you. Our model benchmarks measure capability and guardrail behavior on the same harness, with the full run recorded.

View the benchmarks →

Discuss your security requirements before testing.

Tell us what you need assessed and what access or evidence-handling requirements your team must meet.

Book demo →