# Artifact Lens

> Red team your AI agents. Discover · Attack · Remediate. Powered by Artifact Security threat intelligence.

Artifact Lens is an independent AI red team. It is a product you run, not a consulting engagement.

- **Website:** https://artifactlens.co
- **Contact:** lens@artifactsecurity.co.uk
- **The lab:** https://artifactsecurity.co.uk
- **Location:** London

## The platform — Discover. Attack. Remediate.

A repeatable evaluation that runs four attack categories against your agents — **including the ones you don't know about** — and measures whether your security stack **detects and prevents** them. Detection alone isn't a pass.

The evaluation runs in three stages:

1. **Discover** — Map your agent estate and flag unregistered ("shadow") agents connected to mail, files, and payments.
2. **Attack** — Run adversarial attacks across four categories:
   - I · Direct injection
   - II · Indirect injection
   - III · MCP rugpull
   - IV · Jailbreak
3. **Remediation plan** — A prioritised, per-category report of what was detected, what was blocked, and the fix we hand over.

We test detection *and* prevention across the input, output, and tool-registration layers. Vendor identity is withheld by design.

## We don't compete with your vendors. We attack through them.

Artifact Lens attacks your agents the way a real adversary would — straight through the security controls you already pay for — then shows you, per attack, exactly what your stack caught and what it let through. A product you run, not a consulting engagement.

- **Vendor-agnostic by design.** No runtime tool to rip-and-replace your stack — Lens measures the controls you already run.
- **Every attack routes through your controls.** Detection and prevention, scored per attack category at the input, output and tool-registration layers.
- **Backed by the lab.** Threat intelligence from Artifact Security — AMTSO member since 2013, and the first AI-agent security evaluation in the world for cyber enterprises.

How it works: Artifact Lens (attacker's perspective, independent) — adversarial simulation, shadow-AI discovery, independent validation — attacks *through* your security vendor stack (the controls you bought) to reach the target surface: your enterprise AI agents (chatbots, SOC agents, copilots, pipelines, and the ones you don't know about).

## Engagements — Three ways in.

Scoped in days, run in weeks — not months. Every engagement ends with a verdict your board can read and your engineers can act on. Full detail: https://artifactlens.co/engagements.md

- **Agent estate assessment** (for enterprises) — One full Discover · Attack · Remediate cycle across your estate, shadow agents included. Pricing on request.
- **Lens subscription** (for enterprises, continuous) — Continuous adversarial coverage; new attack patterns run against your estate as we publish them. Pricing on request.
- **Independent validation** (for security vendors) — Your agent-security product, tested by the lab that tests the industry, with right-of-reply. Pricing on request.

Designed for security vendors, enterprises, and regulators & investors needing compliance evidence.

## Research

Featured and latest field notes: https://artifactlens.co/research.md

**Featured (July 2026) — AL-2026-014:** *Foot in the door: one calendar invite walked a support agent into full mailbox exfiltration.* A supplier's calendar invite carried instructions the target's customer-support agent read as its own. Three tool calls later, it was forwarding mailboxes. The security stack raised seven alerts and blocked nothing. We reproduced the full chain in 9 of 10 runs, handed over a prioritised fix, and verified it held on retest — the same chain now fails at step one.

## Attack library

A continuously updated catalog of AI-agent attack patterns from live engagements and lab research — 240 entries and counting. Every pattern we publish, we can run against your estate. Full list: https://artifactlens.co/attack-library.md

## Numbers that matter

- 15+ years of attack intelligence
- 10k+ hours of testing
- 100+ companies tested
- 240 attack patterns in the library

Threat intelligence from Artifact Security — the independent test lab behind Lens. Every engagement runs Discover · Attack · Remediate against it.

---

*Powered by Artifact Security. Methodology AL-M-001 · published before we test. Independent since the first test.*
