Attack a real AI agent inside an isolated test organisation. Watch what your security stack catches, and what it lets through. No sales call.
We use your work email to name the tenant and send the evidence bundle afterwards. That is the whole reason we ask.
No card. No call. No calendar link. The tenant lives for 60 minutes and is destroyed with everything in it. Attacks run only against the synthetic organisation you pick above, never against anything you own.
A real agent estate, a real detection platform in front of it, and a real attack engine pointed at both.
Discovery records configuration observations, each with a stated source. It does not sniff your
network and it does not test anything. Every one of the eleven properties per asset is required, and
a property the source does not state is stored as unknown, never as a blank, a dash, or a
flattering default. record_provenance
on every row here is fixture: these
assets came from a specification document, not from an observation of a running estate, and the
product says so rather than implying otherwise.
None of the three states is coloured. Green means prevention on our surfaces and red means proven attack success, and a conjunction state is neither. Meets is a reason to look first, not a finding. Fails on stated value is one leg stated false, not a clean bill of health.
ordering_state = declined · rank_position = null on every row, at every set size.
Every member of the returned set satisfies the same three legs, the conjunction is the only permitted
discriminator, and it is uniform within the set by construction. So no member is first, highest or top
ranked. A caller looking for a rank finds a null and this reason, not an arbitrary element.
The same ten assets, drawn as a path rather than a list: who talks to what, under which identity, through which tools, and where the data can go. Click any node for its recorded properties.
Unsanctioned first. Click an asset to read its recorded properties and see which legs decided its state.
Unsanctioned · unregistered
NORTHWAY-FINANCIAL-fixture-spec.md v1.0, section 5.1
Recon characterises the detection surface, not your estate. It sends a graded ladder of five stimuli through the platform's inspection API and records where the active policy first reacts. It makes no model call and no database access, so it is cheap, deterministic and side-effect free. The result is frozen to disk and pinned, so the attack that follows is reproducible against a known surface. ATLAS: AML.T0056, AML.T0051.000, AML.T0043.
Five rungs, overtness rising with intensity. Deliberately less potent than the live payloads: the goal is to locate the detector threshold, not to maximise attack success.
What the resolver consumes. Pure function of these four fields.
Recon states what it could not measure, and why. These are declared, not silently omitted.
Same engine, same payloads we run in a paid engagement. Nothing is watered down for the sandbox.
Three stages, run in sequence.
The platform is configured to inspect and flag, not to block. Nothing on this screen measures its blocking ability, and the sandbox does not claim otherwise. Where a chain completes, the agent carried it through. Where it does not, the agent declined. A prevent-mode round is the one that measures blocking, and it has not been run.
Each stage is inspected on the way in and on the way out. Both results are shown.
The same recorded chain, read against both postures. Detection and outcome are independent columns: with prevention off, the second is governed by the agent.
Everything this tenant produced, signed and timestamped. Filed by who reads it.
Same engine. Your agents instead of ours.
You have now seen the product do the thing it claims to do, against an estate you did not have to expose. What you saw is one cycle. The subscription is the same thing, running against your estate, for as long as the estate keeps changing.
Enterprise scope is quoted against a real estate. There is no on-screen calculator.
Link, email, sandbox, evidence, price. The buyer proves the product to themselves and never speaks to anyone until they want to.
A single assessment tells you what was true on the day it ran. Both sides of that sentence move: your estate acquires agents, and the detection layer in front of them changes under you. The subscription exists because we can show you both moving.
Six things that happen without you asking. Each one is a thing this sandbox already does once.
Scoped in days, run in weeks. Every engagement ends with a verdict your board can read and your engineers can act on.
The easy way in. One full Discover, Attack, Remediate cycle across your estate, shadow agents included.
Continuous adversarial coverage, renewed each year. New attack patterns run against your estate as we publish them.
Bespoke scope for multi-team estates, sized to your environment, with a named engagement lead.
These are the rates published on artifactlens.co. Annual is the only subscription term currently priced; a monthly option is not published yet. Anything outside these shapes is quoted against a real estate rather than calculated from a form.
You have run the product and seen the evidence. This is the first point where a person is genuinely useful, because a price needs someone to look at your real estate rather than guess at it.
What we will not do. No drip sequence, no retargeting, no third party gets your address. If you never reply we send one follow-up and then stop.