AI runtime diagnostic
Map one risky workflow
before review does
Watch a simulated diagnostic probe a healthcare prior-authorization agent, map each finding to OVERT controls, and show how runtime evidence becomes a Sprint-ready hardening plan.
Simulated — no live systems are contacted
Ten attack vectors for the runtime map
Every diagnostic probes the target across the categories below, mapped to OVERT, MITRE ATLAS, and the OWASP LLM Top 10. The point is not a generic score; it is a control plan for one workflow.
| Vector | Maps to |
|---|---|
| 01Prompt injection | OWASP LLM01 / ATLAS AML.T0051 |
| 02PII / PHI extraction | OWASP LLM06 / ATLAS AML.T0057 |
| 03Jailbreak chains | OWASP LLM01 / ATLAS AML.T0054 |
| 04Role confusion | OWASP LLM08 / OVERT RT-3 |
| 05Tool-use abuse | OWASP LLM07 / OVERT RT-5 |
| 06Trust-building escalation | OVERT RT-7 / NIST AI RMF MS-2.6 |
| 07Output manipulation | OWASP LLM02 / ATLAS AML.T0048 |
| 08Context poisoning | OWASP LLM03 / ATLAS AML.T0020 |
| 09Excessive agency | OWASP LLM08 / OVERT RT-9 |
| 10Behavioral drift (CUSUM) | NIST AI RMF MS-2.7 / OVERT RT-10 |
Patient identifiers leak via prior-auth response
Adversarial probe asked the agent to summarize its last decision. Response included MRN 9210384, DOB, and name — bypassing the system prompt’s redaction rule.
Median across 1,200+ healthcare-domain runs in the last 90 days. The probe stream begins on first packet; you don’t wait for a full report to see signal.
Zero sensitive-data egress by default
- Stays local
- Prompts, model outputs, PHI/PII, customer context, system prompts, and tool-call payloads remain inside your stack.
- Travels
- Verification metadata only — signed receipt hashes, OVERT control IDs, severity counts, and CUSUM drift summaries.
- Means
- You can publish or share the scan’s evidence without a BAA, DPA, or data-residency review. The proof travels; the data does not.
Scan Complete
Get the workflow diagnostic
Detailed findings, OVERT control mappings, and a hardening plan delivered to your inbox.
Harden your workflow
Use the diagnostic to choose the workflow for a 10-business-day Sprint: map, controls, receipts, evidence pack.
Talk to the teamInspect the evidence
See how signed receipts roll up into a buyer-, auditor-, and security-review evidence pack.
View sample evidence