Resources

Two things you can run yourself.

We built both for our own work and left them open. One tells you what actually broke in AI security this week. The other tells you how far your DPDP programme still has to go.

Neither of these is a red team. They are questionnaires and feeds — you run them, they take minutes, and they work from what you tell them. Our actual work is adversarial: we attack the running system and report only what we could make happen. A self-assessment tells you which questions to ask. An engagement tells you which answers are true.

Neither is a scoreboard with a sales call attached. The briefing needs no account at all. The readiness check stores your name, your organisation and your work email — never your answers — and hands back a list of what to fix, whoever you then hire to fix it. We say elsewhere on this site that a tester who also sells the remedy has a reason to find something; that applies to what we give away too, so these are built not to.