Early Adopter — v1, assess-only

DenseAIArmour

Your people are already using AI assistants and agents. The vendor keys they hand those assistants tend to sit in plaintext — on the same machines you just hardened. DenseAIArmour reads the AI estate and reports where the gaps are. It assesses; it does not fix.

DenseAIArmour results: AISEC findings across the AI estate, each mapped to a control and a public framework

What it reads

The reader is read-only and deterministic: it inspects what is on the host and reports it, the same input yielding the same findings every run. It does not change a setting, and it phones home to nothing. Each finding is tied to an AISEC-* control and cross-referenced to a public framework, so a gap points at a named source instead of an opinion.

Prompt-injection exposure

Where model output becomes an action — agentic workflows, tool use, retrieved content treated as trusted — the reader reports the surface a manipulated instruction can reach. Injection is not a solved problem; what the finding measures is blast radius, not immunity.

Model-manipulation surface

Evasion and manipulation of the model itself remain open problems in the research. DenseAIArmour reports the exposure — unmediated inputs, missing human gates on irreversible actions — and names it, rather than claiming it away.

Data poisoning & provenance

Training, fine-tuning, and retrieval data are a trust boundary. The reader reports what feeds the models and whether its provenance is accounted for, so poisoned or unverified inputs are visible instead of assumed clean.

Secure-default configuration

Vendor keys in plaintext, write-capable credentials where a read-only one would do, defaults left as shipped. The reader finds the misconfigurations that turn a convenient assistant into an unguarded door.

DenseAIArmour check: a single AISEC control, its determination, and the framework it maps to
One control, one determination — mapped to OWASP LLM 2026, OWASP ASI, MITRE ATLAS, and NIST AI 600-1, so the finding cites a source you can check.

Where the fix lives

DenseAIArmour's job ends at the honest assessment. The defenses exist — each AISEC-* control is keyed to a hardening guide that gives the secure default and the pattern to build — but the product does not apply them and does not claim to secure your AI. It tells you, accurately, where you stand today. Fixing is a separate, deliberate step you take with the finding in hand.

DenseAIArmour evidence: a finding with its control id, framework mapping, and the read that produced it
Read-onlyInspects and reports; changes no setting
DeterministicSame estate, same findings, every run
No phone-homeNothing leaves the host it assesses

See where your AI estate actually stands.

DenseAIArmour is v1 and open to Early Adopters now. It reads your AI estate read-only, reports the gaps mapped to named controls and public frameworks, and hands you findings you can act on — without touching a thing on the way through.