Map the AI estate
Discover approved and unregistered models, applications, agents, endpoints, datasets, knowledge sources, MCP servers and tools; connect ownership and dependencies in an AI bill of materials.
Sovereign AI security · Roadmap
Discover AI assets and dependencies, verify models and tools before release, attack-test applications and agents, and contain hostile behaviour through security controls operated inside the customer-defined boundary.
Status: Roadmap. This application is being developed for open-source release. Its repository, OSI-approved software licence, model-specific terms, version, provenance and supported deployment modes will be published with the applicable release.
Core capabilities
Exact coverage, deployment requirements and limitations are documented for the selected version and use case.
Discover approved and unregistered models, applications, agents, endpoints, datasets, knowledge sources, MCP servers and tools; connect ownership and dependencies in an AI bill of materials.
Inspect repositories, model artefacts, containers, dependencies, MCP packages and tools for malicious code, unsafe deserialisation, hidden payloads, tampering, backdoors and vulnerable components.
Run repeatable adversarial tests against models, applications and agents for prompt injection, jailbreaks, extraction, tool misuse, privilege escalation, memory poisoning and resource abuse.
Inspect model traffic, retrieved context, agent actions and tool calls for adversarial behaviour, then allow, block, rate-limit, quarantine, revoke or escalate through approved enforcement points.
Build event timelines across affected assets and dependencies; manage severity, remediation, exceptions, retesting and revocation; and export evidence to authorised security operations workflows.
Product boundary
AI Defense owns cybersecurity posture, hostile-component detection, adversarial testing, threat containment and investigation. AI Guardrails owns expected behaviour, structured outputs, quality evaluation and organisation-defined business policy.
Adoption outcome
Begin with an asset and dependency inventory, define plausible attack scenarios, then establish security testing, release gates, containment and incident evidence appropriate to the environment.
Sovereignty matrix
Product-specific answers are established through the deployment architecture and dated evidence record.
Connected Roadmap capabilities
Every connected capability shown here is part of the current Roadmap.
A practical first step
Begin with an asset and dependency inventory, define plausible attack scenarios, then establish security testing, release gates, containment and incident evidence appropriate to the environment.