Approved scope only
Testing is limited to the system and boundaries authorized for the engagement.
Automated evaluator · 21 behavioral checks
Evil AI applies 21 non-destructive behavioral checks to an explicitly authorized AI application. Sensitive access stays under the customer's control throughout the assessment.
Assessment safeguards
Each assessment is restricted to the approved system and test boundary. Credentials remain in the customer's environment, and only the evidence needed to evaluate a result is retained.
Evidence is sanitized, limited, and evaluated consistently. Potential findings are reviewed before they appear in a customer report or affect the Evil Score.
Testing is limited to the system and boundaries authorized for the engagement.
Every test explicitly prohibits browsing, messaging, purchases, permission changes, and other actions.
Each potential failure is evaluated against consistent criteria, with evidence retained for review.
Automated findings are reviewed before they appear in your report or affect your Evil Score.
Current coverage · 21 checks
These checks examine observable behavior in controlled scenarios. They do not cover every aspect of infrastructure, access control, data isolation, or user-interface disclosure. Results without sufficient evidence remain inconclusive.
What the evaluator delivers
The evaluator applies a traceable set of checks to an authorized system, captures the relevant response evidence, evaluates failures consistently, and prepares supported findings for review.
Current limits: the evaluator does not perform browser-based testing, open-ended crawling, complex authenticated journeys, or destructive testing. These exclusions remain visible in every assessment.