Security research
Threat research, standards analysis, and adversarial testing that turn new attack classes into detectors with a benchmark behind them.
About
Provenant red-teams your MCP servers, tools, and agent configurations before they ship, then signs evidence of exactly what it checked. It comes out of research into how agent systems actually fail — not in the model, but in the seams around it.
Most AI programs secure the prompt or the model in isolation while the real exposure sits in the seams: the identity a tool call runs as, the data boundary a retriever crosses, the MCP metadata an agent trusts, the pipeline that ships a model without a gate. Research starts there because that is where incidents start.
A finding is not finished until it is operational: a control with a named owner, a policy a pipeline can enforce, or a detector inside Provenant. Every attack class we publish ships as a detector measured against a labeled corpus, and the benchmark fails the build if detection or false-positive rate regresses.
Provenant is early. The engine runs, the detectors are benchmarked, and the control plane is deployed — self-serve onboarding is not. We publish where the product actually is rather than let you find out after you have spent time on it, and we would rather release what we learn than hold it back as a sales asset.
How we work
Five commitments that decide what we will and will not put our name to.
We would rather tell you a control is unproven than sign off on one we cannot evidence. Confidence is an output of testing, not a tone of voice.
A control is real when it can be evaluated, traced to an owner, and exported for audit. The risk paper an executive reads and the policy a pipeline enforces describe the same control, or the control does not exist.
No reseller margin, no partner tier, no referral fee shapes a recommendation. The advice follows the risk in your estate.
The work succeeds when your team can run the control without us in the room. We build the muscle and hand over the evidence.
Assurance should let an organization adopt AI further and faster than it safely could before, not become the reason it stalls.
The work
Four areas sit behind the product. Research finds the failure modes, engineering turns them into controls, governance maps them to the frameworks you already report against, and training makes them operable by the people who own them.
Threat research, standards analysis, and adversarial testing that turn new attack classes into detectors with a benchmark behind them.
Identity, secrets, data boundaries, runtime monitoring, and the gates that sit in front of a release.
Control libraries mapped to the frameworks you already report against, with evidence pipelines that survive an audit.
Curriculum built on the same labs and incidents the detectors come from, so the people who own a control can operate it.
Provenant is what we build: registry, scan, governance, and monitoring over one evidence chain. The services practice exists to get it adopted and to feed real estates back into the control library — not the other way around.