vertotechTrust Intelligence. Secure Every Outcome.
Provenant · AI red teaming

Automated red team for agents and models.

Point Provenant at an agent, a system prompt, a retrieval corpus, or an MCP export. It runs adversarial campaigns — jailbreak, extraction, indirect injection, agency abuse, tool poisoning, grant attacks — and returns EXPLOITABLE or HARDENED with the payload that landed.

Red-team walkthrough · target, attack, verdict

Campaign loop

How a red-team run actually proceeds

Four stages. No architecture diagram. No control catalogue. An attacker workflow.

01Targetagent · prompt · RAG · MCP02Reconenumerate surfaces03Attacksix campaign packs04Verdictexploitable · hardened

Where to start

Five steps from this page

Same order every time. The live campaign is the product; the video is the briefing.

01

Open the live campaign

Public sample. No account. Pick the exploitable or hardened fixture.

02

Watch how a run works

Target in, packs fire, hit/miss log, verdict. That is the product.

03

Launch the packs

Jailbreak, extraction, indirect injection, agency, MCP, grants — in one campaign.

04

Sign in for your target

Paste a system prompt, RAG corpus, or MCP tools/list and attack that.

05

Pilot a real estate

When you want us on production agents, request a campaign.

Attack surface

What the payloads hit

Provenant does not inventory your cloud account. It attacks the text and grants the model will ingest.

Agentcampaign targetSystem promptRAG / memoryTools / MCPGrants / identityPayloads land on the surfaces the model actually reads

Campaign packs

Six classes of attack

Each pack is a battery of techniques. Together they are the red team.

Pack 01

Jailbreak

Instruction override, developer-mode role-play, delimiter and markup breakout against the system prompt.

Pack 02

Extraction

Force the model to recite hidden instructions and any secrets that were planted in the prompt or tools.

Pack 03

Indirect injection

Poisoned RAG documents and agent memory the model treats as trusted context — no user jailbreak required.

Pack 04

Excessive agency

Skip confirmation, fire write or egress tools, replace the agent’s goal with the attacker’s.

Pack 05

Tool & MCP poisoning

Adversarial text inside tool descriptions: injection, concealment, exfil, shadow tools, invisible Unicode.

Pack 06

Identity & grants

Wildcard scopes, unsigned manifests, static secrets, live tools nobody declared. Privilege, not paperwork.

Evidence

Hit or miss — with the payload

A finding is a technique that landed. A miss is a technique that did not. The report is that log, signed.

TECHNIQUE LOGHITjailbreak.ignore_previousoverride ingested as controlHITrag.doc_injectionretrieved runbook contains exfil URLMISSextraction.repeat_promptinstruction isolation heldHITmcp.tool_poisoningtool description rewrites github_search

Request a campaign on your agents →