proofplane

A control is HELD only when an executed adversarial attack failed — never because a document says the control exists. Run it below and watch which controls hold.

Guide · Source · Attacks run only against a deliberately-non-compliant target this app boots on a private local port — never an arbitrary or real system.

This runs the real tool, not a recording. It boots the shipped agentic target server (twelve toggleable guardrails, a mock model — no API key, no spend), then spawns the real Python probe suite to execute twelve adversarial attacks against it. A control is credited only when the attack it faces fails in every trial.