Independent AI assurance

We break your AI.
Then we prove it's still safe.

Probative continuously red-teams your production AI — jailbreaks, prompt injection, PII exfiltration, tool misuse, bias, hallucination — and grades every result with an independent judge. Governance tools document your AI. We break it, and hand you the signed evidence.

11
attack classes, every scan
4
frameworks auto-mapped
continuous re-verification
0
model, cloud or security owners
Method

Connect. Attack. Sign.

One endpoint is all Probative needs. The battery runs on a schedule you set; the evidence writes itself.

Diagram of eleven adversarial probes striking an AI system, some deflected, one landing
Fig. 01 — attack surface11 classes
01 / Connect

Point Probative at your AI

An API endpoint or chat interface. No SDK, no code changes, no access to your training data.

02 / Attack

The battery runs continuously

Eleven adversarial probe classes fire on every scan. An independent LLM judge grades each result — pass, fail, or degraded — against published criteria.

03 / Sign

Evidence, not assertions

Every finding lands in a sha256 + ed25519 hash chain and rolls up into framework-mapped evidence packs your auditor can verify independently.

The battery

Eleven ways your AI fails. Tested on repeat.

PRB-01

Jailbreak

Role-play, obfuscation, and multi-turn escalation attempts to bypass your system prompt.

PRB-02

Prompt injection

Hostile instructions smuggled through user content, documents, and tool outputs.

PRB-03

PII exfiltration

Attempts to extract personal data your system holds or has seen.

PRB-04

Bias

Differential treatment across protected characteristics in identical scenarios.

PRB-05

Hallucination

Confident fabrication under pressure — citations, numbers, people, precedent.

PRB-06

Toxicity

Harmful output under provocation, adversarial phrasing, and persona pressure.

PRB-07

Refusal drift

Whether your guardrails are the same today as the day you shipped them.

PRB-08

Data governance

Leakage of system prompts, internal tools, and configuration through the front door.

PRB-09

Tool misuse

Coaxing your agent into calling the wrong tool, with the wrong arguments, on someone else's behalf.

PRB-10

RAG exfiltration

Pulling retrieval-indexed documents out through the answers they ground.

PRB-11 · agentic

Excessive agency

Whether your agent stays inside its mandate when an attacker widens it — the failure class regulators are reading about right now.

Enforcement

What enforces when.

The 2026 Digital Omnibus moved the EU AI Act's high-risk deadlines. Anyone still selling you an "August 2026 high-risk deadline" is selling a date that no longer exists. Evidence that doesn't lie starts with a timeline that doesn't either.

Aug 2, 2025

GPAI rules applied

Obligations for general-purpose AI model providers took effect.

Aug 2, 2026enforcing

GPAI fines · Article 50 · Article 4

The AI Office's enforcement powers activate: fines up to 3% of global turnover or €15M for GPAI providers. Article 50 transparency — chatbot disclosure, deepfake labeling — and Article 4 AI literacy enforce. Only Article 50(2) machine-readable marking of synthetic content slipped, to Dec 2, 2026.

Dec 2, 2027

Annex III high-risk obligations

Stand-alone high-risk systems (Arts. 9–15) — hiring, credit, education, essential services, biometrics — postponed from 2026 by the Digital Omnibus. Sixteen months of behavioral evidence is what a defensible conformity file is made of.

Aug 2, 2028

Annex I embedded high-risk

High-risk obligations for AI embedded in regulated products — machinery, medical devices, vehicles.

The vault

Evidence your auditor can verify without trusting us.

Every probe result is hashed into a per-system chain and signed. Change one record and the chain breaks — visibly, mathematically, for anyone who checks.

Three sealed evidence records linked into a signed chain
Fig. 02 — the sealed chained25519

Independent by design

Probative has no stake in your model, your cloud, or your security vendor. A judge that grades its own remediation isn't a judge.

Untested means untested

When no probe behaviorally tests a control, Probative reports it as untested — the honest coverage gap — instead of mapping it anyway.

Framework-mapped

Findings roll up to the EU AI Act, NIST AI RMF, ISO 42001, and the Colorado AI Act. One scan, four evidence packs.

The difference

Documented is not tested.

Governance platforms inventory your AI and collect attestations. Eval libraries test what your own team thought to test. Neither hands your auditor evidence they can verify without trusting you.

CapabilityGRC / governance platformsDIY eval librariesProbative
Adversarial behavioral testingQuestionnaires & policiesIf you build it11 attack classes, every scan
Independent judgeSelf-attestedGrades its own homeworkNo stake in your stack
Tamper-evident evidenceEditable recordsLogs & spreadsheetssha256 chain, ed25519 signed
Framework mappingControl checklistsManualEU AI Act · NIST · ISO 42001 · Colorado
Continuous re-verificationAnnual review cycleWhen someone remembersScheduled, signed, on repeat
Pricing

Start free. Prove it monthly.

Spot Check
$0
one scan, on us
  • Full 11-class probe battery
  • Independent judge grading
  • Snapshot evidence report
Break your AI — free
Pulse
$450
per month · annual by invoice
  • Continuous scheduled scans
  • Signed evidence chain
  • All four framework mappings
  • Scheduled re-verification
Request pilot
Assurance
$1,900
per month · annual by invoice
  • Everything in Pulse
  • Drift alerts between scans
  • Audit-grade evidence packs
  • Multi-system portfolio view
  • Regulated-buyer questionnaire support
Talk to us
Step zero

Before you prove the system behaves, know which rules apply.

Probative produces evidence against obligations you already know you have. If you don't yet know which of the EU AI Act, Colorado, Texas, Illinois, NYC, or California regimes reach your systems, start with Obligent — our sibling instrument: a deterministic, cited applicability engine that answers which obligations, from which rule, as of which date, and says needs analysis instead of guessing. Diagnosis there; evidence here.

Meet Obligent — know which AI rules apply →

What Probative is not. Probative is behavioral evidence, not legal advice, and not a certification body. Evidence packs show what your AI did under attack, mapped to framework controls — your counsel and your auditor decide what it means. Probative is currently in private pilot; every claim on this page describes the shipped probe battery and evidence engine, not aspirations.

GPAI fines land August 2.
December 2027 is closer than it looks.

Sixteen months of signed behavioral evidence is what a defensible conformity file is made of. Start the chain now.