The console one senior team runs an engagement from.
Specialized agents and fine-tuned models give an engagement machine scale. A senior operator carries the judgment on every finding. The workbench is where the two meet.
The operator console for adversarial engagements.
Serpio runs its adversarial engagements from one internal console. Specialized agents and fine-tuned models put the known attack classes to a target at machine scale. Senior operators scope the work, clear every high-impact gate by hand, and rate every finding against a fixed rubric. The workbench stays with Serpio: clients read results, they do not operate it.
One engagement, in view.
A crew of agents runs in dependency order against the agreed scope and stops the moment it reaches a step that would act with real authority. What follows is an illustrative run: client identity is sealed, the codes and packs are placeholders.
run_8f3c1a · crew track_a · blocked on gate · 3 of 7 steps done
| Step | Agent and pack | Status |
|---|---|---|
| scope | scope.ingest | done |
| recon | recon.surface, read-only surface map | done |
| attack_prompt | attack.prompt, pack llm.indirect_injection.v1 | done |
| attack_agent | attack.agent, pack agent.tool_exfil.v1, high-impact | awaiting human gate |
| judge | judge.eval | pending |
| evidence | evidence.pack | pending |
| report | report.draft | pending |
A crew of agents executes in dependency order against the agreed scope. Each step records what ran and against which asset.
Every high-impact step stops at a gate. A named operator approves it before anything acts with real authority, and no agent can clear its own gate.
Each finding is rated on three axes: impact, exploitability, and authority, with impact weighted double. Severity follows from the score, not from feel, and a finding with no demonstrated exploit stays Info.
Attack classes exercised by a pack and classes demonstrated by a recorded finding, tracked across cadences as an auditable number rather than an adjective.
Run starts, steps, gate requests, and gate decisions append to the engagement log. The record is append-only: a decision cannot be edited after the fact, and a denial cannot be flipped to an approval.
The workbench, its attack packs, and the models under it stay with Serpio. They are not shipped, licensed, or run on client infrastructure. What the client receives is a read-only record of one engagement: the report, the findings, and the evidence bundle.
Authored once, run for many.
Operators author an attack pack once, versioned and mapped to a named coverage class, and the workbench runs it against many targets. That is what lets one senior team hold depth and scale at the same time: the machine carries the repeatable work, the operator carries the judgment. The client reads the results in the engagement record and never touches the console.
Standing coverage, two ways.
The same console backs two recurring offers, one operator-driven and one automated.
Senior-led, on a cadence
The retainer. Standing adversarial coverage against a fixed set of named assets, re-run on a cadence, with findings tracked to closure and re-tested as your systems change. A senior operator drives every attack, rates every finding, and clears every gate.
It is the premium tier. You receive a read-only engagement record on every cadence: runs, findings, coverage over time, and the evidence bundle for every finding, replayable by your own team.
Automated packs on a cadence
Versioned attack packs run against your staging or model endpoint on a schedule. It exercises the known, published attack classes, reports coverage over time, and raises a regression alert when a class that was closed reopens. Lower marginal cost, because it runs on compute rather than senior-operator weeks.
It is not the deep human red team: it runs the published classes, it does not discover new ones or judge novel findings. That depth stays with Continuous Assurance.
Ask about early access →Bring us a system to break.
The workbench runs behind every Serpio engagement. Start with a scoped adversarial test, or ask about continuous coverage.
Scope an engagement →