We build runtime verification and security auditing tooling for AI agent production systems. Every claim on this page is backed by data you can independently verify — no fabricated numbers, no borrowed credit.
Each result below links to its primary source. Figures are taken from the artifacts themselves, not from estimates.
A bytecode-verified set of vulnerability detection patterns for AI agent frameworks, covering RCE, SSRF, credential exposure, prompt injection, and schema drift.
A release of 20,000 real production agent execution traces published for independent verification. Covers 13 LLM providers and 33 models.
Distinct LLM providers and models represented in the public trace dataset, counted from the dataset fields.
The full trace asset inventory behind the CCS program, held in the internal asset archive.
A public specification of the CCS runtime verification framework for agent systems, registered with a resolvable DOI.
Our detection rules provide rule-level coverage for known vulnerability classes in the AI agent ecosystem. Coverage of a published CVE means our engine detects the underlying pattern — it does not mean Correctover reported that CVE.
Rule coverage for sandbox-escape and command-injection patterns in containerized agent execution.
Rule coverage for remote command execution patterns in MCP tool invocation paths.
Rule coverage for protocol-level patterns across MCP servers: readOnlyHint bypasses, path traversal, credential exposure, and SSRF.
Vulnerabilities we have reported to coordinated disclosure programs. Status reflects our submission state, not the program's final disposition.
In-flight report regarding a Cloudflare MCP integration issue.
Submitted · In TriageReport #3904830
Three reports delivered to the Microsoft Security Response Center for the open-source markitdown project.
Submitted · Awaiting Triage3 items delivered
Start with a free snapshot audit of your AI agent infrastructure. No commitment, no code access required.