Breaking July 31: AI agent containment breach confirmed at 3 organizations

The attack on your AI
already happened.
Did you catch it?

RedLens runs the same real adversarial attacks hackers use against your AI, then shows you exactly where you're exposed before damage is done.

0
Attack
Categories
0
Attack
Methodologies
0
Breaches
Last Month
<10m
To First
Finding
APE · PROMPT INJECTION ACE · CONTAINMENT ESCAPE DEI · DATA EXFILTRATION ATA · TOOL HIJACK OOB · FILTER BYPASS
LIVE SCAN — 5 OF 6 CATEGORIES ACTIVE
Trusted by security teams at healthcare organizations nationwide
SOC 2 Type II — In Progress
HIPAA BAA — Available on Request
Enterprise SLA Available
The audit-to-runtime lifecycle
The loop now closes: your findings watch your live traffic
See the whole loop →
Attack proven
Master Attack Schema v2.0, scored by CVSS
Mapped to controls
HIPAA, NIST AI RMF, ISO 42001, CJIS, OWASP
Briefed to the board
Plain language, citing the real findings
Finding becomes a rule New
Reviewed, never auto-applied
Watching live traffic Preview
Observes and flags: evidence / partial / gap
Live Threat Intelligence
AI Agent Containment Escape — New Attack Class Detected
AI agents are now capable of escaping sandboxed environments and breaching production infrastructure. That is an attack class your current security tools cannot detect.
View all intel →
0
Average cost of a
healthcare data breach
0
Organizations breached
by AI agents · July 2026
0
Of health systems deploying
AI without security testing
0
Existing tools that test
AI adversarial attacks
Healthcare is the costliest sector for data breaches. The AI-enabled breach figure below is a cross-industry average, so the two measure different things. Source: IBM 2026 Cost of a Data Breach Report.
Why Now

The economics of AI attacks just tipped

Attackers don't need a breakthrough to hit your AI systems. They just need you to not be testing them. The latest industry data shows that gap is already being exploited at scale.

1 in 4
malicious breaches are now AI-enabled, a share that grew 56% year-over-year. These breaches cost organizations $6M on average, about $1M more than a typical breach.
20%+
of organizations reported a breach that specifically targeted their AI models or applications. The most common ways in were compromised APIs/plugins and cloud misconfigurations.
Source: IBM 2026 Cost of a Data Breach Report, with the Ponemon Institute, published July 29, 2026.
The Assessment Process

From zero to security report in under 10 minutes

Try it free →
01
Register your AI systems
Tell RedLens about the AI your organization uses: patient chatbots, diagnostic tools, dispatch AI, internal copilots. We build a threat model specific to your deployment.
02
RedLens attacks your AI
Our engine fires real adversarial attacks from the Master Attack Schema v2.0: 6 categories and 18 methodologies, each scored by CVSS. Prompt injection, containment escapes, data exfiltration, and more.
03
A report your board can read
A PDF with your risk score, every vulnerability found, remediation steps, and compliance evidence mapped to HIPAA §164.x, NIST AI RMF, and OWASP LLM Top 10 (2026). Auditor-ready in minutes.
See It In Action

This is the actual platform

These are real screens from a live RedLens deployment, not mockups.

RedLens live dashboard showing total scans, confirmed vulnerabilities, attacks deflected, and a composite risk score
Live risk dashboard
Scan volume, confirmed vulnerabilities, and a composite risk score, updated as attacks run.
A confirmed RedLens finding with severity and CVSS score
Every finding, scored
Confirmed vulnerabilities land with a severity rating and CVSS score, ready to route to your team.
RedLens compliance evidence package mapped to HIPAA, NIST AI RMF, and ISO/IEC 42001
Auditor-ready evidence
One-click compliance packages mapped to HIPAA, NIST AI RMF, and ISO/IEC 42001. Every control reads evidence-recorded, partial, or gap, never just a checkmark.
The six Master Attack Schema categories inside the RedLens dashboard
Six categories, continuously tested
Every scan runs the full Master Attack Schema v2.0, from prompt injection to containment escape.
Continuous Monitoring & Alerts

A one-time scan tells you today's answer. RedLens keeps asking.

Prompts change, models get swapped, new attack classes get published. Scheduled re-testing catches drift automatically, critical findings alert your team the moment they're confirmed, and a daily-refreshed threat feed keeps you current. No one has to remember to log back in.

Scheduled Drift Detection
Put a system prompt on a daily or weekly retest cycle. Every run replays the identical adversarial suite against the identical prompt and models. The moment a dimension regresses, you're emailed exactly what changed.
  • Daily or weekly cadence, frozen prompt and models per schedule
  • Every regression, improvement, or lost signal named explicitly
  • A failed run retries within hours, so monitoring never goes silently quiet
Real-Time Critical Alerts
The moment a scan, vendor assessment, blast-radius map, PHI egress check, or prompt-hardening run turns up a critical-severity finding, RedLens emails your team automatically. No one has to remember to check the dashboard.
  • Fires across 5 modules: scans, vendor risk, PHI egress, blast radius, prompt hardening
  • Per-user preferences, on by default for critical severity
  • Every send is logged and auditable, whether it was delivered, suppressed, or failed
Live Threat Intelligence
A feed of real-world AI security incidents, refreshed daily from CISA, NIST, and other security research sources, keeps your team current on the attack classes making news right now. It is the same feed driving the banner at the top of this page.
  • Refreshed daily, no manual curation required
  • Every record mapped to a Master Attack Schema category
  • Powers the live banner here and the full Threat Intel feed
Every one of these can also stream straight into your SOC. See Splunk Export below.
Master Attack Schema v2.0

Every known AI attack vector. Tested.

Built from documented real-world incidents. Updated continuously. Category 6 added July 2026 in response to the Anthropic breach.

APE · Instruction Layer
Adversarial Prompt Engineering
Can an attacker override your AI's instructions and make it behave as an unrestricted system? Instruction override, privilege escalation via roleplay, payload splitting.
CWE · Memory / RAG Layer
Context Window Exploitation
Can an attacker poison your AI's memory or inject malicious instructions into your knowledge base? Conversation poisoning, RAG pipeline attacks, context overflow.
OOB · Safety / Filter Layer
Safety Filter Evasion
Can an attacker bypass your AI's safety guardrails using obfuscation, encoding, or gradual boundary erosion? Semantic obfuscation, encoding substitution, low-and-slow attacks.
ATA · Agentic / API Layer
Agent and Tool Abuse
If your AI can take actions like sending email, querying databases, or calling APIs, can an attacker hijack those actions? Indirect prompt injection, tool chain hijacking.
DEI · Data / Training Layer
Data Exfiltration & Inversion
Can an attacker extract your system prompt, reconstruct training data, or surface PII? System prompt extraction, training data reconstruction, embedding space probing.
ACE · Agent Runtime NEW
AI Containment Escape
Can your AI agent break out of its sandbox? Root cause of the July 2026 breach. Network escape, behavioral deviation, micro-step attack chains: attack patterns your current tools cannot see.
The Platform

One console, from first attack to live traffic

The scanner finds the vulnerabilities. The rest of the platform turns them into hardened prompts, least-privilege agents, auditor evidence, and a briefing your directors can read. Now it also turns them into runtime rules that watch for the same attack coming back.

Core · Red Team Scanner
Adversarial Attack Engine
Real attacks from the Master Attack Schema v2.0: 6 categories and 18 methodologies, every finding scored by CVSS and mapped to HIPAA, NIST AI RMF, and OWASP LLM Top 10 (2026).
Third-Party Risk · TPRM
Vendor AI Assessment
Black-box security testing of the AI vendors in your stack. Every target requires recorded vendor-side authorization before any attack traffic is sent. The output is a Vendor AI Safety Scorecard.
Runtime · Preview
Runtime Guard
The last stage of the same loop, not a second product: the findings the scanner already confirmed become per-tenant runtime rules, and every verdict names the finding whose rule fired and reports it in the evidence pack's own evidence / partial / gap wording. Observes and flags today; blocking is gated. Follow one finding through all five stages →
Healthcare · HIPAA
PHI Egress Scan
First-pass triage of the data flowing to your AI vendors: pattern-based detection of PHI-shaped content, flagged when it heads to a vendor with no BAA on file. It is a signal for compliance review, not a determination.
Pre-Deployment
Prompt & Guardrail Hardener
Score a system prompt's robustness before it ships: a free static analysis for instant gap-spotting, or a full adversarial red-team that attacks the prompt empirically and reports what broke.
Agentic AI
Blast Radius Mapper
Ingest your agent's tool schema in OpenAPI, Anthropic, or OpenAI format, and see what a hijacked agent could actually reach: attack chains, excessive permissions, and an auditable blast-radius score.
Agentic AI · OWASP
Excessive Agency Test
The OWASP LLM Top 10 (2026) least-privilege check: declare an agent's task and every tool it can reach, inject an adversarial instruction, and measure how much out-of-scope capability it holds.
Compliance
Evidence Packages
Point-in-time, auditor-ready records of what your testing actually captured, mapped to HIPAA and NIST AI RMF. Every control reads evidence-recorded, partial, or gap. RedLens documents evidence; it never certifies compliance.
Executive Reporting
Boardroom Risk Translator
Turns confirmed findings into a plain-language briefing for directors. Every risk statement cites, and is grounded in, real findings from your own scans, never generic boilerplate.
Visibility
Shadow AI Discovery
Passive detection of unmapped AI models and agentic calls in your outbound traffic. The LLM your security team doesn't know about is the one that never got tested.
Integrations · SIEM
Splunk Export
Export findings directly to Splunk via HTTP Event Collector. Events arrive field-parsed and searchable alongside the rest of your security telemetry, so AI risk lives where your SOC already works.
Industries

Protecting the organizations that cannot afford to fail

Healthcare and law enforcement AI deployments handle life-critical decisions. A vulnerability is not an inconvenience. It is a patient safety event or a civil rights violation.

Healthcare
Hospitals, health systems, and healthcare AI vendors deploying AI for patient care, clinical decision support, and administrative automation.
  • EHR automation agents with high-privilege database access
  • Patient-facing intake and scheduling chatbots
  • Diagnostic AI and clinical decision support tools
  • HIPAA compliance evidence packages for auditors
Learn more →
Law Enforcement
Police departments, federal agencies, and public safety organizations using AI for investigations, dispatch, and records management.
  • Criminal records and warrant query AI systems
  • 911 dispatch assistance and call triage
  • Digital evidence analysis platforms
  • Air-gapped on-premise deployment available
Learn more →
Enterprise
Financial services, legal, government, and enterprise organizations deploying AI agents with access to sensitive data and business-critical systems.
  • AI agents with tool, API, and database access
  • Customer-facing AI and support automation
  • Internal copilots with data access
  • MSSP and white-label multi-client mode
Learn more →
Why RedLens

Your current tools were
not built for this threat

The AI security market has consolidated fast: four of RedLens's closest peers were acquired by Palo Alto Networks, Cisco, Check Point, and F5 in the last two years. All of them run some form of AI red teaming or model scanning. None of them were built around healthcare compliance. RedLens was.

Scroll to compare all 8 platforms →
Capability RedLens AI Microsoft
Defender
CrowdStrike HiddenLayer
Independent
Palo Alto
Prisma AIRSfka Protect AI
Cisco
AI Defensefka Robust Intel.
Lakera
Guarda Check Point company
CalypsoAI
now F5 AI Guardrails
Mindgard
Independent
Works with any AI model Azure only integrated services only
Runs real adversarial attacks 1 detection only
Citation-level HIPAA §164.x mapping with evidence grading 2 3 4 5 6 7 8 9
Healthcare-only product 10 10 10
Detects AI containment escapes
Self-serve free assessment 11
Accessible to community hospitals quote-based; no public entry tier quote-based; no public entry tier Enterprise Enterprise Enterprise free eval; production quote-based Enterprise Enterprise
  1. Cisco AI Defense — red teaming: its "algorithmic red teaming" leans toward automated scanning rather than adaptive, human-style red-teaming.
  2. Microsoft Defender — HIPAA: the Regulatory Compliance Dashboard maps general Azure infrastructure controls to HIPAA, not AI/LLM-specific controls.
  3. CrowdStrike — HIPAA: the core Falcon platform is Coalfire-validated against eight key HIPAA technical requirements — the EDR platform, not a per-control public evidence grid for the AI product.
  4. HiddenLayer — HIPAA: generic marketing — "controls that support HIPAA compliance" and "HIPAA, HITRUST, and emerging AI governance requirements" — with no §164.x citations.
  5. Palo Alto Prisma AIRS — HIPAA: healthcare is named as a served industry in acquisition materials only; no HIPAA control mapping appears on product pages.
  6. Cisco AI Defense — HIPAA: says it can "help address the new HIPAA Security Rule standards" and is positioned for regulated sectors including healthcare — but with no §164.x detail.
  7. Lakera — HIPAA: no HIPAA-specific language found on lakera.ai or checkpoint.com/ai-security.
  8. CalypsoAI / F5 — HIPAA: the most explicit of the generic group — "automated auditing templates for GDPR, HIPAA, EUAIA, and more"; "security rules align with HIPAA, GDPR, FDA" — but still no citation-level mapping.
  9. Mindgard — HIPAA: no HIPAA mention; maps to MITRE ATLAS, NIST, OWASP, and AIUC-1 only.
  10. Dedicated healthcare page: CrowdStrike, HiddenLayer, and CalypsoAI/F5 each publish a healthcare page, but none is a healthcare-exclusive product the way RedLens is.
  11. Cisco AI Defense — self-serve: offers an "Explorer Edition" self-serve trial, which likely requires signup.

HiddenLayer, Palo Alto Prisma AIRS (formerly Protect AI; reportedly ~$500–700M, an unofficial press estimate — the figure was never officially disclosed, closed July 2025), Cisco AI Defense (formerly Robust Intelligence, ~$400M, closed September 2024), Lakera Guard (acquired by Check Point for a reported ~$300M, an unconfirmed press estimate, announced September 2025), and CalypsoAI (acquired by F5 for $180M, closed September 2025) are all genuine, capable AI red-teaming or runtime-protection platforms. None map findings to HIPAA, NIST AI RMF, or OWASP the way RedLens does. Credo AI is worth a separate mention too. It is the closest adjacent player on compliance, but built for governance and oversight rather than running attacks against your AI.

Pricing

Simple, transparent pricing

Every plan includes a free assessment so you see exactly what we find before you commit to anything.

Developer
$799/mo
For dev teams testing a single AI agent before it ships. Self-serve, with no procurement or demo call required.
  • 1 AI agent or model under test
  • Monthly automated scans
  • All 6 attack categories
  • HIPAA compliance mapping
  • PDF security reports
Start Self-Serve →
Enterprise
$150k/yr+
For large health systems, federal agencies, and MSSPs with complex, multi-environment deployments.
  • Unlimited monitored workflows & simulations
  • Full air-gapped Docker deployment
  • Automated HIPAA/NIST compliance audits
  • Splunk SIEM integration (HTTP Event Collector)
  • Custom SLA available
Contact Sales

Every plan starts with a free AI security assessment. No credit card required to try it · Enterprise starting at $150k/yr, custom pricing for complex deployments

Common Questions

What your security team and legal counsel will ask

Do you have a SOC 2 certification?
We are in the process of SOC 2 Type II certification, targeting Q3 2027. Our infrastructure runs on Railway (SOC 2 Type II certified) and Anthropic (SOC 2 Type II certified).
How is RedLens different from CrowdStrike or Microsoft Defender?
Microsoft Defender only covers Azure-hosted AI. CrowdStrike finds misconfigurations. RedLens runs actual adversarial attacks against your AI and shows you exactly how it responds. Neither competitor does this.
Can RedLens deploy in our air-gapped environment?
Yes. For federal, law enforcement, and healthcare organizations with air-gapped requirements, we offer a self-hosted Docker deployment using an on-premise model. Your data never leaves your network.
Get Started

Your AI is live.
Is it secure?

Run a free assessment in 10 minutes. See exactly what an attacker would find in your AI deployment today, right now, with no account required.

Get New Posts by Email

New posts, straight to your inbox

Original writing on AI security from the people building the platform: agentic risk, red-team findings, and the advisories worth reading in full. A few times a month at most, no sales sequence, and one click to leave.

We use your address for new-post notifications and nothing else. Every email carries an unsubscribe link. See our Privacy Policy.