RedLens has spent its whole life proving how your AI breaks and writing that down as evidence an auditor will accept. Runtime Guard is the stage that was missing: the same finding, the same methodology code, and the same vocabulary, now watching the live request. Not a second product. The last step of the one you already have.
RedLens finds the attack, scores it, and writes it into an evidence record your auditor can read. That has been the product for a long time and none of it changes. What changes is what happens to a finding after the report: it now becomes a rule, and the rule watches the live request. Same finding ID. Same methodology code. Same three status words. Here is the whole thing, end to end.
Abstractions are easy to agree with and easy to forget. So here is one finding, a real row from the synthetic test tenant, carried from the attack that proved it through to the verdict it produces at runtime. Nothing in this table is a different system talking about the same thing. It is one record, growing.
Plenty of products run adversarial tests. Plenty of products filter traffic. Some vendors even do both, and their two halves still have nothing to say to each other, because a test suite and a traffic filter were built by different teams against different taxonomies. RedLens's halves were not. The methodology code that scored your finding is the methodology code the guard reports coverage against; the finding ID that broke you in the audit is the finding ID stamped on the verdict. This screen is the whole argument, and it is one screen because it is one system.
This is the part of an inline product that most vendors leave to the fine print, so it goes near the top here instead. RedLens rewrote its own SLA page once already to withdraw uptime guarantees it could not measure. Putting a RedLens dependency in front of your users' requests would have re-created that dishonesty at much higher stakes. Fail-open inverts it: a RedLens outage costs you coverage, never availability.
Enforcement is not a toggle somebody can find in a settings page. It is gated in code, the gate is visible in the console, and one criterion is honestly marked as missing rather than quietly assumed.
RedLens is a lifecycle, not an all-in-one platform, and the difference matters when you are the one signing for it. Here is the list a competitor would hand you, written by us first so you do not have to find out from them.
The audit half has been proving how your AI breaks for a long time, and it keeps doing exactly that. Runtime Guard is the stage that finally does something with the answer. A demo walks one finding through all five stages on a synthetic tenant (attack, controls, briefing, rule, verdict), including the stages that still read as gaps.