Stalwart AI Assurance
Find every way past your AI guardrails, prove the ones that hold and get a checked fix for the ones that don't. One API for guardrails, agent tool choice and model verification.
Products
5 in one API
Every finding
Reproduced + fixed
Evidence
Auditor-checkable
Access
One API key
Everything you need to trust what your AI does
Five products, one API key. Each one gives you an answer you can act on: proof that something cannot happen, or the exact case where it does, with a fix.
Guardrail Bug Hunter
Find every way past your AI guardrails before an attacker or an accident does.
Guardrail Verification
A yes-or-no answer, with evidence, to “can this agent ever do X without Y?”
Guardrail Writing
Write a rule in plain English and get back a policy that has already been checked.
MCP Tool Selector
Predictable, explainable tool choice for AI agents.
Random Forest Verification
Show that your random-forest model behaves as required, or get the exact case where it does not.
Bot Builder
Declare a domain agent that acts with all of the above built in.
We scanned the public guardrails that a whole industry copies
We pointed the Guardrail Bug Hunter at the public rule files of a leading open-source AI guardrail framework: the framework's own library of ready-made safety rails, the sample assistants its vendor publishes, and partner and community projects. 185 files from 12 repositories, scanned offline with no AI model in the loop.
Two files held real vulnerabilities, and each was reproduced in the framework's own runtime. The Bug Hunter wrote a corrective rule for the first and proved that it closes the hole without blocking anything else.
These are professional reference files that many teams copy, so every defect travels with every copy. Sampling would not have found them. Exhaustive analysis did.
185
guardrail files from 12 public repositories
2
vulnerable files, each reproduced in the framework's own runtime
32
tool calls an attacker could trigger just by steering the conversation
8.5 s
to scan the framework's 115 toolkit files
Hallucinations reported as jailbreaks
A rail that detects hallucinations raises them as jailbreaks. A team that blocks jailbreaks blocks every hallucination too, and a team that handles hallucinations never sees this rail's.
Three defects in a food-ordering assistant
Clearing the cart never runs, swapping an item checks the wrong value, and replies about the customer's order are left to unchecked AI-generated text.
Tool calls anyone can trigger
32 tool calls in 28 files run on the user's apparent intent alone, so anyone who can steer the conversation can trigger them. Two of them place food orders with no check of who asked or whether they confirmed.
Figures from our research paper, for a scan run on 3 October 2026.
Proving what an AI agent cannot do
Testing samples. Proof covers every case.
Red-teaming and evaluation suites only find a hole if someone happens to try it. Stalwart AI Assurance checks every case, and gives you evidence either way.
| THE QUESTION | SAMPLING & RED-TEAMING | STALWART AI ASSURANCE |
|---|---|---|
| What is checked | The prompts someone thought to try | Every possible case |
| When nothing is found | A pass only means nothing failed | A certificate anyone can re-check |
| When something breaks | A transcript, if you are lucky | The exact case, reproduced |
| The fix | Manual prompt tweaking | A fix that has already been checked |
| For your auditor | Hard to repeat | Deterministic and replayable |
See what your AI cannot do
Read the API reference and try a call, or register your interest and our team will be in touch.
A finance case study, step by step
Our technical demo runs the engine on a regulated-finance policy set: a trade-booking approval gate, a below-threshold exemption that opens a bypass, and a consumer-duty advice rule. Pick a case to see the policy, the verdict and the evidence.
Algebraic Guardrail Verification in Action
define user request_trade_booking
"book this contract note"
define flow trade_booking_gate
user request_trade_booking
if $four_eyes_approved
bot book_trade
else
bot refuse_unapproved_bookingMATHEMATICALLY SAFE (UNSAT)
The algebraic solver derives 0 = 1 in 5 steps. Over all possible 2^N runtime contexts, the action book_trade is provably unreachable unless four_eyes_approved is positively asserted.
Algebraic verification benchmarks
Regulatory policies, tool dispatch gates and state lookbacks, decided by deterministic finite-field elimination.
FCA Consumer Duty Advice Guardrail (410 Variables)
410-variable synthesized GF(2) circuit under FCA COBS/Duty obligations. Proved that advising permissions cannot be bypassed via targeted-support advice flows.
Middle-Office Trade Booking Dispatch Gate
Discovered an OR-accumulation hole in a sub-threshold booking exemption. Generated a minimally disruptive policy patch certified to block the vulnerability.
Multi-Step Velocity Chain State Lookback ($prev.v)
Stateful lookback verification enforcing dynamic transaction frequency caps across conversational turn state variables.