AI Security Lab
I’m building this in the open, in two directions at once: security for AI — red-teaming AI systems I operate myself — and AI for security — using AI to run security operations, strictly human-in-the-loop. Both are tracked here the same way IEM-PM is tracked on the Roadmap: what’s built, what’s proven, what’s next.


The Architecture
Visual, Not Verbose
Security for AI
A URL-driven adversarial testing tool for LLM applications — real prompts against real live sites, no mocked targets, every test case grounded in the live OWASP GenAI LLM Top 10 2026, fetched fresh at runtime rather than bundled as a stale copy.
Production-tested on the live OWASP GenAI Top 10 2026, run against this site’s own two assistants (the general one and the LiftOff TA) as real targets.
Converged Security Intelligence
Converges physical security, cybersecurity, and operations telemetry into a single intelligence layer, then verifies the installed products actually coordinate when a real event fires — surfacing coverage gaps before they become incidents. AI is scoped to narration and remediation guidance only; every action stays human-confirmed.
Live in production on real client telemetry, proven on a config-driven engine that onboarded a new data source with a single configuration change and zero new code. In internal validation ahead of client rollout.

Validation at Scale
What was actually tested in production — not what’s planned, not what’s theoretical.
Validated Against Real Sites
- Every test sends real adversarial prompts to real, live LLM-backed sites and records the real replies — no mocked targets, no simulated responses
- Four probe categories run with evidence on disk: Jailbreaking (LLM01), Sensitive Information Disclosure (LLM02), Insecure Output Handling (LLM10), Unbounded Consumption (LLM06)
- Every test case is grounded in the live OWASP GenAI LLM Top 10 2026, fetched fresh at runtime — never a stale bundled copy
- Evidence discipline enforced end to end: states what was tested and what wasn’t, reports heuristic findings, never issues a bare “SECURE” verdict
- Run against this site’s own two live assistants as real targets — both endpoints (/api/chat, /api/liftoff-chat) discovered by the tool itself, not told to it; screenshots on /evidence
Validated in a Live Platform
- A single configuration change onboarded an entirely new telemetry source in production, with zero new code — proof of a data-driven architecture, not one built around any single vendor
- An Implementation Assurance Twin verifies installed security products actually coordinate when a real event fires, surfacing coverage gaps before they cause an incident
- AI stays strictly human-in-the-loop: narration, natural-language queries, and remediation guidance only — no autonomous action, no write access to production, ever
- Multi-tenant by design, with enforced isolation on every data layer including every AI tool call — currently in internal validation ahead of client rollout

The Road Ahead
Four Probes Built & Tested
Jailbreaking, Sensitive Information Disclosure, Insecure Output Handling, and Unbounded Consumption — each grounded in the live OWASP GenAI LLM Top 10 2026, and run against this site’s own two live assistants as real targets (see /evidence for the screenshots).
Extend Coverage, Integrate
Expanding probe coverage further down the OWASP Top 10 and formalizing the disclosure/reporting workflow.
Broaden the Evidence Base
Continue expanding coverage as the field and its standards evolve — every new claim held to the same evidence discipline: state what was tested, what wasn’t, never a bare guarantee.
Convergence Architecture Proven
Introduced alongside IEM-PM as IEM’s security half. Config-driven convergence engine designed and proven: physical, cyber, and operations telemetry land through one data-driven pipeline, with no vendor-specific code required.
Applied in Production
Live in production on real client telemetry. An Implementation Assurance Twin verifies installed products actually coordinate when a real event fires, surfacing gaps before they become incidents. In internal validation ahead of client rollout.
Publish the Discipline
The convergence discipline publishes in the open, alongside IEM-PM, once production validation across live client sites concludes.
Findings and Writing

Latest build update, posted alongside this work as it happens.
Read on LinkedInThe full archive of what’s posted, on this and everything else, lives on Writing.
Both directions, in the open
Security for AI and AI for security, tracked with the same evidence discipline as everything else here. Follow along on LinkedIn, or see how this fits alongside the program-management track on the Roadmap.