AI/RAG security scan
Discover and test AI APIs, model protections, retrieval boundaries and connected tools from one verified domain.
Test the trust boundaries attackers target
VICE follows the public AI surface from API access through model behavior, retrieved context and connected tool actions.
Evidence, not vibes
Every finding keeps its raw evidence next to the remediation, so you can verify the problem is real before you fix it.
An AI fix for every finding
Each finding ships with a plain-language explanation and the exact patch. Paste it into Cursor or your migration and move on.
API discovery
Discovers same-origin AI routes and checks anonymous access, authentication, CORS and rate limits.
Model protections
Tests prompt injection, system instruction exposure and sensitive output.
RAG pipeline
Checks retrieval isolation, cross-tenant exposure, poisoned context and deleted documents.
Connected tools
Tests unsafe URL access, internal destinations and unauthorized actions.