AI accelerates the work. It never makes the call alone
AI is woven through our platforms: it detects, enriches, triages, authors tests, and builds investigation context continuously. What it never does is act unsupervised on anything consequential. This page draws that line exactly, because when your auditor or your customers ask how AI acts on your environment, that line is the answer you'll need.
Five commitments on how we use AI
01
Automation proposes; humans decide
AI runs the parts that scale: detection, enrichment, triage, test authoring, investigation context. It stops at the approval gate. Containment, response, and any consequential action execute only under a named human's approval. The autonomous loop in VirtueShieldX has run in production since June 2026, under analyst supervision, with a human owning every consequential decision.
02
We publish where the AI acts, and where it doesn't
Every platform page states, plainly, which capabilities are autonomous, which are AI-assisted (and reviewed by a human), and which are human-decided. Most vendors won't draw that line in public. We do, because a buyer deploying AI in their security or quality operations deserves to know exactly what runs without a person in the loop, and because it lets you answer your own AI-governance questionnaires with specifics rather than a vendor's assurances.
03
AI assists; evidence decides
A model can suggest, prioritize, and draft; it cannot assert a finding into existence. Exposures are corroborated across engines and proven exploitable before they reach your team, and what we stand behind is the demonstrated evidence rather than the model's confidence.
04
Dry-run before anything changes
Response playbooks can run in simulated mode first, so you see exactly what an automated action would do before it touches a live system. Nothing consequential happens on your environment without both a preview and an approver.
05
Your data is handled like evidence
Engagements run under NDA; engineers who handle client data undergo background checks; findings and telemetry are shared through agreed channels and not retained beyond the engagement. AI processing follows the same discipline. See the Trust page for the full posture.
The three roles AI plays, stated on every platform
Autonomous
Detection, enrichment, and investigation context-building run continuously, without waiting for a person.
AI-assisted
Triage, prioritization, and test authoring are AI-driven and then reviewed by an engineer or analyst before they carry weight.
Human-decided
Containment, response, and any consequential action execute only under a named human's approval, never by the model alone.
If you assess vendors with an AI questionnaire, these are our answers on the record. Anything more specific belongs in your service agreement, where it binds us.
Where does AI run in your operation?
Inside our three platforms. VirtueShieldX runs AI-driven detection, enrichment, and autonomous triage in security operations; VirtueThreatX uses it in exposure discovery and validation; VirtueATLAS in test authoring and self-healing automation. Each platform page publishes which of its capabilities are autonomous, AI-assisted, and human-decided, so you can quote that taxonomy directly into your own vendor assessment.
Where do humans review AI output?
At defined gates. Analysts supervise the VirtueShieldX loop and its AI-drafted triage before it carries weight; engineers review AI-proposed test repairs in VirtueATLAS before they land; consequential actions wait at an approval gate for a named person. You are buying the judgment of the people at those gates, with the AI doing the volume work underneath them.
Which decisions remain human?
Every consequential one. Containment, response, and any action that changes a live system execute only under a named human's approval. The autonomous loop in VirtueShieldX completed its first end-to-end production runs in June 2026, under analyst supervision, with human approval gates, and that supervision qualifier is part of how we describe it everywhere.
What happens to our data, and does it train your models?
No. Client data is never used to train models, in any of our platforms. Beyond that: engagements run under NDA, our platforms keep client data in per-tenant isolation, and findings and telemetry move through agreed channels and are not retained beyond the engagement. The same commitments are fixed in your service agreement before work starts, in writing you can hold us to, rather than left to a policy page that can change after signature.
How do you keep model errors out of what we receive?
Structurally. In VirtueThreatX, a finding is corroborated across engines, adversarially probed, and assigned one of four honest states before anyone sees it; only proven-exploitable exposures page your team. In VirtueShieldX, AI-drafted detections and triage run under analyst review and approval gates. Nothing a model asserts reaches your report without validation or a human review in between, which is why what you receive is evidence you can act on without re-checking our tooling.
We also secure other people’s AI
AI features are a new attack surface: prompt injection, insecure model integration, and shadow-AI endpoints sit outside the checks conventional tools run. Our offensive practice tests them as first-class targets: in one engagement we demonstrated a working prompt-injection bypass in an AI text-rewrite endpoint, found and verified fixed on retest. VirtueThreatX treats AI/LLM systems as one of its ten attack surfaces.