Field 01 — Security declaration · injection screening
Raw email is attacker-controlled input. We screen every message for prompt injection before your agent reads it, then publish exactly how well that screening holds, including what got through. No vendor can honestly promise immunity, so we don't. We show you the record instead.
Field 02 — Inspection record
A corpus of attack emails run through the real production pipeline. Most attacks come from independent AI adversaries and a public benchmark, not from us. Every figure below is pinned to the exact models and date it was measured, and re-run against a fixed corpus each release. We keep the live attack corpus private — publishing it would just hand the next attacker a starting kit.
Field 03 — Failure ledger
A security page that only lists wins is marketing. Here are the failure modes the board tracks, described plainly. Hiding them is what would make the rest worthless.
Field 04 — Adversaries we don't control
A defense tested only against attacks its own author imagined is grading its own homework. Most of this corpus is written by models from other labs that don't know our internals, plus a public benchmark. A miss they find is real signal.
Field 05 — Cracks found & closed
The point of the exercise is to break the defense before an attacker does. Three real weaknesses it surfaced, and what we did about each one.
Field 06 — What we don't claim
Want the detail behind the aggregate? Prompt injection attack examples walks through six payload shapes — hidden HTML, stripped comments, zero-width text, and the multi-step decode SOPs that beat model-only screening — each with the real sanitizer and scanner output our pipeline produces on it. Email prompt injection is the channel-level threat model: every part of a message that can carry an instruction, the fixed gate order, and which way each gate fails.
Field 07 — Dispatch
Screened against known patterns, never immune. The record above is the whole claim.