STALE MEASUREMENTOur published benchmark result was measured with v0.32.0, 9 releases ago. That is our own number, not your assessment, which runs against your policy on the current release. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
FOUNDING COHORT · 3 OF 3 SPOTS OPEN

A founding rate, in exchange for the right to publish the result.

Provael has no customer logos, no testimonials and no published case studies. That is a statement of fact, not modesty — and this programme is how it changes. The discount is not a discount: it is what publication is worth.

THE OFFER
$15,000
vs $25,000 standard — the same 2-3 week scope and the same deliverables
what you trade:
· permission to publish the result, co-branded or anonymised
· a reviewer who confirms the write-up before it goes live

3 of 3 spots open as of 20 August 2026
Why the rate is lower — stated plainly

You are paying partly in permission.

A red-team result nobody may describe is worth less to Provael than the same result published. The founding rate is that difference, priced. It is not an introductory offer that expires, not a volume discount, and not a signal that the work is smaller — the scope and the deliverables are identical to a standard assessment.

Saying so up front is deliberate: it pre-qualifies. If your organisation cannot agree to publication in any form, the standard rate is the right one and this page has saved you a call.

What you get

The same deliverables as every paid tier

A 2-3 week engagement. In exchange for the rate, permission to publish a co-branded, anonymized-if-needed case study. There is no reduced-scope version of the work — the difference between this and a standard assessment is the publication right, not the engagement.

  • Measured ASR with 95% Wilson confidence intervals and a benign false-positive control
  • Narrated attack chains, each with a reproducible proof-of-concept and per-trial trace
  • SARIF findings + a CI red-team gate for your pipeline
  • Compliance crosswalk: EU AI Act Art. 15, EU Machinery Reg, ISO 10218:2025, NIST AI RMF, IEC 62443
  • One free retest after you remediate, so the evidence reflects the fixed policy
  • Runs in your environment; you keep the data. Evidence, not certification.
What you give

Precisely what "design partner" costs you

  • Permission to publish the result as a co-branded case study — or anonymised, if you prefer (see the FAQ for exactly what anonymised removes).
  • Permission to publish the measured numbers: the attack-success rate with its interval, the benign control, and the families that did not transfer.
  • A named technical reviewer on your side who can confirm the write-up is accurate before it goes live.

Nothing here is a licence to publish whatever we like. You see the write-up before it exists publicly, and a factual correction is not negotiable — it is the point. What you cannot do is withdraw a result because it is unflattering; that is the one thing the rate is buying, and we publish nulls anyway.

The outcome

Where the case study lands

On /findings, alongside the existing measured write-ups, in the same shape they use: the headline attack-success rate with its 95% Wilson interval, the benign false-positive control, the attack families that did not transfer, and a "what this is not" section. It carries the same caveats as everything else here — simulation only, stated sample size, stated limits.

It is indexed, linked from the research feed, and included in the site's Markdown twins so agents evaluating vendors can read it. If the engagement is anonymised, it lands in the same place with the identifying detail removed rather than in a separate, quieter section.

/case-studies is the buyer-facing index of those write-ups. It currently holds none — that is stated in its own heading rather than disguised — and it sets out what a published study contains, exactly what anonymisation removes, and a worked example built from Provael's own measured run.

FAQ

The three questions this offer actually gets

Can we stay anonymous?

Yes — that is what "anonymised-if-needed" means, and here is exactly what it removes: your organisation's name and logo, the checkpoint identifier, any model or product name, the task descriptions if they are proprietary, and any trace detail that would identify the system. What stays is the measurement: the attack families, the rates with their intervals, the benign control, and the caveats. A study becomes "a humanoid manipulation policy" rather than a named product.

The one thing anonymisation cannot do is remove the result itself. If the finding is only publishable when nobody can tell it happened at all, this is the wrong programme and the standard rate is the right one.

What if the result is bad?

Then we publish it, and that is the answer we would give before you asked —why we publish null results was written before this programme existed. A red-team that only reports when it finds something has no denominator, and a vendor who suppresses its own bad results has told you exactly what its good ones are worth.

Worth separating two things a "bad result" could mean. A high ASR is a finding about the policy, and publishing it with the remediation and the free retest is a stronger story than a clean sheet — it is the shape most of the useful write-ups in this field take. A null result — the attacks did not transfer — is a publishable measurement too, and the existing reference run already reports honest 0% nulls for two of its three families.

Who owns the data?

You do. The assessment runs in your environment and you keep the data — that is one of the standing deliverables above, not a concession made here. Provael does not take custody of your checkpoint, your weights or your traces, and nothing about the engagement transfers rights in them.

What the programme licenses is narrower and specific: permission to publish the measurements produced by the assessment, and the co-branding, in the form you approve. Commercial terms are settled in the contract before work starts, not inferred from this page.

Next

Applying

A 30-minute scoping call establishes whether your stack is a fit and whether publication is something your organisation can agree to. Both of those are better settled in a conversation than in a form — and /contact explains why there isn't one.

Book a scoping call →Compare the tiers

Not ready to talk money? /submit is the free, self-serve path: run the suite yourself and put the row on the leaderboard, no call required.