Connect to Target
Run real HTTP probes against your AI agent or infrastructure endpoint. Unlike the conformance test cards, these probes send actual requests to your target system and check the real response. No bundled results, no simulations. 30 probes across all 7 DGV layers.
How this differs from the conformance test cards
Conformance Test Cards (89)
Run bundled test scripts against the bundled verifier. Self-referential: the tool tests its own verifier against its own test cards. Useful for demonstrating the receipt format and gate states, but does not test your infrastructure.
Live Probes (30)
Send real HTTP requests to your target system. Check the actual response status code, body, and timing. Generate PSR-001 receipts from real evidence. This is what an auditor would use to verify your system is actually secure.
Live probes require the desktop app
Live probes send real HTTP requests to your target system. This requires the DGV Auditor Toolkit desktop app to avoid browser CORS restrictions. Download it here.
Target Configuration
Available Live Probes (30)
These probes send real HTTP requests to your target system. Unlike the conformance test cards, these do not use bundled or simulated results — each probe checks your target's actual behavior.
What the probes test (30 probes across 7 layers)
L1: Boot & Identity (5 probes)
Connectivity, auth required, token tampering, expired token rejection, security headers, CORS, health endpoint.
L2: Memory & State (3 probes)
Provenance traceability, model version disclosure, models endpoint.
L3: Mutation & Integrity (4 probes)
Adversarial input, error message leakage, PII handling, prompt injection.
L4: Timing & Replay (5 probes)
Replay detection, audit log availability, rate limiting, streaming integrity, fail-closed latency.
L5: Session & State (1 probe)
Session continuity — non-existent session handling.
L6: Risk Interpretation (6 probes)
Deterministic output, boundary enforcement, instruction hierarchy, multi-turn manipulation, regulatory compliance, data exfiltration.
L7: Application Enforcement (3 probes)
Refusal correctness, high-risk content refusal, out-of-scope execution, privilege escalation.
Each probe generates a PSR-001 receipt with the real HTTP response status, body snippet, headers, and timing. The receipt is marked _live_probe: true to distinguish it from conformance test card receipts.