Train and Evaluate Safer, More Capable Agents
Simulated, industry-specific workflows contain hidden attacks grounded in real-world adversarial patterns to measure whether agents complete tasks while resisting manipulation.
Start the ConversationAlice Data Advantage
Alice is the world’s largest collector and manager of adversarial intelligence data. Our data is the cornerstone for protecting platform, tech, and users online.
Explore Rabbit Hole IntelligencePrepare Agents for the Threats They Will Face in Production
Train and evaluate agents on real-world tasks across high-fidelity computer-use and tool-use environments generating full trajectories for training, custom evaluations, and benchmarking.
Adversarial Risk Coverage
Test prompt injection, jailbreaks, PII exposure, data exfiltration, malware, bias, and compliance failures.
Computer-Use and Tool-Use Environments
Cover visual interfaces, APIs, connected tools, and terminal-based workflows.
Consumer and Enterprise Workflows
Simulate applications across industries, business functions, and everyday consumer tasks.
Deterministic Verifiers and Rubrics
Reliably measure whether agents complete tasks, follow safety policies, and resist manipulation.
RL Gyms Across Domains, Capabilities, and Risks
E-commerce Seller IPI WebGym
A high-fidelity replica of an e-commerce seller back office where agents complete realistic operational tasks while navigating indirect prompt injections hidden across the interface.
Coding Security
A coding-agent environment that tests whether agents can complete development tasks while resisting manipulation embedded across code execution, repository interactions, and connected tools.
WebApp PenTesting
A realistic web application environment where agents identify and exploit vulnerabilities across red-team and blue-team security tasks.
HR Agent Tool-Use Gym
An enterprise HR environment where agents complete workflows involving hiring, payroll, and employee data through connected tools and non-visual interfaces.
Tasks measure whether agents complete the requested workflow while following safety policies, protecting sensitive information, and resisting instructions that could redirect them toward unauthorized actions.
The Alice Difference
The Rabbit Hole, our adversarial engine, draws on billions of data points across hundreds of languages and cultures to create hidden attacks that reflect what agents encounter in production.
Deep Harm Area Domain Expertise
Over eight years partnering with top-10 tech platforms on trust and safety across extreme harms spanning safety (CBRNE, deception, political bias, child safety), security and privacy (prompt injections, PII, data exfiltration, malware), and other risks including financial, legal, and medical.
Reliable Training Signals
Deterministic verifiers and expert-calibrated rubrics produce auditable rewards that show whether an agent succeeded, followed policy, resisted manipulation, and where it failed.
Realistic, Expert-Built Workflows
Near-pixel-match environments and tasks developed with domain, safety, and security experts. Every gym undergoes SME consultation and QA to minimize the gap between simulation and production.
Lead with Safety. Innovate with Confidence.
GenAI risk addressed early becomes a competitive advantage - enabling responsible releases, sustained trust, and faster innovation.
Ready to take the next step?
What’s new from Alice
ENT-IPI Bench: Enterprise Indirect Prompt Injection Benchmark
We evaluated nine frontier models as enterprise agents across 147 adversarial scenarios from seven work domains in seven industries for their vulnerability to indirect prompt injection.
LIVE from Black Hat Las Vegas: AI, Nation-States, and the Battlefield That Keeps Changing
What if the biggest threat to your security team isn't the attacker, it's the model you're relying on to stop them? LIVE from Black Hat Las Vegas, Mo and Madi bring together two cybersecurity authors, Caroline Wong, Chief Strategy Officer at Axari and author of The AI Cybersecurity Handbook, and Allie Mellen, Principal Analyst at Forrester and author of Code War, who wrote very different books that turn out to be arguing the same point. One explains why nations attack the way they do. The other explains why AI just changed the cost, speed, and scale of everything. Tune in!
It Takes AI to Break AI: The Case for AI Red Teaming
As AI systems gain autonomy, organizations need security approaches built specifically for AI behavior. Learn why AI-driven red teaming is becoming a critical defense layer.
5 Ways Your Third-Party CX Agent Gets Broken
Third-party CX agents create hidden liability. Learn the 5 attack patterns vendors miss and how WonderSuite closes the gap.
