Skip to content

AI Policy

Escape uses AI in Automated Security Testing and Attack Surface Management (ASM). This policy explains the AI features available in Escape, how their data is handled, and the safeguards in place.

Read the Full Policy

Download the Escape AI Overview & Trust Guidelines (PDF)

The PDF is the authoritative version. This page summarizes it.

AI-Powered Features

Escape uses proprietary AI models and external AI services across DAST and ASM workflows.

First-Party Proprietary AI Features

Escape's proprietary AI models run on AWS infrastructure and support:

  • Business Logic Security Testing: AI-driven testing that identifies business logic vulnerabilities in web applications and APIs.
  • Attack Surface Management and Asset Discovery: automatic identification and mapping of APIs and web applications to find potential attack surfaces.

Externally Enhanced AI Features

Escape uses Microsoft Azure LLM Deployments and Cloudflare Workers AI Models alongside its proprietary models for:

  • Escape MCP: an AI assistant that manages applications, monitors scans, and reviews issues through MCP over the Escape API.
  • AI Context and Remediations: contextual guidance and recommendations for vulnerabilities based on real-time scan data.
  • AI Pentesting: AI-assisted testing that improves vulnerability detection and remediation.
  • False Positive Triage: AI filtering that improves scan accuracy and efficiency.

Data Handling and Safeguards

  • First-party models: data is processed and stored in Escape's designated AWS region.
  • External AI services: these services may retain data for up to 30 days for abuse detection and moderation. They don't use it for model training or store it long term.
  • Tenant isolation and access: AI interactions stay within your Escape environment. Customer data isn’t shared between customers, and role-based access control limits access to each user's role.
  • Processing location: AI processing runs in Escape infrastructure by default. External processing follows the applicable regional retention policies and standards, including EU and US requirements.
  • AI-generated output: output can vary between runs.

AI-generated outputs are for operational use and may be used commercially when they comply with Escape's platform terms.

AI Principles

  • No customer data for training: customer data is never used to train AI models.
  • Data privacy: customer data is processed securely within your Escape environment.
  • Opt-out: you can ask to disable external AI features at any time. These actions are logged and auditable.
  • Transparent interactions: AI features are explainable and aligned with cybersecurity standards, including SOC 2 Type II and GDPR.

Questions

For questions about Escape's AI features, contact your account manager.