AI accelerates the work — it never makes the call alone
AI is woven through our platforms: it detects, enriches, triages, authors tests, and builds investigation context continuously. What it never does is decide, unsupervised, on anything that matters. This page states exactly how — because in security and quality operations, where AI stops and a human takes over is the question that actually matters.
Five commitments on how we use AI
01
Automation proposes; humans decide
AI runs the parts that scale — detection, enrichment, triage, test authoring, investigation context. It stops at the approval gate. Containment, response, and any consequential action execute only under a named human's approval. The autonomous loop in VirtueShieldX has run in production since June 2026 — under analyst supervision, with a human owning every consequential decision.
02
We publish where the AI acts — and where it doesn't
Every platform page states, plainly, which capabilities are autonomous, which are AI-assisted (and reviewed by a human), and which are human-decided. Most vendors won't draw that line in public. We do — because a buyer deploying AI in their security or quality operations deserves to know exactly what runs without a person in the loop.
03
AI assists; evidence decides
A model can suggest, prioritize, and draft — it cannot assert a finding into existence. Exposures are corroborated across engines and proven exploitable before they reach your team; a model's confidence is never the last word. AI raises the signal; demonstrated evidence is what we stand behind.
04
Dry-run before anything changes
Response playbooks can run in simulated mode first, so you see exactly what an automated action would do before it touches a live system. Nothing consequential happens on your environment without both a preview and an approver.
05
Your data is handled like evidence
Engagements run under NDA; engineers who handle client data undergo background checks; findings and telemetry are shared through agreed channels and not retained beyond the engagement. AI processing follows the same discipline — see the Trust page for the full posture.
The three roles AI plays — stated on every platform
Autonomous
Detection, enrichment, and investigation context-building run continuously, without waiting for a person.
AI-assisted
Triage, prioritization, and test authoring are AI-driven and then reviewed by an engineer or analyst before they carry weight.
Human-decided
Containment, response, and any consequential action execute only under a named human's approval — never by the model alone.
AI features are a new attack surface — prompt injection, insecure model integration, and shadow-AI endpoints sit outside the checks conventional tools run. Our offensive practice tests them as first-class targets: in one engagement we demonstrated a working prompt-injection bypass in an AI text-rewrite endpoint, found and verified fixed on retest. VirtueThreatX treats AI/LLM systems as one of its ten attack surfaces.