Security Stack Logo

Workspace

Evaluation packs

TL;DRCurated requirement sets per Domain, distilled from industry-standard security frameworks.

An evaluation pack is a researcher-curated starter set of requirements for a Domain. It exists so you do not have to build an evaluation from a blank page: load the pack and your run starts with the capabilities that matter in that market, every one of them ready to edit.

What a pack seeds

A pack seeds capability requirements: documented catalog features, under their canonical names, that our research ties to the security outcomes buyers in that Domain evaluate for. Because the seeded rows use the catalog's own vocabulary, the matching system can score every one of them automatically against every listing.

A seeded row is a normal requirement. Reprioritize it, rename it, or remove it; the run owns its requirement set, and the pack claims no special authority once loaded.

Distilled from industry-standard frameworks

Pack contents are distilled from published security frameworks. The live AI Security pack, for example, draws on the OWASP LLM Top 10, the NIST AI RMF, and MITRE ATLAS. Behind each pack sits a curated map from the outcomes those frameworks describe to the documented features that cover them, and the pack seeds the features that map targets. The curation is editorial work, maintained by us and reviewed as the frameworks and the catalog evolve. The map is the one piece we do not publish row by row, because it would hand vendors a recipe of exact features to claim; what a pack seeds is visible in full when you preview or load it.

Optional by design

Packs are a library, never a gate. You can preview a pack's contents before loading it, load it when you create the evaluation or later from the Requirements stage, and remove it again. An evaluation built entirely from your own requirements works the same way and ranks the same way.

Packs are built one Domain at a time. AI Security is live today, with GRC & Compliance and Identity & Access Management next in line. In a Domain without a live pack you start from your own requirements, and everything else about the run is identical.