AI Security & Integrity Lab

Defensive, authorized research protecting AI-powered education, publishing systems, open-source dependencies, and public-interest information.

The AI Security & Integrity Lab is a program of the AI Understanding Research Group. Its purpose is to identify and reduce security risks in systems we own, evaluate defensive controls in isolated environments, remediate verified findings, and coordinate responsible disclosure when a finding affects third-party open-source software.

Current research scope

  • Application security: authentication, authorization, input handling, session boundaries, and abuse-resistant workflows.
  • Software supply chain: dependency advisories, upgrade verification, build-time exposure, and reproducible remediation.
  • Prompt-injection resilience: defensive testing of AI-assisted research and publishing pipelines with untrusted source content.
  • Information integrity: source attribution, provenance, correction history, and controls against manipulated or misleading inputs.
  • Operational resilience: monitoring, recovery checks, least privilege, and evidence-based incident review.

Verified baseline: September 1, 2026

We ran an automated dependency audit, remediated the actionable web-runtime advisories through supported package and lockfile updates, and repeated the audit. The audited application-runtime subset reported zero known npm advisories across 106 dependencies. Three high-severity advisories remain in the Prisma deployment CLI dependency chain. That CLI is packaged for controlled schema synchronization during container startup and is not loaded by web request handling; the advisories are tracked for supported upstream remediation rather than hidden or force-downgraded.

Authorization and research controls

Testing is limited to AI Understanding-owned systems, local copies of open-source software, purpose-built labs, and environments for which we have explicit written authorization. We do not authorize malware deployment, denial-of-service activity, persistence, credential theft, access to another person's data, or testing of third-party systems without permission.

Potentially sensitive findings receive human review before reproduction, remediation, or disclosure. We retain only the evidence needed to validate a finding and follow the affected project's coordinated-disclosure process.

Research workflow

  1. Define the owned or explicitly authorized target, test boundary, expected risk, and stop conditions.
  2. Run defensive analysis in a controlled environment and preserve reproducible evidence.
  3. Validate impact without accessing unrelated data or expanding beyond the authorized scope.
  4. Prioritize and implement remediation, then repeat the test to verify the root cause is resolved.
  5. Coordinate disclosure with affected maintainers when the finding is not limited to AI Understanding.

Public accountability

The program is led by Alex Gonzalez, Founder and Research Program Lead. Security reports can be submitted through our vulnerability-disclosure process or by emailing [email protected]. We will publish additional methods and defensible aggregate findings as the program produces validated work; this page does not claim CVEs, bug-bounty awards, penetration-testing credentials, or third-party authorization that we do not have.

Program launched: September 1, 2026. Baseline last verified: September 1, 2026.

Help keep AI education free and open for everyone.

Donate