Skip to main content

Trust & Security

Built for careful security conversations before trust expands.

Mythos AI Security works around sensitive AI, security, data, and deployment questions. This page explains how Mythos approaches authorization, scope, sensitive information, responsible disclosure, and product claim boundaries.

Authorized/Scoped/Evidence-first

Trust posture

Trust starts with boundaries.

Mythos assessments should be authorized, scoped, non-destructive, and controlled by the customer. The goal is to help organizations understand AI deployment risk through evidence, not to create uncontrolled testing, unapproved access, or unsupported claims.

Authorized

Testing should only happen with customer approval and a defined scope.

Scoped

Systems, data, roles, tools, environments, and limits should be clear before review begins.

Evidence-first

Findings should connect to proof, remediation guidance, and retest requirements.

Sensitive conversations

How Mythos handles sensitive conversations.

Early conversations should focus on the system type, deployment stage, risk concerns, and assessment goals. Sensitive technical details should be shared only through an approved, scoped process.

Appropriate for public forms

  • General system type
  • Deployment stage
  • Primary concern
  • Company contact information
  • High-level description of the AI workflow
  • Preferred next step

Should wait for a scoped process

  • Production architecture details
  • Sensitive security findings
  • Proprietary source code
  • Customer data
  • Regulated records
  • Credentials, secrets, keys, or tokens
  • Sensitive incident details

Authorized testing

Authorized and scoped testing.

Mythos testing should be conducted only under explicit authorization. Scope should define what systems are included, what systems are excluded, what environments may be tested, what data may be used, what actions are allowed, and what limits apply.

Systems in scope
Systems out of scope
Test environment
Data boundaries
Approved user roles
Approved tools and actions
Safety limits
Retest expectations
Reporting requirements

Mythos does not authorize independent testing of customer systems, third-party systems, or Mythos systems outside an approved process.

Please note

No secrets in public forms.

Public website forms are not the right place to submit sensitive production material. Please do not submit secrets, credentials, private keys, regulated records, private customer data, proprietary source code, classified information, or sensitive production incident details through public forms.

If sensitive material is needed for an assessment, Mythos should request it only through an approved, scoped, and controlled process.

Data handling

Data handling principles.

Mythos is building its process around minimizing unnecessary data exposure. Assessment conversations and evidence handling should be limited to what is needed for the agreed scope.

01

Minimize what is shared

Only request information needed for the assessment path.

02

Separate public forms from scoped review

Sensitive details should not be submitted through general website forms.

03

Use evidence carefully

Assessment evidence should support findings, remediation, and retest decisions.

04

Avoid unnecessary retention

Information should not be kept longer than needed for the approved business purpose.

05

Keep humans accountable

Mythos supports human-reviewed security, product, compliance, and deployment decisions.

Responsible disclosure

Responsible disclosure.

If you believe you have found a security issue affecting Mythos AI Security’s public website or systems, please report it responsibly. Do not access, modify, delete, exfiltrate, or disrupt data. Do not test third-party systems, customer systems, or non-public Mythos environments without written authorization.

A report should include:

  • A clear description of the issue
  • Steps to reproduce, if safe
  • Affected URL or system
  • Potential impact
  • Your contact information

Report a security issue

info@mythosaisecurity.com

Suggested subject

Security Report — Mythos Website

Submitting a report does not authorize further testing, exploitation, persistence, data access, service disruption, or public disclosure.

Product claim boundaries

Product claim boundaries.

Mythos is careful about how it describes its products, strategic horizon work, and assessment outcomes. Mythos does not claim compliance certification, government authorization, customer assurance, vehicle safety certification, quantum-safe certification, or guaranteed AI safety unless explicitly stated and supported.

Athena

Athena helps map systems, access, data flows, model routes, permissions, findings, remediation guidance, and evidence.

Achilles

Achilles helps test AI behavior, RAG, prompt injection, tool use, approval boundaries, release readiness, and retest behavior.

Minotaur

Internal only

Minotaur is internal-only adversarial validation support and is not presented as a customer-facing product.

Hermes

Strategic horizon

Project Hermes is a strategic horizon direction for AI-driven vehicle, fleet, autonomy, telematics, OTA/model update, and cyber-physical mobility assurance. It is not a vehicle safety certification or crash-prevention guarantee.

Quantum-adjacent AI

Strategic R&D

Quantum-adjacent AI is a strategic R&D scenario. It is not a claim of current quantum-safe certification, quantum hardware validation, or production quantum integration capability.

Contact security

Contact security.

For security reports, sensitive assessment questions, or concerns about how to share technical information, contact Mythos before submitting sensitive details.

General and security inquiries

info@mythosaisecurity.com

Suggested subject lines

  • Security Report — Mythos Website
  • Assessment Scope Question
  • Sensitive Information Handling Question

Start the right conversation

Have a sensitive AI deployment question?

Start with a high-level inquiry. Mythos can help determine the right conversation path before sensitive technical details are shared.