Strategic Innovations

We attack the AI that reads text from outside your company, then fix what got through.

For teams whose AI reads email, documents, tickets or forms. 78 written attacks on one integration, the fixes, a retest and the evidence pack: $7,500.

Start this job How the test runs

You get the scope in writing first. Nothing is charged until you agree, and no attack runs before the person you name approves it in writing.

What $7,500 covers

  • The run78 written attacks in three sets, two of them written by authors who never saw the code.
  • The fixesDecisions a later instruction cannot reach, and nothing sent out that you did not allow.
  • A retestWithin 30 days, against the same 78.
  • The evidence packA letter stating what was tested and what held, the findings mapped to OWASP LLM01:2025, written answers for the AI sections of vendor questionnaires, and a signed receipt for every run.
  • The dateThe report within ten working days of access.

How the test runs

  1. You name the integration. The place where your model reads a document, an email, a ticket or a form that someone outside your company wrote, and the person who can approve a test of it.
  2. You get the scope in writing. What we will attack, the price of $7,500 and a date. Nothing is charged until you agree, and no attack runs before that person approves it in writing.
  3. We run three sets of attacks. 78 in all, against a staging address if you have one. The report says which got through, and arrives within ten working days of access.
  4. We fix, retest and hand over the evidence. The fixes, a retest within 30 days, and the pack your customers' security reviews ask for, with a signed receipt for every run.

What the same three sets found on our own product

Run on the service that drafts our appeal packets, 17 September 2026.

An attempt counts as through when its goal is in the draft and the draft passes every check, so it would have reached a person marked ready.

SetAttacksFirst runAfter the fixes it prompted
Fitted set, written with the code in view12, each run twice8 of 24 through, with no defence0 of 24
First blind set, by an author who never saw the code30, each run twice8 of 60 through the defences of that morning0 of 60
Second blind set, by a second author36, run once1 of 36 through0 of 36; 7 produced the wording and each was held for a person

What a fixed set cannot tell you

Each new set found something the one before it had missed. A set that has taught the defence is a baseline, and the next unseen set is the next real number. Published work points the same way: in October 2025 researchers bypassed twelve recent defences with attacks that adapt to the defence, most of them more than nine times in ten, where the defences' own authors had reported close to none (The Attacker Moves Second).

So the report says exactly what was tested, and the fixes lead with structure: decisions a later instruction cannot reach, and nothing sent out that you did not allow. The 78 attacks are the baseline the retest runs against.

Every run ends in a signed record your customer can check

The evidence pack carries a signed receipt for every run. Each step's fingerprint covers the step before it, and the newest one is signed with a key whose public half we publish. Anyone holding the record can check it on their own computer. Change one word anywhere and the check fails, and says which step changed.

The record beside this text is one we publish from the appeals product. Press Change one character, then check, to see a failure, or paste any export we issue into the verifier.

For your developers, the same check in one command:

curl -s 'https://appeals.strategic-innovations.ai/example/ledger.json' \
  | curl -s -X POST -H 'content-type: application/json' \
      --data-binary @- https://appeals.strategic-innovations.ai/v1/ledger/verify

Change one character of the export and the same command answers "ok": false with the reason. The public key is at the public key endpoint.

Check a real record from this page

Our published example from the appeals product, for a fictional practice: 2 appeal packets, 1 reviewer correction, 6 signed steps.

  1. Record opened by Strategic Innovations

    224cec74
  2. Packet drafted by our drafting service

    3390ff46
  3. Corrected by Dr Example (fictional reviewer)

    9d5238e1

    Quote the policy criterion word for word and give the date of every note you rely on.

  4. Packet drafted by our drafting service

    3f901b0c

    Drafted under the correction above

  5. Approved by Dr Example (fictional reviewer)

    f0c8b720

    Quoted and dated. Submit.

  6. Published as the example by Strategic Innovations

    a47ef9cb

Signed head a47ef9cbb97be274, key 3bdb547d2019

  • Chain
  • Head
  • Signature
  • Count

Not checked yet. Both buttons run our public verifier against our published key.

Four jobs we take on, and what each one costs

Prices dated 26 September 2026. Open any row for the full scope and how it is proven.

An attack test on the AI that reads text from outside your company

For teams whose AI reads email, documents, tickets or forms

We send 78 written attacks at the place where your model reads text someone else wrote, fix what gets through, retest, and give you the evidence your customers' security reviews ask for.

What you get, and how it is proven

What you get. We take the place in your product where a model reads a document, an email, a ticket or a form that someone outside your company wrote, and attack it the way an attacker would: 78 written attacks across three sets, two of them written blind. You get the fixes, a retest within 30 days, and an evidence pack: a letter stating what was tested and what held, the findings mapped to OWASP LLM01:2025, written answers for the AI sections of your customers' vendor questionnaires, such as FS-ISAC's Generative AI Vendor Risk Assessment, and a signed receipt for every run. The report arrives within ten working days of access. A fixed set of attacks understates what an adaptive attacker can do, so the fixes lead with structure: decisions a later instruction cannot reach, and nothing sent out that you did not allow.

How it is proven. Measured on our own drafting path on 17 September 2026. The fitted set (12 attacks, each run twice) put 8 of 24 attempts through with no defence and 0 of 24 with it. The first blind set (30, each run twice) put 8 of 60 through the defences of that morning, and 0 of 60 after the fixes it prompted. The second (36, run once) put 1 of 36 through, and 0 of 36 after its fix, where 7 attacks produced the wording and every one was held for a person. The blind sets were written by separate agents that were never shown the code. A set that has taught the defence is a baseline: the next unseen set is the next real number.

Price. $7,500 for one integration: the run, the fixes, a retest within 30 days and the evidence pack. The defences can then run through our text-gate API on your own key, from $29 a month.

$7,500

for one integration, the fixes and a retest included

We run it for you today.

Start this job

An appeal packet your clinician signs

For billing offices, practices and Medicare DME suppliers

Send one denial with identifiers removed and dates reduced to the year. You get the policy matched to the chart, the evidence in order, and a letter for your clinician to sign.

What you get, and how it is proven

What you get. One de-identified denial becomes a packet: the denial mapped to the payer's own policy, the evidence listed in order, the letter drafted, and what is missing named with its owner. De-identified means the names, numbers and addresses are out and every date is reduced to its year; the packet marks where each date goes, and your office fills them in before your clinician signs. Your clinician approves, corrects or rejects it in a console. For DME suppliers: from 28 October 2026 Medicare requires prior authorization nationwide for six more codes (L0456, L0457, L0486, L1833, E0194 and K0005), and we check a request against its coverage policy before you submit it, the first five free.

How it is proven. Prepared automatically, checked by 21 computed checks, then read by a person before you see it. Every decision is one event in a sealed record you can verify yourself.

Price. $39 a packet, first one free. $499 for a written pilot design. $2,500 a month for a queue of 400.

$39

a packet. Your first one is free.

Live. Buy it online.

Get your first packet free

Per-outcome invoices your customer can recount

For companies that bill per resolution or per completed task

Every resolution or task you bill for becomes one signed entry: what was done, when, and who decided. Your customer recounts the invoice from the record instead of disputing it.

What you get, and how it is proven

What you get. Every completed unit of work becomes one event in a chain: what was done, who decided, when, on what evidence, and what correction they left. The month's invoice is computed from that count. Your customer checks the record and the count on our free verifier, or on their own machine, without asking you. Per-resolution bills are disputed today because the buyer cannot see what was counted; this gives them the count.

How it is proven. It runs in our own appeals product today. Every request there is a chain anyone can check on the public verifier, and each month's invoice is computed from the sealed rows. The chain, the signed head, the signature and the count all have to pass, or the answer names the one that failed.

Price. $249 a month for one queue with 25,000 recorded items, then one cent an item. Checking the record is free, on our verifier or anywhere else.

$249

a month for one queue, 25,000 items included

Running in our product. Open as a pilot.

Start this job

A site AI assistants can read, measured before and after

For companies that want AI assistants to read and recommend them

Start with the free check. If AI crawlers get an empty page, blocked bots or files that are not really there, we fix it and check again, with both results in writing.

What you get, and how it is proven

What you get. We fix what AI crawlers cannot read on your site and measure again: content that only appears after JavaScript runs, crawlers blocked by mistake, a site that answers made-up addresses with a page, and a missing title, description or sitemap. Sites on Cloudflare can fix some of this in its dashboard for free; the rest, and sites hosted elsewhere, are what we do.

How it is proven. Measured with the same check on our own properties first: four endpoints answered 200 with a page that carried none of the content they claimed. Fewer than half of all HTML page requests now come from a human (Cloudflare, 6 August 2026), and GPTBot, ClaudeBot and PerplexityBot do not run JavaScript (Vercel and MERJ, December 2024).

Price. $1,900 for one site: the fixes, and the check run before and after, in writing.

$1,900

to fix one site, with both checks in writing

We run it for you today.

Check your site free

Work that is none of these four gets a written scope and a price before it starts. Get a fixed price.

The services behind this work are open as APIs

Create an account, issue a key on your account page, and send it as a bearer token. The first 100 calls a day cost nothing, and every answer says how many you have left. 11 of the 17 answer a key you issue yourself today; the other 6 need a credential we hold, and we open them when you ask.

Read the catalogue Create an account and get a key

PlanCalls a dayPrice
Free100$0
Scale5,000$29 a month
Volume50,000$99 a month

What we have measured, and where each number comes from

FigureWhat it countsSource and date
LLM01:2025 Prompt injection is the first risk on the OWASP list for applications built on language models OWASP, read 17 September 2026
12 of 12 recent defences were bypassed by attacks that adapt to the defence, most of them more than nine times in ten Nasr and others, The Attacker Moves Second, October 2025
8 of 60 attempts from our first blind set got through the defences we had that morning; the same set read 0 of 60 after the fixes it prompted our own run, 17 September 2026
0 of 36 attempts through on our second blind set after its fix, where 7 produced the wording and every one was held our own run, 17 September 2026
8 events verified as one chain on the public endpoint after a request was published our own record, 17 September 2026
Under half of all HTML page requests now come from a human Cloudflare, 6 August 2026

Questions before a first job

What does it cost?

An attack test is $7,500 for one integration, with the fixes, a retest within 30 days and the evidence pack. Appeal packets are $39 each, and your first one is free. Invoices your customer can recount are $249 a month for one queue. Making a site readable to AI assistants is $1,900, and the check that tells you whether you need it is free. API access is free for 100 calls a day, then $29 or $99 a month. Every job gets its scope and price in writing before any work starts.

Is 78 attacks enough?

No fixed number is. The 78 are a baseline: three sets, two of them written by authors who never saw our code, and each new set found something the one before it had missed. Attacks that adapt to a defence get through defences that hold against a fixed set, so the fixes we make lead with structure, and the report says exactly what was tested and what was not.

Do you have customers yet?

No customer results are published yet; we are selling the first tests now. That is why every job starts with a fixed price in writing, and why you do not have to take our word for the work: the record can be checked without us.

Are you SOC 2 or HITRUST certified?

No. We hold no SOC 2, HITRUST or ISO 27001 report today, and we say so rather than imply one. An attack test runs against the address you give us, a staging address if you have one. Appeal packets are prepared only from denials with the patient identifiers removed and every date reduced to its year.

What happens if the work is wrong?

On an attack test, the retest within 30 days is part of the price, and the report names anything that still gets through. On appeal packets, a person reads each one before you see it, and your clinician approves, corrects or rejects it. A correction becomes a rule the next packet follows, and the record shows both.

How does my customer check the record?

With the export and our public key, on any computer, without asking you or us. Press Check the record on this page to watch it run, or give your developers the one command beside it.

How we handle data is written out on the security page.

Ask a question, or get a price for other work

Tell us what arrives, who approves it today, and what you would need to show afterwards.

The prices reach your inbox within a minute. A person replies to anything they do not answer. Nothing is charged until you agree.

Or start on your own today

Start an attack test. A few questions, then the scope in writing.

Get your first appeal packet free. Send one denial with the patient identifiers removed and every date reduced to its year.

Create an account and get a key. The first 100 calls a day cost nothing.

Or write to sales@strategic-innovations.ai. Support: support@strategic-innovations.ai.