4 free to run · no account needed

Tools we build and use ourselves

Start with the four below — templates, the GRC starter kit, the audit trial and the scenario bank all run right now, free, without an account. Under those sit the AI-security and supply-chain scanners and the security-architect studios — interactive canvases with an AI copilot for threat modeling, architecture design, design review, org design and a unified risk register. Those come with any subscription, and the source stays private.

Free cyber-artefact templatesfree · no signup

25 editable starting points — artefacts, policies, processes and audit packs. Generated in your browser.

GRC Starter Kit — full bank edition80 documents

Audit-ready policies, procedures, standards and internal-audit templates written for one fully worked fictional global bank. Download by document or as one ZIP.

Audit Trial — find the gapsNew15 documents · scored

A fictional client submits real-looking policies, firewall rule sets and vendor assessments with planted gaps. Flag every issue, get scored, and see the answer key.

Scenario Bank — pick your answer, beat the pollNew100 scenarios

Realistic interview scenarios across cyber and AI engineering. Pick a response, see how it compares to a simulated peer poll, and read the reasoning behind the strongest move.

NPM Scanner

·Automated Supply Chain Risk Scannerlive

Daily scanning of npm packages — download the same tool for your own repos.

PlayCISO scans the top npm packages daily against 50 risk policies (install scripts, ownership changes, typosquats, obfuscation). Paid users run the same CLI via npx @playciso-scanner/npm-scanner --token <token> against their own packages, repos, or file lists.

Open

Prompt Scan

·Prompt Injection Scannerbeta

Static detection for prompt-injection and jailbreaks.

Matches text against known injection patterns and maps each hit to its OWASP LLM risk — fully local, nothing sent to a model.

Open

MCP Guard

·MCP Config Auditorbeta

A static audit of your MCP server config.

Paste your MCP config; it flags plaintext secrets, unpinned installs, shell pipes, and over-broad filesystem roots.

Open

Model Audit

·Model Behavioural Auditbeta

Red-team a model endpoint you control.

Runs an adversarial suite — jailbreak, injection, secret-leak — against your own model endpoint and hands you the replies.

Open

Extension Scanner

·Chrome Extension Risk Scannerbeta

Score a Chrome extension by what it can actually do.

Give it an extension ID; it pulls the live Web Store manifest and scores the permission combinations nobody reads.

Open

AI BOM

·AI Bill of Materialsbeta

A bill of materials for your AI stack.

Turns a package.json or models/datasets manifest into a CycloneDX-style inventory with a license-risk read per component.

Open

Resume Review

·AI Resume Critiquebeta

A resume critique tuned to security roles and your market.

Grades your resume for a specific role and market, rewrites the flat bullets, and finds the ATS keywords you’re missing.

Open

AI SVS

·AI Security Verification Standardalpha

A verification standard for AI systems — in development.

An ASVS-style verification standard for AI systems, still being written — the one thing here you can't run yet.

Open

AI Cert Prep

·AI Cert Practice Drillsbeta

Gamified practice for CSA, IAPP, ISACA, and ISO/IEC 42001.

600+ questions across four AI security/governance certifications — CSA AI Security, IAPP AIGP, ISACA AAIA, and ISO/IEC 42001 Lead Auditor. XP-gated levels keep the grind honest.

Open

The Cut

·Competitive Budget Siegelive

Survive a 10% budget cut, get a CISO Score, challenge a colleague.

One shared board per week, a server-graded CISO Score out of 1000, a live leaderboard, and challenge links that make a colleague play your exact scenario. Free, no account.

Open

M&A Cyber Assessment

·M&A Cyber Due Diligencebeta

Six-phase acquisition scenario with ransomware incident, dual roles, and NPC advisors.

6 phases · 2 roles · ~3h · cyber incident · 7 NPC advisors

Open

Cinematic Video

·Cinematic Introduction Videobeta

Upload your resume, get a 60-second cinematic video with AI voiceover.

Extracts your career story, writes a narrative script, records motion graphics with professional AI voiceover, and delivers a shareable MP4. First video free.

Open

LiteLLM Checker

·LiteLLM / TeamPCP Exposure Checkernew

Check a host for IOCs from the March 2026 LiteLLM supply chain attack.

A free, local, single-file Python script — no network calls, no telemetry. Checks installed version, lockfiles, dropped files, systemd persistence, and Kubernetes lateral-movement pods against the known IOCs.

Open

Security-architect studios

new

Three independent, interactive canvases. You stay in control — the AI proposes, you dispose: edit, accept, dispute or dismiss everything, then export. Nothing is versioned; your work autosaves locally and exports whenever you want.

Share

Threat Model Studio

·STRIDE Threat Modeling Canvasstudio

Draw the system, let an AI copilot map the threats.

Sketch a data-flow diagram — or describe your system and have it drawn for you — then get STRIDE threats suggested per element, with likelihood, impact and control mappings you accept, edit or dismiss. Export PNG, SVG, JSON, CSV and a PDF report.

Open the studio

Architecture Studio

·Security Architecture Canvasstudio

Blueprint a reference architecture with live compliance coverage.

A component palette plus a blueprint wizard: pick a pattern, cloud, compliance regime and data classification, and the AI seeds a labelled architecture you keep editing. Live NIST/CIS/ISO coverage, generated ADRs, and export to PNG, SVG, JSON, CSV, Terraform stubs and a PDF brief.

Open the studio

Design Review Workbench

·RFC / Design Security Reviewstudio

Paste an RFC, triage the findings, sign it off.

Drop in a design doc and get a severity-ranked findings board you can accept, dispute (and challenge the AI back), defer or assign — beside an annotation whiteboard and an OWASP ASVS checklist. Export PNG, SVG, JSON, CSV and a PDF sign-off.

Open the studio

Attack Path Simulator

·Animated Kill-Chain Simulatorstudio

Watch a breach move through your enterprise, live.

Pick an industry + threat actor; it generates a multi-tier enterprise (DMZ, identity, internal, Kubernetes, cloud, OT, data) and plays the intrusion like a movie — hop by hop to the crown jewels and back out on exfil, each step mapped to ATT&CK. 33 scenarios, actor→industry targeting.

Open the studio

Org Designer

·Greenfield Security-Org Builderstudio

Design the team before you hire it.

Five facts about the company in — a defensible org out: functions, headcount model, budget split, KPIs per role, a first-year hiring roadmap, and job descriptions you can download and edit.

Open the studio

Cyber PMO

·10 Security Project Packsstudio

The ten projects every program runs — fully packed.

Business case, phased plan with exit criteria, governance, baselined KPIs, status-report skeleton and a pre-seeded RAID log — for MFA, EDR, PAM, SIEM/SOC, vuln management, IR, Zero Trust, DLP, vendor risk and awareness.

Open the studio

Risk Register

·Unified Cross-Tool Risk Registerstudio

Every risk from all three studios, board-ready.

Aggregates threats, architecture control gaps and design-review findings into one register with owners, status and residual risk — then exports a board report plus SARIF, Open Threat Model, Threat Dragon, OSCAL and CSV. Set an org profile once and the AI copilot tailors everything to it.

Open the studio
All tools require a Pro plan.

Free users see landing pages and can preview docs. Run buttons and the architect studios require a paid subscription. See pricing.

Security Tools & Architect Studios · PlayCISO