// Company

Eleven years measuring operators. Now the agents.

XORCISE.AI is not a first attempt at this. It is built and operated by Fifth Domain Pty Ltd, an Australian company that has been building cyber simulations and analysing how people perform inside them since 2015, and spent the last couple of years running evaluations for the teams building cyber AI.

The tool on this site is that work, opened up. It exists so anyone can evaluate cyber AI for themselves, rather than take anyone's word for a number, including ours.

// Why it is free

The engine is not the business. It is how the business gets better.

XORCISE.AI is a cyber AI development technology company. The engine is open so more people can test cyber AI than could otherwise afford to, and some of them, having read the evidence, will buy what we build alongside it. The tool earns the relationship; the products earn the revenue.

So here is the line as it stands today: hosting a mission, connecting your agent, taking the trace, and grading it with your own models is free, with no paid tier, no feature held back for one, and no account. The commercial work (custom missions, and grading agents of ours) is built beside that, not carved out of it.

We are not going to promise that forever, because a promise is not a mechanism. Fifth Domain owns the project, and its Contributor License Agreement carries the right to relicense the work as a whole, so a future board could relicense what we write next; every release we have already made stays Apache-2.0 and no later decision can reach back and take it. What we will say is that a licence change would be announced before it shipped, not discovered in a release note, and that the right to fork what came before is not ours to withdraw.

  • The engine stays Apache-2.0The engine, the public mission library, the playbooks skill and the docs. Host a mission, connect an agent, take the trace, grade it with your own models. Unlimited local runs, no account, nothing gated.
  • Runs on your machineMissions run in your containers. Traces, results and reports stay on your machine and we get no telemetry; the one outbound call is to the judge model you configure. Publishing a result is a deliberate act.
  • Accountability stays humanThe tool informs a decision about fielding an agent. It does not make it. That is the doctrine.

// What we sell

The missions are the hard part. That is the product.

Anyone can score a transcript. The expensive thing is the environment underneath it: real hosts, real services, a real objective, with the rubric and the terrain authored before an agent ever sees it. Ours come out of a synthetic simulation capability that builds them at volume, for a fraction of what authoring one by hand costs.

The public library is that capability given away. The commercial expression is missions built to a customer's own environment and threat model, plus grading agents of ours. If the free library is what convinces you the missions are worth trusting, that is the intended outcome.

You are not locked into our missions either way. Authoring a mission from a local bundle already works, and importable mission packs, so a set can be shared as one artefact, are on the roadmap. How missions are built →

// The conflict

We author the missions and publish the scores. Do not take our word for it.

Our own use cases page says a system that tunes an agent cannot grade it, and tells a buyer to ask who wrote the criteria. Turned around, we are standing in the same place: we write the missions and the rubrics, we ship the grader, we publish the leaderboard, and we sell missions.

The answer is not our good faith. It is that there is nothing held back to have faith in. The rubric and its weights are on your machine, readable before the first run. The raw trace is written verbatim and sealed. The judge prompt is preserved on the result, with every score and the reason for it. Swap our judge for one of yours and regrade the same evidence. And our own published results carry their conditions, caveats and failures. The numbers we publish are the numbers we got.

The long version, with the five questions to ask us →

// The entity

For the record.

  • Operating companyFifth Domain Pty Ltd, ACN 606 251 585. Australian, trading since 2015. XORCISE.AI is its business name.
  • CertificationsISO 9001 and ISO/IEC 27001, held by Fifth Domain Pty Ltd. Both cover how the company is run. Neither is an audit of the XORCISE engine or its isolation boundary.
  • Not heldNo SOC 2, and none in progress. No third-party penetration test of the engine is published. XORCISE is a local process you run; there is no hosted service holding your data to certify.
  • SupportXORCISE is public beta and carries no SLA, no support tier and nothing to purchase. Issues are answered on a best-effort basis. If you need something contractual, the address below is where that conversation starts.

The policies that govern all of it are published in full: privacy, AI trust & safety, and trademark. What the engine does and does not protect you from is on the security page.

// Contact

Who to talk to.

Four addresses, so a message reaches whoever is on that job rather than one person's inbox.

Prove it on your own agent.

pip install xorcise

Apache-2.0 · Python 3.12+ · runs locally · no phone-home.