Attacker Friction Rating: A Better Question for Security Metrics
Closed findings don't mean a harder environment. AFR measures what an adversary must absorb to reach what matters.
AI-powered internal tools, secure SaaS, agent workflows
Identity, data pipelines, telemetry, and AI systems
Cloud-native delivery with guardrails and self-service
“Move fast and break things” doesn't work when the things are people's data, trust, and safety.
Closed findings don't mean a harder environment. AFR measures what an adversary must absorb to reach what matters.
Anthropic's new default model scores 63.2% on SWE-bench Pro, beats Opus 4.8 on GDPval, and costs $2/$10 through August. But a new tokenizer inflates real costs up to 35%, and xhigh effort can erase the savings entirely. Here's the honest math.
Three weeks after emergency export controls pulled it offline, Fable 5 returned today with a hardened classifier and a deal: up to 50% of your weekly usage limits, included, through July 7. Then it goes metered. Here's what happened, what to do right now, and what to throw at it this week.
Anthropic just shipped the first Mythos-class model the public can touch. Three days in, people are beating Pokémon with vision alone, building game engines in a week, and compressing two-month migrations into a day. Here's what's real, what it costs, and where the guardrails bite.
Opus 4.7 jumped 11 points on SWE-Bench Pro, added an xhigh effort level, tripled its vision resolution, and ships with automatic cybersecurity safeguards. Here are the 5 problems where I'm already pointing it.
Project Glasswing pairs an unreleased AI model with 12 industry partners to find and fix critical vulnerabilities before attackers can exploit them. Here's what it means for defenders.
If you need help shipping AI that's secure, fast, and actually works — let's talk.
Get in touch