AI Risk Assessment Platform. Evidence-backed. Offensive-validated. Signed.
Not a questionnaire. Not a framework checklist. What actually breaks when we attack.
Every AI risk assessment tool on the market asks "do you have X control?" and scores
you on your answer. None of them run an attack to find out.
RED SCORE is different. It runs NIGHTFALL against your AI platform, collects
Ed25519-signed findings from live tool execution, and produces a score backed by
what actually broke — not what you claim to have.
EU AI Act Article 15 enforcement begins August 2026. "We completed a questionnaire"
is not a compliance artefact. A signed, reproducible, evidence-backed RSC-{hex12}
report is.
finding_score = base_CVSS_4.0 × impact_multiplier × confidence.layer_score = 10 × (1 − normalised_finding_weight).RED_SCORE = Σ(layer_weight × layer_score).
Every finding is scored as: CVSS 4.0 × impact_multiplier × confidence.
Each layer aggregates findings and normalises against the maximum possible damage.
Final RED SCORE is the weighted sum — 0 = existential risk, 10 = exceptional posture.
Every RED SCORE report maps findings to EU AI Act Article 15, ISO 42001, and SOC 2 AI criteria. Status per control: COMPLIANT / PARTIAL / GAP / CRITICAL. Gaps exported as actionable text for legal and compliance teams.
Every finding in a RED SCORE report includes the specific AI Shield module that mitigates it. Not a generic recommendation — mapped to the exact finding type and WMD class.
WARLORD SELECTOR draws from the full 122-tool NIGHTFALL registry. Each tool is tagged by attack surface, kill chain phase, risk layer, minimum gate level, and WMD classes.