Investigations Platform

Stop shipping blind spots.

A private Council of AI Investigators reads your product like an incident report waiting to happen. In ninety seconds you get ranked villains, VRSD scoring, and a ship-or-redesign verdict.

Sample · Roastfluencer.ai · v01
Verdict · ship with fixes
5 fixes before you ship.
Villains at a glance
01The Bullying Corridor12Active
02The Amplification Chain11Active
03The Peer-Status Roast Game11Active
05The Politician's Suit10Fixed
Why now

Two years ago this was optional. Now it's on someone's checklist.

The regulatory floor moved. Insurance moved. Enterprise procurement moved. Villain's Hat lands the evidence.

EU AI Act 2026

Article 9 says you have to have done this.

Risk management (Art. 9) and record-keeping (Art. 15) enter full enforcement in August 2026 for high-risk AI systems. Investigations give you documented pre-ship analysis, versioned per release. It's what the checklist asks for.

AI liability insurance

Underwriters are asking for pre-ship audits.

Standalone AI liability policies emerged in 2025. Every one asks the same question: what did you do to identify misuse and harm vectors before shipping? A Villain's Hat report is the answer, dated and attributable.

Enterprise procurement

Buyers are asking. You want to be ready.

Enterprise buyers now include AI safety evidence in vendor questionnaires. If your competitor can show a pre-ship audit and you can't, you lose the deal. Investigations Platform makes that evidence three clicks away.

Three passes over your product. One report you can ship on.

Every investigation runs the same architecture. Screened, investigated, answered.

Pass 1 · Screening

Nothing gets in without being read.

The Sentinel runs two independent passes on every upload. Pattern scan first, semantic verification second. Prompt injections, policy bypasses, and adversarial payloads stop here. They never reach the Council.

Pass 2 · Investigation

Ten adversarial angles. In parallel.

The Council of ten Investigators covers weaponization, minor safety, compliance, viral amplification, deception, technical exploits, brand risk, self-harm vectors, and more. Each returns a structured finding. The specific roster stays proprietary and evolves quarterly.

Pass 3 · Response

PM, Design, and QA answer.

For every villain the Council names, the Response Council answers with a business case (PM), a design intervention (Designer), and a detection plan (QA). Root causes, second-move chains, effort estimates.

Sample report

This is what your investigation lands as.

A printable A4 report. Verdict at the top. Villain rankings, VRSD scores, root causes, second-move chains, and Response Council recommendations flow through. Read it in fifteen minutes. Forward it to your team, your lawyer, or your insurer in one click.

Villain's Hat · Investigation Report INV-2026-0847
Complete · v01 · 2026-07-06

roastfluencer.ai

Verdict · ship with fixes
5 fixes before you ship.
Investigators · 10 of 10 reported
3 Blind Spot 2 Hidden Threat Sentinel · GREEN
Methodology

VRSD · four dimensions, one score.

Every villain the Council names gets scored across four dimensions, rated zero to three by the flagging Investigator, then reconciled by the Council's Verdict.

V
Vector
How does this attack enter the product? Photo upload, prompt input, sharing mechanism, API call.
R
Reachability
How likely is a real user to trigger this? Base rate matters. Rare edge cases score low.
S
Severity
How bad is the harm when it lands? Reputational damage, legal exposure, harm to individuals.
D
Detectability
How hard is this to catch in production? Server-invisible attacks score high.
Max score is 12 / 12. That is a ship-blocker. Anything above 8 lands this sprint. Anything above 10 stops the launch.
Pricing

Simple pricing. Ship-blocker cheap.

One investigation costs less than the meeting you'd have to run after a viral incident.

Per
€49 per investigation

One-shot, no subscription. Best for agencies, one-off audits, "just this project" moments.

  • Full Council of 10 Investigators
  • Response Council · PM, Design, QA
  • VRSD-scored ranked villains
  • Ship-or-Redesign verdict
  • Full PDF export (A4)
  • 3 investigations per hour
Start with one
Bespoke
€5,000 starting

Custom Investigators for your industry, built with the founder. 4 to 6 week engagement.

  • Custom Investigators for your vertical
  • Industry-specific regulatory library
  • Quarterly reviews with the founder
  • Priority support
  • Multi-product setups
  • Team access negotiated
Talk to us
Need more? Pro add-on packs
+5 €35 +10 €65 +20 €120
Feature comparison
Every feature, side by side
Feature Per Pro Bespoke
Council of 10 Investigators
Response Council · 3 perspectives
Sentinel · double-pass screening
VRSD scoring + Ship verdict
Full PDF export (A4)
Investigations per month1 · pay per use15 · rolloverUnlimited
Priority queue
Regulatory library updates first
Custom industry-specific Investigators
Quarterly reviews with founder
Multi-product setup
Rate limit3/hour3/hour rollingNegotiated
How we stay honest

Trust isn't a marketing claim. It's a workflow.

Regulatory currency

The regulatory library refreshes every 90 days. New legislation like the EU AI Act 2026 becomes part of the Investigator toolkit within a quarter of passage. Pro users get updates first.

Data security

Google OAuth for authentication. Encryption at rest, TLS in transit. Row-level security means users only ever see their own investigations. Uploaded documents are stored encrypted and never used to train models.

Made by a builder

Villain's Hat is built by Pavitra S. Tandon, who spent years designing consumer AI products before founding this. Every prompt was tested against real products before it went live.

Questions

The stuff people ask before they sign up.

Can I use a Villain's Hat report as EU AI Act Article 9 evidence?

Yes. Article 9 requires you to have "identified, analysed, and mitigated" reasonably foreseeable risks. A dated Villain's Hat investigation report, versioned per release, is documented evidence you did that work. It doesn't replace a lawyer's judgement, but it does give your compliance team something to hand to the auditor. This is the single most-asked question from buyers, so we lead with the answer.

How is this different from asking ChatGPT or Claude directly?

Generic LLMs are trained to be helpful. They won't red-team your product unless you know how to prompt them to. Villain's Hat runs a curated adversarial architecture: ten specialist Investigators with domain-specific prompts, a Sentinel that catches prompt injection attempts on your upload, a Verdict that reconciles conflicting findings, and a Response Council that translates findings into fixes. It's ten focused red teams running in parallel, not one general assistant guessing.

What happens to my uploaded documents?

Documents are encrypted at rest, transmitted over TLS, and stored under row-level security in your account. They are not used to train any model. Per-tier users' documents auto-delete after 12 months. Pro users' documents persist while their subscription is active plus 90 days grace after cancellation. You can export or delete anytime.

How current is your regulatory knowledge?

The regulatory library refreshes every 90 days with new legislation, case law, and enforcement patterns. Between refreshes, urgent additions (like a new EU AI Act guidance note) get pushed within a week to Pro and Bespoke users. Per users get the same library at the next refresh cycle.

Do you support teams?

Not yet on Pro. Bespoke customers get negotiated team access. If you need team seats before we ship them on Pro, talk to us.

What's your refund policy?

If The Sentinel blocks your upload as a false positive and you can't run the investigation, you're not charged. If you completed an investigation but weren't satisfied with the depth of findings, email us within 7 days and we'll issue a credit or refund. We haven't had to do this yet, but the policy exists.

Can I export my report?

Yes. Every completed investigation exports to PDF (A4 print-ready), CSV (structured data), and JSON (full raw findings). Filename convention: YYYYMMDD-VHReport-productname-vNN.pdf so multi-year archives sort chronologically.

Why don't you list your specific Investigators?

Because the moment we publish them, product teams stop building for safety and start building to pass our tests. The Investigators' identity, prompts, and methodology stay proprietary and update quarterly. You see the outcome, not the machinery. That's how the tool stays honest.

Pre-launch

Not ready to sign up yet?

The Investigations Platform ships shortly. Join the waitlist for early access, launch pricing, and the "state of AI product misuse" quarterly report.

Stop shipping blind spots.

One investigation. Ninety seconds. A report your team, your lawyer, and your insurer can all read.