AltaySec Laboratory
A controlled simulation environment where attack and defence become security data. A red AI generates Turkish attack scenarios, a blue AI tries to defend, and a separate referee scores and labels the outcome. Records that pass quality review are versioned and used in Gözcü and in our security testing.
- Method
- Controlled red and blue simulation
- Scoring
- A separate referee layer
- Output
- Versioned, quality-reviewed records
- Language
- Turkish first
Three roles in every simulation
The laboratory is also known as the AltaySec Arena. Each run is a contest between two models, observed by a third that takes no side.
Red: the attacker
Generates new Turkish attack variants, such as impersonation, morphological evasion and code-switching, to find where the defence breaks.
Blue: the defender
Refuses, detects the trap or falls for it. Each outcome shows where a defence layer fails.
The referee
Takes no side and suggests no strategy. It scores the result and writes it as a labelled, standard-mapped record.
How the data engine works
A repeatable four-step workflow that produces labelled, quality-reviewed and versioned Turkish security data.
-
Generate
The attacker AI produces new attack variants using current Turkish techniques.
-
Defend
The defender AI tries to block them. Failure points are measured by the model's actual behaviour.
-
Score
The referee scores the outcome and labels each record with OWASP, MITRE ATLAS, NIST and KVKK metadata.
-
Distil
Records that pass the quality check are added to Gözcü after team approval.
Principles of the laboratory
The data is only useful if the runs can be repeated, checked and traced.
Repeatable and controlled
Scenarios, models, languages and win conditions are recorded, so that results can be compared and dataset versions reviewed over time.
Objective and auditable
The referee does not create strategies for either side; it only scores the outcome. Every record is mapped to standards and can be traced.
Turkish first
Attacks use local techniques such as Turkish identity spoofing, morphological evasion and code-switching, which English-language corpora rarely cover.
From laboratory to product
Gözcü compiles the laboratory records and makes them available to our services and product development.
- Laboratory
- Adversarial records from controlled red and blue simulations, labelled and scored by a separate referee.
- Gözcü
- A versioned threat feed built from the records that pass review.
- LLM penetration testing
- Current Turkish attack vectors for our penetration tests.
- Guardian
- A test and rule source for prompt injection protection during development.
What we maintain is a pipeline rather than a single static dataset: scenario generation, referee labelling, quality review, standards mapping and versioned publication. It keeps Guardian and our security testing grounded in the same Turkish threat knowledge.
Put laboratory data to work for your organisation
Explore the products that draw on laboratory data, or discuss a custom red team data programme for your organisation.