TachyonicTachyonic

Platform Guide

Using the Tachyonic dashboard for scan management, findings review, and team collaboration

Overview

The Tachyonic platform at platform.tachyonic.co provides a dashboard for managing security scans, starting runtimes, reviewing findings, and tracking your AI systems' security posture over time.

Sign Up

Create an account at platform.tachyonic.co/sign-up. Sign up with email/password or Google/GitHub OAuth. An organization and default workspace are created automatically.

Targets

Targets represent the AI endpoints you want to scan. Create a target with:

  • Name: descriptive label.
  • Endpoint: the URL of the LLM API, for example https://api.openai.com/v1/chat/completions.
  • Provider: the LLM provider, which determines request and response format.

Domain Verification

For dashboard-initiated scans, external targets must be verified. After creating a target:

  1. Go to target settings and click Verify
  2. Choose DNS or HTTP verification:
    • DNS: Add a TXT record at _tachyonic-verify.yourdomain.com
    • HTTP: Serve a JSON file at https://yourdomain.com/.well-known/tachyonic-verify.json
  3. Click Check to confirm

Known providers (Anthropic, OpenAI, Google, etc.) are auto-verified.

CLI and API key scans bypass domain verification.

Scans

Submit a Scan

From the dashboard:

  1. Select a target
  2. Choose attack categories
  3. Set max attacks (optional)
  4. Click Start Scan

Scans run on Tachyonic's infrastructure. Progress updates stream in real-time.

Scan Status

StatusDescription
QueuedWaiting for runner capacity
RunningAttacks in progress
CompletedFinished with results
FailedRunner error (check logs)
CancelledStopped by user

Cancel a Scan

Click Cancel on a running scan to terminate it immediately.

Findings

Each finding includes:

  • Attack name: which attack triggered the finding.
  • Category: OWASP LLM Top 10 mapping.
  • Severity: critical, high, medium, low, info.
  • Verdict: confirmed, probable, suspicious, dismissed.
  • Confidence: 0.0 to 1.0.
  • Evidence: what the model response contained.
  • Payload: the adversarial input sent.
  • Response: the model's actual response.
  • Reproduction steps: how to reproduce.

Runtimes

For scans that need a bounded runtime, budget caps, approval gates, or egress allowlists, start a runtime instead of a plain scan. This is the path for MCP servers, agent stacks, and production endpoints with sensitive data.

  • Runtime pool: Free uses the default pool. Paid plans can select aws-us-east-1 or aws-eu-west-1.
  • Budget envelope: wall-clock minutes, model tokens, and spend caps.
  • Approval gates: tools matching policy.approvals.require_before pause and create a pending approval.
  • Egress allowlist: the runtime allows only platform endpoints, the target host, and hosts listed in policy.

Starting a runtime

From the dashboard:

  1. Go to Runtimes > New Runtime.
  2. Choose the target endpoint, region, model, and budget.
  3. Click Start Runtime to start a live runtime or Create Plan for a dry run that validates the runtime bundle without spending budget.

The runtime appears on /runtimes with live status streamed via SSE. Click through for the runtime detail page: state-transition timeline, events, artifacts, findings, and the approval inbox.

The same surface is available from the CLI under tachyonic runtime .... See Runtimes for the full command reference and the manifest schema.

API Keys

Create API keys at Settings > API Keys for CLI and CI/CD integration. Each key is scoped to your workspace with configurable permissions.

Billing

Scan limits

PlanScans/monthRate limit
Free510/min
Pro5060/min
TeamUnlimited120/min
EnterpriseUnlimited300/min

Runtime limits

PlanRuntime startsRuntime poolMinutesSpendEvidence retention
Free3/monthDefault15$172 hours
Pro50/monthDefault, US, EU60$1030 days
TeamUnlimitedDefault, US, EU120$5090 days
EnterpriseUnlimitedDefault, US, EU240$250365 days

Upgrade at Settings > Billing.

Signed runtime evidence is downloadable and shareable only during the plan retention window. Artifact downloads and reviewer links return HTTP 410 after that window closes.

On this page