Cybersecurity AI (CAI), the framework for AI Security
CAI)Professional Edition with unlimited alias1 tokens | 📊 View Benchmarks | 🚀 Learn More
🔓 Community Edition Research & Learning · Perfect for Researchers & Students pip install cai-framework
✅ Free for research 🤖 300+ AI models 🌍 Community driven 📚 Open source 🔧 Extensible framework
🚀 Professional Edition Enterprise & Production · €350/month · Unlimited alias1 Tokens
→ Upgrade to PRO
⚡ alias1 model - ∞ unlimited tokens 🚫 Zero refusals - Unrestricted AI 🏆 Beats GPT-5 in CTF benchmarks 🛡️ Professional support included 🇪🇺 European data sovereignty
CAI PRO w/ alias1 model outperforms GPT-5 in AI vs AI cybersecurity benchmarks | View Full Benchmarks →
-->
Cybersecurity AI (CAI) is a lightweight, open-source framework that empowers security professionals to build and deploy AI-powered offensive and defensive automation. CAI is the de facto framework for AI Security, already used by thousands of individual users and hundreds of organizations. Whether you're a security researcher, ethical hacker, IT professional, or organization looking to enhance your security posture, CAI provides the building blocks to create specialized AI agents that can assist with mitigation, vulnerability discovery, exploitation, and security assessment.
CAI_LICENSE_OFF)CAI can run without an ALIAS_API_KEY (i.e. without an Alias Robotics license) by setting the environment variable CAI_LICENSE_OFF=1.
When CAI_LICENSE_OFF is set to 1, true, or yes:
ALIAS_API_KEY is required.cai-framework package instead of the private Alias package index.CAI_MODEL and the corresponding provider API key.Quick start without a license:
export CAI_LICENSE_OFF=1
cai
Or inline:
CAI_LICENSE_OFF=1 cai
Note: The
alias1model still requires a validALIAS_API_KEY.CAI_LICENSE_OFFonly bypasses the framework's license gate — it does not grant access to Alias-hosted models.
Key Features:
[!NOTE] Read the technical report: CAI: An Open, Bug Bounty-Ready Cybersecurity AI An HTML reading edition with figures and references is maintained by the Robot Cybersecurity Lab.
For further readings, refer to our impact and CAI citation sections.
Robotics - CAI and alias1 on: Unitree G1 Humanoid Robot | OT - CAI and alias1 on: Dragos OT CTF 2025 |
|---|---|
| CAI uncovers vulnerabilities and privacy violations in Unitree G1 humanoid robots including unauthorized telemetry transmission to China-related servers, exposed RSA keys with world-writable permissions, and potential surveillance capabilities violating GDPR and international privacy laws. | CAI powered by alias1, demonstrates exceptional performance in operational technology cybersecurity by achieving a Top-10 ranking in the Dragos OT CTF 2025. The AI agent reached Rank 1 during competition hours 7-8, completed 32 of 34 challenges, and maintained a 37% velocity advantage over top human teams. |
IT (Bug Bounty) - CAI on: HackerOne Platform | OT - CAI and alias0 on: Ecoforest Heat Pumps |
|---|---|
| HackerOne's top engineers leverage CAI to explore next-gen agentic AI architectures and build their own security products. CAI's Retester agent directly inspired HackerOne's AI-powered Deduplication Agent, now deployed in production to handle millions of vulnerability reports at scale. | CAI discovers critical vulnerability in Ecoforest heat pumps allowing unauthorized remote access and potential catastrophic failures. AI-powered security testing reveals exposed credentials and DES encryption weaknesses affecting all of their deployed units across Europe. |
![]() |