YOFUNE_LABSINTELLIGENCE, TESTED.
Yofune Labs / AI Security Products01 — 03 / 2026

Three perspectives.
Every risk, a trace.

With AI security at our core, we turn artificial intelligence and offensive research into products for real business environments. From agentic testing to human-risk simulations and code analysis, connect risk discovery with evidence-based decisions and practical improvements.

Explore products
AI SECURITY / PRODUCTS01—03
Three products. One commitment to evidence.SCROLL TO DISCOVER
01 / Product profileHuman-risk simulation platformYOFUNE LABS ↗

TaiGong

A simulation.
More than a click.

TaiGong connects people, simulation content, execution plans and behavioral reviews. Turn a realistic business scenario into awareness training with a clear objective, useful feedback and a next step.

Book a product demo
Campaign operationsPRODUCT VIEW / 01
TaiGongHuman risk workspace
Interactive demo · Sample data
Campaign workspaceCampaign results

Four departments. Observe recognition and reporting.

BEHAVIOR / 01

Every action tells a story.

Follow unique participants from delivery to interaction and feedback.

Delivered
240100%
Opened
18678%
Clicked
4218%
Submitted
125%
Reported by staff

Include threat recognition in your review

57people

Choose a campaign, then explore its funnel, event history and AI plan.

01

Scenarios grounded in your business

Pair email and landing-page content with employee directories and department groups to organize clearly scoped simulations.

02

See each step of the response

Connect sent, opened, clicked and submitted events. Use campaign funnels and event records to identify where attention is needed.

03

AI assistance with human checkpoints

Turn an objective into an execution plan, run preflight checks and confirm key actions. Pause, cancel or resume when needed.

04

Connect review to learning

Build courses, quizzes and training cohorts around campaign results. Export reports to inform the next round of simulations.

From question to action

  1. 01Define the audience
  2. 02Plan a scenario
  3. 03Review behavior
  4. 04Target the training
02 / Product profileAgentic security testingYOFUNE LABS ↗

KUROSHIO

Let agents explore.
Let evidence speak.

KUROSHIO organizes planning, tool execution and evidence around an authorized objective. Connect assets, observations and decisions so your team can see where an investigation stands and how its conclusions were reached.

Book a product demo
Agent task workspacePRODUCT VIEW / 02
KUROSHIOValidation workspace
Interactive demo · Sample data
Task orchestration02 / 04

Turn observations into a path

Use tool results and asset context to organize the next validation steps.

Context and evidence at every step
Authorized scopeScope defined
Tool call budget4 / 20 calls
Execution policyApproval for sensitive actions

Move through four stages to inspect planning, candidate findings and evidence.

01

Keep the objective in view

Plan from a testing objective and adapt to observed assets, facts and findings, keeping task state connected to execution progress.

02

Bring tools and context together

Configure agents, models, skills and MCP tools to support your work, with exploration paths and asset views in context.

03

Keep key actions under control

Use tool policies and approvals to guide execution. Pause, resume or stop tasks whenever your team needs to intervene.

04

Move from leads to evidence

Link request and response records, tool outputs and finding details. Export structured data or reports for further review.

From question to action

  1. 01Define the scope
  2. 02Plan and explore
  3. 03Review the evidence
  4. 04Build the report
03 / Product profileAI code security workbenchYOFUNE LABS ↗

DeepHook

Deep into code.
Clear on the risk.

DeepHook combines source semantics, data flow and AI vulnerability analysis to trace inputs through propagation paths to sensitive calls. Turn an alert into code evidence you can understand, challenge and review.

Book a product demo
Code evidence workspacePRODUCT VIEW / 03
DeepHookCode research workspace
Interactive demo · Sample data
routes/download.tsCode context
async function download(req, res) {
const root = UPLOAD_DIRECTORY;
const name = req.query.name;Source
const file = resolve(root, name);
const bytes = await readFile(file);Sink
return res.send(bytes);
}
Data flowSemantic analysis
Sourcereq.query.name
Flowresolve(root, name)
SinkreadFile(file)

Trace external input to a sensitive operation.

AI drives research · Evidence supports decisionsDeepHook / CWE-22

Select a finding, follow the evidence through the code and review remediation guidance.

01

Understand the source

Import a code project and combine multi-language semantic analysis with data-flow tracing to investigate potential risks across functions and files.

02

Make the path visible

Connect input sources, propagation steps and sensitive calls to code locations, making trigger conditions and potential impact easier to understand.

03

Go deeper with Hunter

Query evidence around a vulnerability hypothesis, inspect counterevidence and develop validation suggestions for further researcher review.

04

Deliver a path toward repair

Review remediation guidance, diffs and dry-run previews, and generate redacted reports. Agree on authorization and an environment before dynamic validation.

From question to action

  1. 01Import a project
  2. 02Scan the semantics
  3. 03Investigate evidence
  4. 04Review remediation

Start with the problem you need to solve.

Three independent products, each focused on a different surface: human behavior, running systems and source code. Choose the entry point that fits your work.

Start with the problem you need to solve.
ProductFocusDesigned forKey outputs
TaiGongPeopleSecurity operations & awareness teamsCampaign funnels, event reviews & training feedback
KUROSHIOApplications & systemsRed teams & security researchersLinked findings, execution records & evidence reports
DeepHookCodeAppSec, code auditors & vulnerability researchersCode evidence, analysis & remediation guidance
01Which product should we start with?

Choose TaiGong for phishing simulations, behavioral reviews and awareness training. Choose KUROSHIO for agentic security testing of authorized targets. Choose DeepHook for source analysis, vulnerability investigation and code evidence. Evaluate them individually or discuss how they could support the same business scenario.

02Can I interact with these interfaces?

Yes. Switch campaigns, task stages and code findings to explore the workflows. These interfaces were redesigned for this website and use sample data. The actual interface and available features depend on the product version demonstrated and delivered.

03How can we assess the fit for our environment?

Tell us about your team size, system scope or code languages and we will arrange a relevant demo. We will agree on deployment, model connections, data handling, authorization and deliverables before an assessment begins.

YOUR NEXT DISCOVERY.

Your next discovery
starts here.

Start with an AI application assessment, a business-system validation or a security exercise. Together, we will find the right approach.

Discuss your use case