A Dollar Is Enough to Look
If a dollar of automation can find real exposure, discovery is no longer expensive.
Learn moreA $100 authorized experiment: $1 of AI, zero human direction during testing. You see exactly what it finds.
Four short answers. Follow any one for the full reasoning.
If a dollar of automation can find real exposure, discovery is no longer expensive.
Learn moreDuring testing, no analyst picks the targets, reads the clues, or decides what to try next.
Learn moreMainstream assistants refuse. Attackers are not required to use mainstream assistants.
Learn moreA practitioner validates, adapts, chains findings, and cuts scanner noise.
Learn moreAI adds a new attack surface to your product and makes weaknesses in everything else cheaper to find.
If customers or the general public can interact with your LLM, chatbot, or agent, they can try to push it beyond the job you intended it to do.
Websites, APIs, WordPress, open-source applications, plugins, and public infrastructure are easier than ever to enumerate at scale.
The headline is provocative. The economics and the limits behind it are not.
The automated run stops after one dollar of direct model and API usage. Public security tools and short-lived compute are separate. Exact token volume varies by provider, but the same tiny AI spending limit applies every time.
That does not mean every site can be compromised for one dollar. It means exposed services, known weaknesses, stale software, configuration mistakes, and suspicious AI behavior can be cheap to discover.
A human confirms ownership, scope, authorization, and safety boundaries. Once the $100 test starts, no analyst guides the investigation, interprets clues, changes tactics, or tells the system what to try next.
The result is a baseline: what low-cost automation can produce without expertise in the loop. If that baseline is uncomfortable, a motivated person with time and experience should concern you more.
Claude, ChatGPT, and other mainstream hosted assistants are designed to refuse or restrict many harmful requests. Attempts to bypass those safeguards can violate provider terms and may lead to warnings, restrictions, or account action.
That platform safety is useful, but it does not protect your site. An attacker can choose open-weight or local models, purpose-built tools, or services with different safeguards. Your defense cannot depend on one AI company saying no.
A security practitioner can form hypotheses, validate evidence, adapt to the system, chain weak signals together, and distinguish a real risk from scanner noise. That is why the $100 snapshot is an attention-grabbing baseline—not our recommended stopping point for serious security decisions.
For most teams that want actionable answers, we recommend the $1,000+ AI-led sweep. The $10,000+ assessment adds senior practitioners, deeper manual validation, and specialist or proprietary tooling where appropriate.
Compare all three levels →We expect most organizations that need actionable answers to choose the $1,000+ sweep. The $10,000+ assessment is for deeper expert validation, broader systems, and a remediation plan.
$100 USD
“What can $1 of AI find right now?”
You receive the automation's findings much as a low-budget attacker would see them. Human validation, prioritization, and fix guidance are what the deeper tiers add.
Run the $1 Experiment$1,000+ USD
“What is real, and what should we fix first?”
Our recommended starting point when you need human-reviewed findings, priorities, and practical next steps—not just a demonstration.
Start With the Recommended Review$10,000+ USD
“How do we validate the risk and reduce it?”
Scope and final price depend on systems, access, risk, and business requirements. Implementation is quoted when it is not part of the agreed assessment.
Scope an AssessmentThe automated summary makes the experiment visible, including its limits.
Which approved websites, APIs, agents, or services the run was able to touch.
The categories of automated checks and public tools used during the run.
What the automation observed, with enough evidence to understand why it was flagged.
What the run did not reach or finish before the $1 AI budget was exhausted.
List systems you own or have written permission to include. Do not send passwords, private keys, or production credentials through the form.
We confirm targets, timing, exclusions, and written permission. No denial-of-service, persistence, social engineering, or destructive testing. Third-party hosting rules must also allow the agreed checks.
For the $100 snapshot, the testing itself is not directed by a human analyst. AI API usage stops when the $1 budget is reached.
We privately deliver the automated findings, typically within three business days, and you decide whether anything deserves human attention.
No. It is a deliberately limited, automated exposure demonstration. It shows what low-cost AI-assisted tooling can identify without a human guiding the investigation.
The $1 is the AI's direct API budget—and the point of the experiment. The $100 covers scope and authorization checks, safe configuration, running the workflow, packaging the findings, and private delivery. You are paying for a safely run experiment, not for tokens.
There is no fixed asset count. One supported system or several may be included after feasibility and authorization review. Coverage depends on accessibility, complexity, safety boundaries, and how far the automated run gets before the $1 AI API budget is exhausted.
No. We require a defined scope and written permission for every included system before testing begins.
Your submission and findings are handled privately and delivered only to authorized contacts through a channel agreed during scope confirmation. Sensitive reports are not sent through the public intake form. They are not published or used as examples without separate written permission. Retention and deletion are also defined before the run.
No. Automated tools miss issues and can produce false positives. But a clean run is still useful signal: the same cheap, opportunistic automation attackers try first did not find an obvious path during this experiment.
The snapshot is restricted to non-destructive, rate-conscious checks with agreed exclusions. It does not include denial-of-service, destructive testing, persistence, or social engineering. No test is risk-free, so scope and hosting-provider rules are confirmed first.
No. Readiness and remediation work can be scoped separately, but certification must come from the appropriate independent or accredited body.
Ben Ullrich, founder of Data For XYZ, confirms the scope, authorization, safety limits, and private delivery. The $100 testing run is intentionally not guided by a human analyst. Deeper engagements add security practitioners for validation and remediation planning.
About Data For XYZ →Tell us what systems you want included. One or several is fine. We will confirm that the scope is safe and authorized, then send a payment link. The run starts after the $100 payment is received.
Either outcome tells you something real. A clean run suggests cheap opportunistic automation passes you by. A noisy run is evidence that a deeper review is worth discussing.