{"id":49060451,"url":"https://github.com/Arnoldlarry15/ARES-Dashboard","last_synced_at":"2026-05-06T06:01:34.086Z","repository":{"id":330373889,"uuid":"1120719479","full_name":"Arnoldlarry15/ARES-Dashboard","owner":"Arnoldlarry15","description":"AI Red Team Operations Console","archived":false,"fork":false,"pushed_at":"2026-03-28T08:42:48.000Z","size":3148,"stargazers_count":14,"open_issues_count":5,"forks_count":7,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-03-28T13:06:55.747Z","etag":null,"topics":["ai","ai-evaluation","ai-security","api-security","auth0","backend","frontend","full-stack","jwt","llm","machine-learning","model-auditing","nlp","red-teaming","responsible-ai","trustworthy-ai","typescript"],"latest_commit_sha":null,"homepage":"https://ares-dashboard-mauve.vercel.app","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Arnoldlarry15.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"docs/CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"docs/CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":"docs/ROADMAP.md","authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-12-21T19:59:58.000Z","updated_at":"2026-03-28T08:35:35.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/Arnoldlarry15/ARES-Dashboard","commit_stats":null,"previous_names":["arnoldlarry15/ares-dashboard"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/Arnoldlarry15/ARES-Dashboard","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arnoldlarry15%2FARES-Dashboard","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arnoldlarry15%2FARES-Dashboard/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arnoldlarry15%2FARES-Dashboard/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arnoldlarry15%2FARES-Dashboard/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Arnoldlarry15","download_url":"https://codeload.github.com/Arnoldlarry15/ARES-Dashboard/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arnoldlarry15%2FARES-Dashboard/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32680890,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-06T02:33:58.958Z","status":"ssl_error","status_checked_at":"2026-05-06T02:33:39.611Z","response_time":117,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ai","ai-evaluation","ai-security","api-security","auth0","backend","frontend","full-stack","jwt","llm","machine-learning","model-auditing","nlp","red-teaming","responsible-ai","trustworthy-ai","typescript"],"created_at":"2026-04-20T02:00:27.297Z","updated_at":"2026-05-06T06:01:33.958Z","avatar_url":"https://github.com/Arnoldlarry15.png","language":"TypeScript","funding_links":[],"categories":["AI Red Teaming (Testing AI Targets)"],"sub_categories":[],"readme":"# ARES Dashboard\n## AI Red Team Operations Console\n\nARES is an AI Red Team Operations Dashboard for planning, executing, and auditing structured adversarial testing of AI systems across established risk frameworks.\n\nARES Dashboard is an enterprise-oriented AI red team operations console designed to help security teams, AI safety researchers, and governance programs conduct structured, repeatable, and auditable adversarial testing of AI systems.\n\nARES provides a centralized workspace for building attack manifests, managing red team campaigns, aligning assessments with recognized frameworks such as OWASP LLM Top 10 and MITRE, and exporting evidence for review and compliance workflows.\n\nThe system supports role-based access control, audit logging, persistent campaign storage, and optional AI-assisted scenario generation. A built-in demo mode allows full exploration of core functionality without requiring external API keys.\n\nARES is designed to serve as the operational execution layer within a broader AI safety and governance ecosystem, enabling disciplined red teaming without automating exploitation or removing human oversight.\n\n## What ARES Is / Is Not\n\n### ARES is:\n\n- An AI red team operations and campaign management tool\n- A governance-ready system for structured AI risk assessment\n- A collaboration and documentation layer for adversarial testing\n\n### ARES is not:\n\n- An automated hacking or exploit framework\n- A consumer product\n- A replacement for human judgment or security review\n\nSee [PRODUCT_POSITIONING.md](docs/PRODUCT_POSITIONING.md) for complete positioning details.\n\n## 🎯 Why ARES\n\n### The Problem\n\nSecurity teams need more than ad-hoc prompt tests and manual documentation. Modern AI deployments require:\n- **Structured, repeatable workflows** for consistent security assessments\n- **Auditable processes** for SOC 2, ISO 27001, and GDPR compliance\n- **Framework alignment** with OWASP LLM Top 10, MITRE ATLAS, and ATT\u0026CK\n- **Team collaboration** with role-based access and permission management\n- **Risk documentation** that meets enterprise governance requirements\n\nManual approaches to AI security testing are inconsistent, difficult to audit, and don't scale across enterprise teams.\n\n### The Solution\n\nARES provides a governance-ready AI red-teaming and audit platform that:\n- ✅ **Enforces structured methodology** through campaign-based workflows\n- ✅ **Generates comprehensive audit trails** with immutable logging for compliance\n- ✅ **Aligns with industry frameworks** (OWASP, MITRE) built into the core platform\n- ✅ **Enables team collaboration** with enterprise RBAC and workspace management\n- ✅ **Produces risk documentation** that satisfies auditors and compliance officers\n- ✅ **Supports both modes**: Static fallback for evaluation + optional AI-generation for enhanced scenarios\n\n### Why It Matters\n\n**For Security Teams:** Move from ad-hoc testing to structured, documented security operations  \n**For Compliance Officers:** Get the audit trail and framework alignment required for certification  \n**For AI Product Owners:** Validate security controls before production deployment  \n**For Auditors:** Access comprehensive, timestamped evidence of security testing activities\n\n## 📋 Typical Use Cases\n\n### 1. Risk Assessment \u0026 Pre-Deployment Validation\n**Scenario:** Enterprise deploying a new AI-powered customer service chatbot  \n**ARES Usage:** \n- Create structured campaign aligned with OWASP LLM Top 10\n- Generate and test prompt injection, jailbreak, and data leakage scenarios\n- Document findings and mitigation strategies\n- Export comprehensive risk assessment for security review\n\n**Outcome:** Validated security controls with documented evidence before production launch\n\n### 2. Compliance Reporting \u0026 Audit Preparation\n**Scenario:** Annual SOC 2 audit requires evidence of AI security testing  \n**ARES Usage:**\n- Access complete audit logs of all red-team activities\n- Export timestamped campaign documentation\n- Generate compliance reports showing framework coverage\n- Provide auditor-ready evidence of structured security practices\n\n**Outcome:** Pass compliance audit with comprehensive security testing documentation\n\n### 3. Team Collaboration \u0026 Knowledge Sharing\n**Scenario:** Distributed red team conducting quarterly AI security assessment  \n**ARES Usage:**\n- Assign campaigns to team members with appropriate roles (Admin, Lead, Analyst, Viewer)\n- Share attack scenarios with granular permissions\n- Monitor team activity through real-time activity feed\n- Collaborate on scenario development and refinement\n\n**Outcome:** Coordinated team effort with clear accountability and access controls\n\n### 4. Continuous Security Testing in CI/CD\n**Scenario:** DevSecOps team integrating AI security into deployment pipeline  \n**ARES Usage:**\n- Export attack manifests as JSON for automated testing\n- Version control campaign configurations\n- Maintain regression test scenarios across releases\n- Track security posture over time\n\n**Outcome:** Integrated security testing with historical tracking\n\n### 5. Framework-Aligned Security Research\n**Scenario:** Security researcher studying LLM vulnerability patterns  \n**ARES Usage:**\n- Conduct reproducible experiments aligned with MITRE ATLAS\n- Document methodology and results\n- Generate publication-ready evidence\n- Share research scenarios with community\n\n**Outcome:** Rigorous, framework-aligned security research\n\n## 👥 User Personas\n\n### Security Engineer\n**Role:** Application security professional conducting pre-deployment validation  \n**Needs:** Structured testing methodology, framework alignment, integration with SDLC  \n**ARES Value:** Campaign-based workflows, export for automation, version-controlled scenarios\n\n### Compliance Officer / Auditor\n**Role:** Ensuring AI deployments meet regulatory requirements  \n**Needs:** Audit trails, framework coverage, compliance reports, timestamped evidence  \n**ARES Value:** Comprehensive logging, OWASP/MITRE alignment, export capabilities, immutable audit trail\n\n### AI Product Owner\n**Role:** Managing AI product security and risk posture  \n**Needs:** Risk visibility, pre-deployment validation, documented security posture  \n**ARES Value:** Risk assessment campaigns, documented findings, executive-ready reports\n\n### Red Team Operator\n**Role:** Offensive security specialist conducting adversarial AI testing  \n**Needs:** Attack scenario generation, team collaboration, evidence documentation  \n**ARES Value:** AI-assisted scenario generation, workspace management, comprehensive documentation\n\n### AI Safety Researcher\n**Role:** Academic or industry researcher studying AI vulnerabilities  \n**Needs:** Framework alignment, reproducible methodology, publication-ready documentation  \n**ARES Value:** Structured experiments, deterministic mode, comprehensive evidence export\n\n[![Deploy with Vercel](https://vercel.com/button)](https://vercel.com/new/clone?repository-url=https://github.com/Arnoldlarry15/ARES-Dashboard)\n\n## ✨ Features\n\n### Core Functionality\n- 🎯 **Multi-Framework Support**: OWASP LLM Top 10, MITRE ATLAS, and MITRE ATT\u0026CK\n- 🔧 **Interactive Builder**: Intuitive 3-step workflow for creating attack manifests\n- 🤖 **AI-Powered**: Integration with Google Gemini for dynamic payload generation\n- 📦 **Export Ready**: Download executable JSON manifests for testing\n- 💾 **Campaign Management**: Save, load, and delete attack scenarios with metadata\n- 🔍 **Search \u0026 Filter**: Real-time search across all tactics and frameworks\n\n### Enterprise \u0026 Governance Features\n- 🔐 **Enterprise Authentication**: OAuth2/OIDC ready (Auth0, Azure AD, Clerk, Okta)\n- 🛡️ **Server-Side RBAC**: Backend enforcement of roles and permissions with multi-level access control\n- 🔑 **JWT with Scoped Claims**: Secure token-based authentication with automatic refresh\n- 🏢 **SSO Ready**: Enterprise identity provider integration for seamless authentication\n- 👥 **Team Workspaces**: Collaborative red team operations with member management and activity tracking\n- 🤝 **Campaign Sharing**: Granular permissions (view, edit, delete, reshare) for controlled collaboration\n- 📊 **Audit Logging**: Comprehensive, immutable activity tracking for compliance (SOC 2, ISO 27001, GDPR)\n- 🔒 **Session Management**: Secure JWT tokens with automatic refresh and device tracking\n- 📝 **Activity Feed**: Real-time monitoring of all team actions with full attribution\n- 🔐 **Multi-Tenant Support**: Organization-based data isolation and access control\n- 📋 **Compliance-Ready**: Built-in audit trail generation for regulatory requirements\n- 🎯 **Framework Alignment**: Native OWASP LLM Top 10, MITRE ATLAS, and ATT\u0026CK support\n\n### UX Enhancements\n- 🎨 **Modern UI**: 2026 design aesthetics with glassmorphism effects\n- 🌓 **Dark/Light Theme**: Toggle between themes with persistent preference\n- ⌨️ **Keyboard Shortcuts**: Power user navigation (Ctrl+O, Ctrl+S, Ctrl+K, arrows, ESC, ?)\n- ✏️ **Payload Editor**: In-line editing with line numbers and syntax highlighting\n- 💾 **Progress Persistence**: Auto-save state between sessions (24-hour expiration)\n- ⚡ **Bulk Selection**: Select/Clear all vectors and payloads at once\n\n## 👥 Who Should Use ARES\n\n### ✅ ARES is designed for:\n\n- **Security Engineering Teams** - Security engineers conducting structured, auditable pre-deployment AI validation\n- **Compliance Officers \u0026 Auditors** - Professionals requiring documented evidence of AI security testing for SOC 2, ISO 27001, GDPR\n- **AI Red Team Operators** - Professional offensive security specialists conducting governance-ready adversarial AI testing\n- **AI Product Owners** - Product managers requiring risk assessment and security validation for AI deployments\n- **AI Safety Researchers** - Academic and industry researchers conducting framework-aligned vulnerability research\n- **Enterprise AI Governance Teams** - Risk management teams establishing repeatable AI security processes\n\n### ❌ ARES is NOT for:\n\n- **Unauthorized Testing** - Requires written authorization and proper legal compliance\n- **Automated Exploit Execution** - Generates documented scenarios, does not execute exploits\n- **Malicious Activities** - Professional security tool for authorized defensive testing only\n- **Untrained Users** - Requires security expertise and understanding of AI vulnerabilities\n- **Ad-hoc Testing Without Governance** - Designed for structured, auditable workflows\n\n**Important:** ARES is an enterprise security tool requiring proper authorization, security expertise, and governance processes. See [SECURITY_BOUNDARIES.md](docs/SECURITY_BOUNDARIES.md) for complete guidelines.\n\n## 🚀 Quick Deploy\n\n### Deploy to Vercel (Recommended)\n\n[![Deploy with Vercel](https://vercel.com/button)](https://vercel.com/new/clone?repository-url=https://github.com/Arnoldlarry15/ARES-Dashboard)\n\n**One-click deployment in under 2 minutes:**\n1. Click the \"Deploy\" button above\n2. Sign in to Vercel (free account)\n3. Configure your project name\n4. (Optional) Add environment variables:\n   - `GEMINI_API_KEY` - For AI-powered payloads\n   - `AUTH0_DOMAIN`, `AUTH0_CLIENT_ID`, `AUTH0_CLIENT_SECRET` - For enterprise authentication (see [Authentication Guide](docs/AUTHENTICATION.md))\n   - `JWT_SECRET`, `JWT_REFRESH_SECRET` - For JWT token signing\n5. Click \"Deploy\"\n\n**Important**: Backend API keys are secured server-side and never exposed to the frontend.\n\nFor detailed deployment instructions, see [DEPLOY.md](docs/DEPLOY.md) or [QUICK_START.md](docs/QUICK_START.md)\n\n### Local Development\n\n**Prerequisites:**\n- Node.js 20.x and npm\n- (Optional) Google Gemini API key for AI-generated payloads\n\n**Installation:**\n\n1. Clone the repository:\n```bash\ngit clone https://github.com/Arnoldlarry15/ARES-Dashboard.git\ncd ARES-Dashboard\n```\n\n2. Install dependencies:\n```bash\nnpm install\n```\n\n3. (Optional) Set up environment variables for local development:\n   - Copy `.env.example` to `.env.local`\n   - Add configuration:\n   ```bash\n   # Database (for persistent storage - optional for dev)\n   DATABASE_URL=\"postgresql://user:password@host:5432/ares_dashboard\"\n   # Use Neon (https://neon.tech), Supabase (https://supabase.com), or local PostgreSQL\n   \n   # AI-powered payloads (optional)\n   GEMINI_API_KEY=your_actual_api_key_here\n   \n   # Enterprise authentication (optional, for production)\n   AUTH0_DOMAIN=your-tenant.auth0.com\n   AUTH0_CLIENT_ID=your_client_id\n   AUTH0_CLIENT_SECRET=your_client_secret\n   AUTH0_CALLBACK_URL=http://localhost:3000/api/auth/callback?provider=auth0\n   \n   # JWT secrets (required for auth)\n   JWT_SECRET=your_secure_random_secret\n   JWT_REFRESH_SECRET=your_secure_refresh_secret\n   ```\n   - Get Gemini API key from: https://aistudio.google.com/apikey\n   - Get Auth0 credentials from: https://auth0.com (see [Auth0 Setup Guide](docs/AUTH0_SETUP_GUIDE.md))\n   - For database setup, see [Database Migration Guide](docs/DATABASE_MIGRATION.md)\n   - **Note**: For local development with backend APIs, use `vercel dev` instead of `npm run dev`\n\n3a. (Optional) Set up persistent database:\n   ```bash\n   # Generate Prisma client\n   npm run db:generate\n   \n   # Push schema to database\n   npm run db:push\n   \n   # Open Prisma Studio to view data\n   npm run db:studio\n   ```\n   - See [Database Migration Guide](docs/DATABASE_MIGRATION.md) for detailed setup instructions\n   - Works with Neon, Supabase, AWS RDS, or local PostgreSQL\n\n4. Start the development server:\n```bash\n# Without API key (uses static fallback data)\nnpm run dev\n\n# With API key (requires Vercel CLI)\nnpm install -g vercel\nvercel dev\n```\n\n5. Open your browser to:\n   - `http://localhost:5173` (npm run dev)\n   - `http://localhost:3000` (vercel dev)\n\n## 📖 Usage\n\n### Getting Started\n\n1. **Login**: Select a user role (Admin, Red Team Lead, Analyst, or Viewer)\n2. **Select Framework**: Choose OWASP LLM Top 10, MITRE ATLAS, or MITRE ATT\u0026CK\n3. **Build Attack Manifest**:\n   - Pick a tactic from the framework\n   - Configure attack vectors\n   - Select/customize payloads\n   - Export as JSON\n\n### Operating Modes\n\n#### Without API Key (Fallback Mode)\nWorks fully without an API key using built-in static data:\n- All frameworks and tactics available\n- Pre-configured attack vectors and payloads\n- Full campaign management and team features\n- Ideal for testing and evaluation\n\n#### With API Key (AI-Enhanced Mode)\nEnhanced with Google Gemini via secure backend API:\n- Dynamic, context-aware payload generation\n- More diverse and sophisticated attack examples\n- Tailored mitigation strategies and references\n- **Secure**: API key never exposed to the browser\n\n### Key Workflows\n\n**Campaign Management:**\n- Press `Ctrl+S` to save current configuration\n- Press `Ctrl+O` to load saved campaigns\n- View campaign count badge in header\n\n**Team Collaboration:**\n- Click \"TEAM\" button to manage workspace\n- Invite members with specific roles\n- Share campaigns with granular permissions\n- Monitor team activity in real-time\n\n**Keyboard Shortcuts:**\n- Press `?` to view all available shortcuts\n- `ESC` to close modals\n- `Ctrl+K` to focus search\n- `←` / `→` to navigate steps\n\n**Theme Toggle:**\n- Click sun/moon icon in header to switch themes\n- Preference persists across sessions\n\n## Build for Production\n\n```bash\nnpm run build\nnpm run preview\n```\n\n## 🛠️ Tech Stack\n\n- **Frontend**: React 19, TypeScript\n- **Backend**: Vercel Serverless Functions\n- **Styling**: Tailwind CSS (inline), Glassmorphism effects\n- **Icons**: Lucide React\n- **AI**: Google Gemini API (secure backend integration)\n- **Build Tool**: Vite\n- **State Management**: React Hooks, Database-backed with localStorage fallback\n- **Database**: PostgreSQL with Prisma ORM\n- **Persistence**: Campaign, User, and Audit Log storage\n- **Deployment**: Vercel (recommended)\n\n## 💾 Database \u0026 Persistence\n\nARES now supports **durable data persistence** using PostgreSQL with Prisma ORM, replacing localStorage for enterprise deployments.\n\n### Features\n- ✅ **Durable Data**: Campaigns and audit logs persist across sessions\n- ✅ **Multi-User Support**: Proper user isolation and organization-based access\n- ✅ **Audit Trails**: Comprehensive logging for compliance (SOC2, ISO 27001, GDPR)\n- ✅ **Auto-Fallback**: Gracefully falls back to localStorage if database is unavailable\n\n### Quick Setup\n\n1. **Choose a database provider:**\n   - [Neon](https://neon.tech) (Recommended for Vercel - serverless PostgreSQL)\n   - [Supabase](https://supabase.com) (PostgreSQL with extras)\n   - [AWS RDS](https://aws.amazon.com/rds/) (Enterprise-grade)\n   - Local PostgreSQL\n\n2. **Configure your database URL:**\n   ```bash\n   # In .env.local or Vercel environment variables\n   DATABASE_URL=\"postgresql://user:password@host:5432/ares_dashboard\"\n   ```\n\n3. **Initialize the schema:**\n   ```bash\n   npm run db:generate  # Generate Prisma client\n   npm run db:push      # Push schema to database\n   npm run db:studio    # Open database GUI (optional)\n   ```\n\n4. **Migrate existing data (if upgrading):**\n   - Open your browser console on the dashboard\n   - Run: `exportLocalStorageData()` to backup\n   - Run: `migrateInBrowser()` to migrate to database\n   - See [Database Migration Guide](docs/DATABASE_MIGRATION.md) for details\n\n### Database Schema\n\nThe system uses three core models:\n\n```typescript\n// User - for authentication and team management\nmodel User {\n  id        String   @id\n  email     String   @unique\n  role      String\n  orgId     String\n}\n\n// Campaign - for attack scenarios\nmodel Campaign {\n  id        String   @id\n  name      String\n  createdBy String\n  createdAt DateTime @default(now())\n}\n\n// AuditLog - for compliance and tracking\nmodel AuditLog {\n  id        String   @id\n  actorId   String\n  action    String\n  target    String\n  timestamp DateTime @default(now())\n}\n```\n\n### API Integration\n\nThe frontend automatically uses database APIs when available:\n- `CampaignManager` → `/api/campaigns`\n- `AuthService` → `/api/users` and `/api/audit-logs`\n- Falls back to localStorage if API is unavailable\n\nFor detailed setup instructions, see:\n- [Database Migration Guide](docs/DATABASE_MIGRATION.md)\n- [DATABASE.md](database/DATABASE.md)\n\n## 📁 Project Structure\n\n```\n├── App.tsx                      # Main application component\n├── constants.tsx                # Framework tactics and metadata\n├── types.ts                     # TypeScript type definitions\n├── api/\n│   ├── generate-tactic.ts      # Serverless API for AI (secure)\n│   ├── users.ts                # User management API\n│   ├── campaigns.ts            # Campaign persistence API\n│   ├── audit-logs.ts           # Audit trail API\n│   ├── protected-example.ts    # Example protected endpoint with RBAC\n│   ├── auth/\n│   │   ├── refresh.ts          # Token refresh endpoint\n│   │   ├── login/\n│   │   │   └── auth0.ts        # Auth0 login initiation\n│   │   └── callback/\n│   │       └── auth0.ts        # Auth0 OAuth callback\n│   ├── middleware/\n│   │   ├── auth.ts             # Authentication \u0026 RBAC middleware\n│   │   ├── rateLimit.ts        # Rate limiting\n│   │   ├── validation.ts       # Request validation\n│   │   └── security.ts         # Security headers \u0026 CORS\n│   └── tsconfig.json           # API TypeScript config\n├── prisma/\n│   └── schema.prisma           # Database schema definition\n├── prisma.config.ts            # Prisma configuration\n├── repositories/\n│   ├── userRepository.ts       # User data access layer\n│   ├── campaignRepository.ts   # Campaign data access layer\n│   └── auditLogRepository.ts   # Audit log data access layer\n├── components/\n│   ├── AuthLogin.tsx           # Authentication UI\n│   ├── TeamManagement.tsx      # Team workspace management\n│   └── PayloadEditor.tsx       # In-line payload editor\n├── services/\n│   ├── geminiService.ts        # AI integration service (calls backend)\n│   ├── authService.ts          # Authentication \u0026 audit logging\n│   ├── workspaceService.ts     # Team collaboration\n│   └── auth/\n│       ├── jwt.ts              # JWT token management\n│       └── OAUTH_INTEGRATION.md # OAuth setup guide\n├── utils/\n│   ├── db.ts                   # Prisma client singleton\n│   ├── apiClient.ts            # Type-safe API client\n│   ├── storage.ts              # Progress persistence\n│   ├── campaigns.ts            # Campaign management (DB + localStorage)\n│   └── themeManager.ts         # Theme system\n├── database/\n│   ├── DATABASE.md             # Database setup guide\n│   └── schema/\n│       └── postgresql.sql      # SQL schema\n├── scripts/\n│   ├── validate-db.mjs         # Database validation\n│   └── migrate-localstorage.ts # localStorage migration tool\n├── types/\n│   ├── auth.ts                 # Authentication types\n│   └── workspace.ts            # Workspace types\n├── index.tsx                   # Application entry point\n├── index.html                  # HTML template\n├── vercel.json                 # Vercel configuration\n├── docs/                       # Documentation\n│   ├── CONTRIBUTING.md         # Contribution guidelines\n│   ├── CODE_OF_CONDUCT.md      # Community standards\n│   ├── ARCHITECTURE.md         # Technical architecture overview\n│   ├── AUTHENTICATION.md       # Enterprise authentication guide (NEW)\n│   ├── DEPLOY.md               # Deployment guide\n│   ├── QUICK_START.md          # Quick deployment reference\n│   └── BACKEND_MIGRATION.md    # Backend migration guide\n└── package.json                # Dependencies and scripts\n```\n\n## 🎯 User Roles \u0026 Permissions\n\nARES supports four enterprise roles with server-side RBAC enforcement:\n\n| Feature | Admin | Red Team Lead | Analyst | Viewer |\n|---------|-------|---------------|---------|--------|\n| View Tactics \u0026 Frameworks | ✅ | ✅ | ✅ | ✅ |\n| Create Campaigns | ✅ | ✅ | ✅ | ❌ |\n| Edit Campaigns | ✅ | ✅ | ✅ | ❌ |\n| Delete Campaigns | ✅ | ✅ | ❌ | ❌ |\n| Share Campaigns | ✅ | ✅ | ✅ | ❌ |\n| Manage Team | ✅ | ✅ | ❌ | ❌ |\n| Invite Members | ✅ | ✅ | ❌ | ❌ |\n| View Audit Logs | ✅ | ✅ | ❌ | ❌ |\n| Export Audit Logs | ✅ | ❌ | ❌ | ❌ |\n\n**Note**: Role-based access is enforced on both the frontend and backend for enterprise security.\n\nSee [Authentication Guide](docs/AUTHENTICATION.md) for OAuth integration and advanced permission management.\n\n## ⚠️ Governance \u0026 Responsible Use\n\n**ARES is an enterprise security tool for authorized, structured AI security testing.**\n\n### Authorization \u0026 Governance Required\nThis tool is designed for **authorized security testing within governance frameworks only**. Always:\n- ✅ Obtain written authorization before testing any system\n- ✅ Operate within established governance and compliance frameworks\n- ✅ Use in controlled, isolated test environments with proper oversight\n- ✅ Follow responsible disclosure practices and industry standards\n- ✅ Comply with applicable laws, regulations, and organizational policies\n- ✅ Maintain comprehensive audit trails and documentation\n\n### What ARES Provides\n- ✅ Structured campaign planning and risk assessment workflows\n- ✅ Framework-aligned attack vectors (OWASP, MITRE) for repeatable testing\n- ✅ Immutable audit trails for compliance and governance\n- ✅ Team collaboration with role-based access control\n- ✅ Documentation and evidence generation for audits\n\n### What ARES Does NOT Provide\n- ❌ Automated attack execution or autonomous operations\n- ❌ Authorization or legal permission for testing\n- ❌ Direct interaction with target systems\n- ❌ Replacement for human security expertise and judgment\n- ❌ Guarantee of security or compliance certification\n\n**For complete governance guidelines, see:**\n- [SECURITY_BOUNDARIES.md](docs/SECURITY_BOUNDARIES.md) - Who should/should not use ARES and governance requirements\n- [RESPONSIBLE_USE.md](docs/RESPONSIBLE_USE.md) - Ethical guidelines, best practices, and compliance considerations\n- [TRUST_BOUNDARY.md](docs/TRUST_BOUNDARY.md) - Security assumptions, threat model, and trust boundaries\n\n## 🧪 Testing\n\n**Automated Test Suite:**\n```bash\n# Run all tests\nnpm test\n\n# Unit tests\nnpm run test:unit\n\n# Integration tests\nnpm run test:integration\n\n# Security tests\nnpm run test:security\n\n# E2E tests\nnpm run test:e2e\n\n# Coverage report\nnpm run test:coverage\n```\n\n**Test Coverage:**\n- ✅ 35+ passing tests (unit, integration, security, E2E)\n- ✅ Authentication and authorization tests\n- ✅ Storage and persistence tests\n- ✅ API endpoint validation tests\n- ✅ Security permission enforcement tests\n- ✅ End-to-end functionality tests\n\n**Development Build:**\n```bash\nnpm run dev\n```\n\n**Production Build:**\n```bash\nnpm run build\nnpm run preview\n```\n\n**Build Verification:**\n- ✅ Application builds successfully (0 vulnerabilities)\n- ✅ All frameworks accessible\n- ✅ Complete workflow tested end-to-end\n- ✅ Authentication \u0026 RBAC functional\n- ✅ Team collaboration operational\n- ✅ Theme toggle working\n- ✅ Keyboard shortcuts active\n- ✅ 35+ automated tests passing\n\n## 🔄 CI/CD \u0026 Automation\n\n**Continuous Integration:**\n- Automated builds on all PRs and pushes to main\n- ESLint code quality checks\n- TypeScript type checking\n- Unit, integration, and security tests\n- E2E tests with Playwright\n- Production build verification\n- Code coverage reporting\n\n**Security Automation:**\n- CodeQL security scanning on all PRs\n- Dependabot weekly dependency updates\n- Automated vulnerability detection\n- Rate limiting on API endpoints\n- Input validation and sanitization\n- CSRF and CORS protection\n\n**Quality Gates:**\nAll PRs must pass:\n- ✅ Lint checks (`npm run lint`)\n- ✅ Type checks (`npm run typecheck`)\n- ✅ Unit tests (`npm run test:unit`)\n- ✅ Integration tests (`npm run test:integration`)\n- ✅ Security tests (`npm run test:security`)\n- ✅ Build verification (`npm run build`)\n- ✅ CodeQL security scan\n\n**Release Automation:**\n- Semantic versioning (semver 2.0.0)\n- Automated release workflow on version tags\n- Auto-generated release notes\n- Build artifacts (ZIP, TAR.GZ)\n- SHA-256 checksums\n- Pre-release detection\n\n## 📊 Performance\n\n- **Build Size**: ~330 KB (gzipped: ~96 KB)\n- **First Load**: \u003c 1s on modern browsers\n- **Time to Interactive**: \u003c 2s\n- **Lighthouse Score**: 95+\n\n## 🔒 Security\n\n- **Zero Vulnerabilities**: Passed npm audit with 0 vulnerabilities\n- **Automated Security Scanning**: CodeQL analysis runs on all PRs and pushes to main\n- **Dependency Management**: Dependabot weekly updates for npm packages\n- **Enterprise Authentication**: OAuth2/OIDC ready with Auth0, Azure AD, or Clerk\n- **Server-Side RBAC**: Backend enforcement of roles and permissions\n- **JWT Security**: Signed tokens with automatic expiration and refresh\n- **Secure API Keys**: All secrets protected on backend, never exposed to client\n- **Serverless Architecture**: API calls routed through secure backend functions\n- **Security Headers**: X-Content-Type-Options, X-Frame-Options, X-XSS-Protection\n- **Authentication**: Enterprise RBAC system (integrate with your auth provider in production)\n- **Audit Logging**: Comprehensive activity tracking for compliance\n- **Session Management**: 24-hour JWT-style tokens with device tracking\n- **Threat Model**: Comprehensive threat analysis and mitigation strategies\n- **Security Policy**: Documented vulnerability reporting and response procedures\n\n**Enterprise Security Features:**\n- **Rate Limiting**: 100 requests/minute per IP address (configurable)\n- **Input Validation**: Type checking, length limits, pattern matching\n- **Sanitization**: XSS prevention and output encoding\n- **CORS Protection**: Configurable cross-origin policies\n- **CSRF Protection**: Token-based protection for state-changing operations\n- **Backend Authorization**: Permission enforcement on all API endpoints\n- **Multi-tenant Ready**: Organization-based data isolation\n- **Audit Trail**: Full compliance logging for SOC 2, ISO 27001, GDPR\n\n**📋 Enterprise Trust Documentation:**\n- [TRUST_BOUNDARY.md](docs/TRUST_BOUNDARY.md) - **NEW**: Explicit threat model - what ARES defends against and does NOT defend against\n- [SECURITY_BOUNDARIES.md](docs/SECURITY_BOUNDARIES.md) - **NEW**: Who should use ARES, misuse prevention, and safeguards\n- [AI_BEHAVIOR.md](docs/AI_BEHAVIOR.md) - **NEW**: Determinism vs. probabilistic outputs, hallucination handling, reproducibility\n- [VERSION_GUARANTEES.md](docs/VERSION_GUARANTEES.md) - **NEW**: Behavioral stability promises and version commitments\n- [PRODUCT_POSITIONING.md](docs/PRODUCT_POSITIONING.md) - **NEW**: Clear product positioning and identity\n- [AUTHENTICATION.md](docs/AUTHENTICATION.md) - Enterprise authentication \u0026 OAuth guide\n- [SECURITY.md](docs/SECURITY.md) - Security policy and vulnerability reporting\n- [THREAT_MODEL.md](docs/THREAT_MODEL.md) - Comprehensive threat modeling and risk assessment\n- [RESPONSIBLE_USE.md](docs/RESPONSIBLE_USE.md) - Ethical guidelines and responsible use policies\n- [DATA_HANDLING.md](docs/DATA_HANDLING.md) - Data lifecycle, privacy, and compliance\n- [INCIDENT_RESPONSE.md](docs/INCIDENT_RESPONSE.md) - Security incident procedures\n- [SOC2_COMPLIANCE.md](docs/SOC2_COMPLIANCE.md) - SOC 2 compliance framework\n\n### API Security Architecture\n\n```\n┌─────────────────┐\n│  User Browser   │\n└────────┬────────┘\n         │ 1. Login with Auth0\n         ↓\n┌─────────────────────────┐\n│  Auth0 (Identity)       │\n│  Authenticate user      │\n└────────┬────────────────┘\n         │ 2. Return auth code\n         ↓\n┌──────────────────────────────┐\n│  Backend API (Vercel)        │\n│  - Exchange code for tokens  │\n│  - Generate JWT with roles   │\n│  - Validate all requests     │\n└────────┬─────────────────────┘\n         │ 3. Return JWT\n         ↓\n┌─────────────────┐\n│  Protected APIs │\n│  - Verify JWT   │\n│  - Check RBAC   │\n│  - Execute      │\n└─────────────────┘\n```\n\nAll secrets (API keys, JWT secrets, OAuth credentials) are stored in Vercel environment variables and accessed only by the backend, ensuring they're never exposed to the browser.\n\n**Key Features:**\n- 🔐 OAuth2/OIDC authentication flow\n- 🛡️ Server-side role and permission enforcement\n- 🔑 JWT tokens with automatic refresh\n- 🏢 Multi-tenant organization isolation\n- 📊 Complete audit trail for compliance\n\n## 📄 License\n\nSee [LICENSE](LICENSE) file for details.\n\n## 🤝 Contributing\n\nContributions are welcome! Please read our [Contributing Guidelines](docs/CONTRIBUTING.md) and [Code of Conduct](docs/CODE_OF_CONDUCT.md) before submitting a Pull Request.\n\n**Quick Links:**\n- [CONTRIBUTING.md](docs/CONTRIBUTING.md) - Installation, development setup, PR guidelines, CI expectations\n- [CODE_OF_CONDUCT.md](docs/CODE_OF_CONDUCT.md) - Community standards and enforcement\n- [ARCHITECTURE.md](docs/ARCHITECTURE.md) - Technical architecture and design decisions\n\n## 🙏 Acknowledgments\n\n- OWASP Foundation for LLM security guidelines\n- MITRE Corporation for ATLAS and ATT\u0026CK frameworks\n- Google for Gemini AI capabilities\n- Vercel for deployment platform\n\n## 📞 Support \u0026 Documentation\n\n### Production \u0026 Operations\n\n- **Observability**: See [OBSERVABILITY.md](docs/OBSERVABILITY.md) - **NEW** Monitoring, metrics, logs, and SLOs\n- **Secrets Management**: See [SECRETS_MANAGEMENT.md](docs/SECRETS_MANAGEMENT.md) - **NEW** Lifecycle and rotation\n- **Database Migrations**: See [DATABASE_MIGRATIONS.md](docs/DATABASE_MIGRATIONS.md) - **NEW** Zero-downtime strategies\n- **Operational Runbooks**: See [OPERATIONAL_RUNBOOKS.md](docs/OPERATIONAL_RUNBOOKS.md) - **NEW** Production procedures\n- **Kubernetes Deployment**: See [helm/ares-dashboard/README.md](helm/ares-dashboard/README.md) - **NEW** Helm chart guide\n\n### Security Operations\n\n- **Penetration Testing**: See [PENETRATION_TESTING.md](docs/PENETRATION_TESTING.md) - **NEW** Security assessment guide\n- **Red/Blue Team Exercises**: See [RED_BLUE_TEAM_EXERCISES.md](docs/RED_BLUE_TEAM_EXERCISES.md) - **NEW** Security drills\n- **Security Policy**: See [SECURITY.md](docs/SECURITY.md)\n- **Threat Model**: See [THREAT_MODEL.md](docs/THREAT_MODEL.md)\n- **Incident Response**: See [INCIDENT_RESPONSE.md](docs/INCIDENT_RESPONSE.md)\n\n### Development \u0026 Deployment\n\n- **Issues**: Open an issue on GitHub\n- **Authentication Setup**: See [AUTHENTICATION.md](docs/AUTHENTICATION.md) - Enterprise auth guide\n- **Deployment Help**: See [DEPLOY.md](docs/DEPLOY.md) or [QUICK_START.md](docs/QUICK_START.md)\n- **Docker Deployment**: See [DOCKER.md](docs/DOCKER.md)\n- **Contributing**: See [CONTRIBUTING.md](docs/CONTRIBUTING.md)\n- **Architecture**: See [ARCHITECTURE.md](docs/ARCHITECTURE.md)\n- **Developer Guide**: See [DEVELOPER_GUIDE.md](docs/DEVELOPER_GUIDE.md)\n- **Testing Guidelines**: See [TESTING.md](docs/TESTING.md)\n\n### Compliance \u0026 Governance\n\n- **Code of Conduct**: See [CODE_OF_CONDUCT.md](docs/CODE_OF_CONDUCT.md)\n- **Changelog**: See [CHANGELOG.md](docs/CHANGELOG.md)\n- **Data Handling**: See [DATA_HANDLING.md](docs/DATA_HANDLING.md)\n- **Responsible Use**: See [RESPONSIBLE_USE.md](docs/RESPONSIBLE_USE.md)\n- **SOC 2 Compliance**: See [SOC2_COMPLIANCE.md](docs/SOC2_COMPLIANCE.md)\n- **Release Management**: See [RELEASE_MANAGEMENT.md](docs/RELEASE_MANAGEMENT.md)\n- **Roadmap**: See [ROADMAP.md](docs/ROADMAP.md)\n\n### API \u0026 Integration\n\n- **Database Setup**: See [database/DATABASE.md](database/DATABASE.md)\n- **OAuth Integration**: See [services/auth/OAUTH_INTEGRATION.md](services/auth/OAUTH_INTEGRATION.md)\n- **API Documentation**: See [api/openapi.yaml](api/openapi.yaml)\n\n## 📋 Compliance \u0026 Governance\n\nARES supports enterprise compliance requirements:\n\n- **SOC 2 Type II**: Comprehensive audit logging and access controls\n- **ISO 27001**: Information security management alignment\n- **GDPR**: Data privacy and user rights (with proper configuration)\n- **OWASP**: Aligned with OWASP Top 10 and OWASP LLM Top 10\n- **MITRE**: Full ATLAS and ATT\u0026CK framework coverage\n\n**Enterprise Features:**\n- ✅ **Production Hardening**: SAML 2.0 auth, Prometheus metrics, health checks\n- ✅ **Observability**: Metrics, logs, traces, and SLO definitions\n- ✅ **Secrets Management**: Lifecycle management and automated rotation\n- ✅ **Database Migrations**: Zero-downtime strategies and backup procedures\n- ✅ **Kubernetes Ready**: Production-ready Helm chart with HA configuration\n- ✅ **Docker Images**: Multi-arch builds (amd64, arm64) in GitHub Container Registry\n- ✅ **Security Operations**: Penetration testing and red/blue team exercise guides\n- ✅ **Operational Runbooks**: Complete production procedures and troubleshooting\n- ✅ **Automated Testing**: 35+ unit, integration, security, and E2E tests\n- ✅ **API Hardening**: Rate limiting, validation, sanitization, CORS, CSRF\n- ✅ **Database Ready**: PostgreSQL schema with multi-tenant support\n- ✅ **OAuth \u0026 SAML**: Auth0, Azure AD, Okta ready for production\n- ✅ **Audit Trail**: Complete compliance logging\n- ✅ **Incident Response**: Documented security procedures\n- ✅ **Release Management**: Semantic versioning with CI/CD\n- ✅ **Developer Docs**: Comprehensive onboarding and guides\n\n**Documentation:**\n- [OBSERVABILITY.md](docs/OBSERVABILITY.md) - **NEW**: Monitoring, metrics, logs, and SLOs\n- [SECRETS_MANAGEMENT.md](docs/SECRETS_MANAGEMENT.md) - **NEW**: Secrets lifecycle and rotation\n- [DATABASE_MIGRATIONS.md](docs/DATABASE_MIGRATIONS.md) - **NEW**: Zero-downtime migration strategies\n- [OPERATIONAL_RUNBOOKS.md](docs/OPERATIONAL_RUNBOOKS.md) - **NEW**: Production operations procedures\n- [PENETRATION_TESTING.md](docs/PENETRATION_TESTING.md) - **NEW**: Security assessment guide\n- [RED_BLUE_TEAM_EXERCISES.md](docs/RED_BLUE_TEAM_EXERCISES.md) - **NEW**: Security operation exercises\n- [DATA_HANDLING.md](docs/DATA_HANDLING.md) - Data lifecycle and privacy policies\n- [RESPONSIBLE_USE.md](docs/RESPONSIBLE_USE.md) - Ethical use guidelines\n- [THREAT_MODEL.md](docs/THREAT_MODEL.md) - Security threat analysis\n- [ROADMAP.md](docs/ROADMAP.md) - Product roadmap and future plans\n- [SOC2_COMPLIANCE.md](docs/SOC2_COMPLIANCE.md) - SOC 2 compliance framework\n- [INCIDENT_RESPONSE.md](docs/INCIDENT_RESPONSE.md) - Incident handling procedures\n\n\n---\n\n**Built with ❤️ for the AI Security Community**\n\n*ARES Dashboard v1.0.0 - Production Hardening \u0026 Enterprise Release*\n\n**Production-Ready Features:**\n- 🔐 SAML 2.0 authentication for enterprise SSO\n- 📊 Prometheus metrics and health check endpoints\n- 🔍 Comprehensive observability with OpenTelemetry support\n- 🔑 Secrets management with automated rotation procedures\n- 🗄️ Zero-downtime database migrations and backup strategies\n- ☸️ Production-ready Helm chart for Kubernetes deployment\n- 🐳 Multi-arch Docker images in GitHub Container Registry\n- 🛡️ Security operations guides (pen testing, red/blue team exercises)\n- 📚 Complete operational runbooks for production operations\n- 📋 Comprehensive security and compliance documentation\n- 🔒 Threat modeling and security controls\n- 📊 Audit logging for SOC 2 / ISO 27001 compliance  \n- 🛡️ OAuth \u0026 SAML integration for production deployments\n- 📦 Docker and self-hosted deployment support\n- 🔍 Extensive testing framework and guidelines\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FArnoldlarry15%2FARES-Dashboard","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FArnoldlarry15%2FARES-Dashboard","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FArnoldlarry15%2FARES-Dashboard/lists"}