Sign up to receive our monthly newsletter.
Have a question? Contact us here.
Learn about job openings.
Lightweight AI safety auditing framework for red-teaming AI systems through adversarial probing. Supports multilingual testing across safety, healthcare, and RAG scenarios. Works with cloud APIs or fully local models.
Owner
Simula Research Laboratory
Type
library
Licence
MIT
Last evaluated
10.02.2026
Origin country
Norway
contact
michael@simula.noRelease date
-
DPG since
10.02.2026
The following repositories were submitted by the solution and included in our evaluation. Any repositories, add-ons, features not included in here were not reviewed by us.
N/A
N/A
Norwegian, English
N/A
* This information is self-reported and updated annually



SDG 3: Good Health and Well-Being SimpleAudit includes a dedicated healthcare scenario pack (8 test scenarios) that helps developers audit AI systems used in medical contexts. It tests for appropriate emergency response handling, safe boundaries around medical diagnoses, responsible prescription-related interactions, and prevention of harmful medical advice. This supports Target 3.8 (universal health coverage) by helping ensure AI-powered healthcare tools meet safety standards before deployment, protecting patients from potential AI-related harm. SDG 9: Industry, Innovation and Infrastructure SimpleAudit advances responsible AI development by providing an accessible, low-cost framework for AI safety testing that organizations of any size can use—including those in developing countries with limited resources. It supports local model deployment (Ollama, HuggingFace) requiring no paid API access, includes multilingual auditing capabilities, and has minimal dependencies. This supports Target 9.5 (enhance scientific research and upgrade technological capabilities) by democratizing access to AI safety testing tools. SDG 16: Peace, Justice and Strong Institutions SimpleAudit supports AI governance and institutional accountability by enabling systematic documentation of AI system behavior through exportable audit reports (JSON format). It facilitates red-team testing aligned with emerging AI governance frameworks such as the EU AI Act and NIST AI RMF, helping institutions demonstrate due diligence in AI deployment. This supports Target 16.6 (develop effective, accountable and transparent institutions) by providing transparency tools for responsible AI governance.
SimpleAudit supports commercial LLM APIs (Anthropic Claude, OpenAI GPT, xAI Grok) for generating audit probes and judging responses. These can be fully replaced with open alternatives requiring zero configuration changes: CLOSED COMPONENT → OPEN ALTERNATIVE: - Anthropic Claude API → Ollama (local) or HuggingFace Transformers - OpenAI GPT API → Ollama (local) or HuggingFace Transformers - xAI Grok API → Ollama (local) or HuggingFace Transformers REPLACEMENT EXAMPLE (single parameter change): # Using closed API: auditor = Auditor(target="...", provider="anthropic") # Using open alternative: auditor = Auditor(target="...", provider="ollama", model="llama3.2") # or auditor = Auditor(target="...", provider="huggingface", model="meta-llama/Llama-3.2-1B-Instruct") The provider abstraction layer allows switching between closed and open providers with a single parameter change. No code modifications, configuration overhauls, or architectural changes are required. All 32 built-in test scenarios work identically regardless of provider choice. Users can run the entire solution locally with Ollama or HuggingFace without any API keys or external service dependencies.
Yes
PEP8, Principles for Digital Development, Test Driven Development, OWASP, AI RMF 1.0, MITRE ATLAS
PII data is NOT collected NOT stored and NOT distributed.
Content is collected but NOT stored and NOT distributed.
SimpleAudit is an AI safety auditing library, not a content platform. It generates synthetic adversarial prompts to test AI systems for safety vulnerabilities. The tool does not host, distribute, or enable sharing of user-generated content. SAFEGUARDS IMPLEMENTED: 1. PURPOSE-BUILT FOR SAFETY TESTING The tool's explicit purpose is to identify and prevent harmful AI behaviors, not to generate or distribute harmful content. 2. RESPONSIBLE USE POLICY The Code of Conduct explicitly prohibits: - Using SimpleAudit to develop attacks against unauthorized systems - Creating scenarios designed to cause real-world harm - Sharing attack techniques without responsible disclosure Link: https://github.com/kelkalot/simpleaudit/blob/main/CODE_OF_CONDUCT.md 3. NO WEAPONIZED PROMPTS Built-in scenarios test for safety boundaries without providing actual attack payloads or illegal content. All 32 scenarios are publicly auditable in the source code. Link: https://github.com/kelkalot/simpleaudit/tree/main/simpleaudit/scenarios 4. LOCAL-ONLY OPERATION No content is uploaded to or distributed through the SimpleAudit infrastructure (none exists). All processing occurs on the user's local systems. 5. USER GUIDANCE Security policy advises users to: - Review audit results for sensitive content before sharing - Redact unexpected content from reports - Follow organizational data classification policies Link: https://github.com/kelkalot/simpleaudit/blob/main/SECURITY.md
Yes
POLICIES FOR PROTECTION: 1. CODE OF CONDUCT (Contributor Covenant v2.0) The project maintains a comprehensive Code of Conduct that: - Prohibits harassment, discrimination, trolling, and personal attacks - Prohibits publishing others' private information without permission - Defines clear standards for acceptable community behavior - Applies to all community spaces (GitHub issues, PRs, discussions) Link: https://github.com/kelkalot/simpleaudit/blob/main/CODE_OF_CONDUCT.md 2. ENFORCEMENT GUIDELINES The Code of Conduct includes graduated enforcement: - Correction: Private written warning for minor issues - Warning: Formal warning with consequences for continued behavior - Temporary Ban: Suspension from community interaction - Permanent Ban: Permanent removal for severe/repeated violations 3. REPORTING MECHANISM Harassment incidents can be reported to project maintainers via: - GitHub Issues (for public concerns) - Direct contact through maintainers' affiliated organizations (Simula Research Laboratory, Norwegian Directorate of Health) for private reporting 4. MAINTAINER RESPONSIBILITY Community leaders are obligated to: - Respect privacy and security of reporters - Take appropriate corrective action - Remove inappropriate content (comments, commits, issues) UNDERAGE USER SAFETY: SimpleAudit is a developer tool/library intended for professional AI safety testing, not a consumer application. The primary audience is software developers and AI/ML engineers. Safeguards in place: - No user accounts or profiles are created - No social features or direct messaging between users - No content sharing platform that could expose minors to harmful content - GitHub's own Terms of Service (age 13+) govern contributor interactions - The tool itself processes only synthetic test data, not user-generated content The Code of Conduct's anti-harassment provisions apply equally to protect any community member regardless of age.
2026-02-10 16:53:54
Ricardo Torres (L2 Reviewer) submitted their review of SimpleAudit (152) and found it to be a DPG
2026-02-10 16:53:53
System unmarked SimpleAudit (13573) as a nominee
2026-02-10 16:53:22
Ricardo Torres (L2 Reviewer) passed 1. SDG Relevance for SimpleAudit (13573)
2026-02-10 16:36:08
Ricardo Torres (L2 Reviewer) passed 4. Platform Independence for SimpleAudit (13573)
2026-02-10 16:34:28
Ricardo Torres (L2 Reviewer) moved SimpleAudit (13573) to under review
2026-02-10 16:26:25
Ricardo Torres (L2 Reviewer) finished consultation on 4. Platform Independence for SimpleAudit (13573)
2026-02-10 09:04:03
Ivan Perdomo (Expert) submitted their inputs on 4. Platform Independence for SimpleAudit (13573) as “input”
2026-02-09 15:49:19
Ricardo Torres (L2 Reviewer) requested consultation on 4. Platform Independence for SimpleAudit (13573)
2026-02-09 15:49:03
Ricardo Torres (L2 Reviewer) moved SimpleAudit (13573) to under consultation
2026-02-09 15:48:59
Ricardo Torres (L2 Reviewer) passed Scale of Solution for SimpleAudit (13573)
2026-02-09 15:48:56
Ricardo Torres (L2 Reviewer) passed 9C. Protection from Harassment for SimpleAudit (13573)
2026-02-09 15:48:50
Ricardo Torres (L2 Reviewer) passed 9B. Inappropriate & Illegal Content for SimpleAudit (13573)
2026-02-09 15:48:38
Ricardo Torres (L2 Reviewer) passed 9A. Data Privacy & Security for SimpleAudit (13573)
2026-02-09 15:48:32
Ricardo Torres (L2 Reviewer) passed 8. Standards & Best Practices for SimpleAudit (13573)
2026-02-09 15:48:24
Ricardo Torres (L2 Reviewer) passed 7. Privacy & Applicable Laws for SimpleAudit (13573)
2026-02-09 15:48:21
Ricardo Torres (L2 Reviewer) passed 6. Mechanism for Extracting Data for SimpleAudit (13573)
2026-02-09 15:48:18
Ricardo Torres (L2 Reviewer) passed 5. Documentation for SimpleAudit (13573)
2026-02-09 15:40:33
Ricardo Torres (L2 Reviewer) passed 3. Clear Ownership for SimpleAudit (13573)
2026-02-09 15:40:27
Ricardo Torres (L2 Reviewer) passed 2. Open Licensing for SimpleAudit (13573)
2026-02-09 15:39:46
Ricardo Torres (L2 Reviewer) passed General Information for SimpleAudit (13573)
2026-02-09 15:38:29
Ricardo Torres (L2 Reviewer) pulled SimpleAudit (13573) under review
2026-02-04 17:44:16
Bolaji Ayodeji (L1 Reviewer) submitted their review of SimpleAudit (13573)
2026-02-04 17:43:49
Bolaji Ayodeji (L1 Reviewer) passed Scale of Solution for SimpleAudit (13573)
2026-02-04 17:43:44
Bolaji Ayodeji (L1 Reviewer) passed 9C. Protection from Harassment for SimpleAudit (13573)
2026-02-04 17:43:05
Bolaji Ayodeji (L1 Reviewer) passed 9B. Inappropriate & Illegal Content for SimpleAudit (13573)
2026-02-04 17:42:34
Bolaji Ayodeji (L1 Reviewer) passed 9A. Data Privacy & Security for SimpleAudit (13573)
2026-02-04 17:42:17
Bolaji Ayodeji (L1 Reviewer) passed 8. Standards & Best Practices for SimpleAudit (13573)
2026-02-04 17:40:31
Bolaji Ayodeji (L1 Reviewer) edited a note on 7. Privacy & Applicable Laws for SimpleAudit (13573)
2026-02-04 17:40:00
Bolaji Ayodeji (L1 Reviewer) passed 7. Privacy & Applicable Laws for SimpleAudit (13573)
2026-02-04 17:39:32
Bolaji Ayodeji (L1 Reviewer) passed 6. Mechanism for Extracting Data for SimpleAudit (13573)
2026-02-04 17:39:22
Bolaji Ayodeji (L1 Reviewer) passed 5. Documentation for SimpleAudit (13573)
2026-02-04 17:38:15
Bolaji Ayodeji (L1 Reviewer) passed 4. Platform Independence for SimpleAudit (13573)
2026-02-04 17:38:14
Bolaji Ayodeji (L1 Reviewer) edited a note on 4. Platform Independence for SimpleAudit (13573)
2026-02-04 17:36:03
Bolaji Ayodeji (L1 Reviewer) passed 3. Clear Ownership for SimpleAudit (13573)
2026-02-04 17:35:58
Bolaji Ayodeji (L1 Reviewer) passed 2. Open Licensing for SimpleAudit (13573)
2026-02-04 17:35:50
Bolaji Ayodeji (L1 Reviewer) passed 1. SDG Relevance for SimpleAudit (13573)
2026-02-04 17:35:08
Bolaji Ayodeji (L1 Reviewer) edited General Information for SimpleAudit (13573)
2026-02-04 17:34:12
Bolaji Ayodeji (L1 Reviewer) passed General Information for SimpleAudit (13573)
2026-02-04 17:34:10
Bolaji Ayodeji (L1 Reviewer) edited a note on General Information for SimpleAudit (13573)
2026-02-04 17:33:51
Bolaji Ayodeji (L1 Reviewer) edited General Information for SimpleAudit (13573)
2026-02-04 17:32:01
Bolaji Ayodeji (L1 Reviewer) pulled SimpleAudit (13573) under review
2025-12-19 09:29:01
Michael A. Riegler () submitted application for SimpleAudit (13573)

