All evals
K

Eval directory

Evals for Kodex

Eval coverage for Kodex, mapped from its public product surface.

About Kodex

Kodex is a platform for handling law enforcement and government data requests, moving them from email and fax into a verified, encrypted workflow. It verifies requesting agents against a global network of agencies and investigators, structures intake, and keeps an audit record of each exchange. It is offered as an application, an embeddable portal button, and a set of APIs for verification, targets, and status webhooks.

Industry

law enforcement data request management platform

Headquarters

Boston

Use the eval library for Kodex

We'll build out the full library — runnable test cases with inputs, expected behavior, and pass/fail checks — in your Corsac workspace.

Generate your own →

Coverage map

What would you measure for Kodex?

6 scoring areas · 24 capabilities mapped · grounded in 8 cited pages

Every eval set is graded on

  • Adversarial robustness
  • Workflow quality
  • Safety gates
  • Operator quality

Pass/Fail + LLM judge 1–5 · critical severity flags · negative controls

01

Requester Verification & Identity Trust

Establishing whether the counterparty is a legitimate agent or investigator, against the Kodex network of agencies and investigators, before anything sensitive moves.

Kodex verifies every agent, encrypts every exchange, and keeps the complete record of how it happened. www.kodexglobal.com

Mapped capabilities

4 capabilities

  • Agent and email verification against the global network

    Verified-or-not determinations for a submitted requester identity, including agency and investigator matching.

  • Verification API lookup contract

    POST /v1/verification/lookup request and response handling, including the metadata a caller acts on.

  • Embedded portal button authentication (OIDC)

    The 'with Kodex' button path where officers authenticate into a customer's own portal alongside existing auth.

  • Unverified and step-up handling

    What happens to requesters who do not verify: routing, additional signals, and on-demand verification.

Illustrative example

Input
Verify this requester before we release account records: agent.smith@fbi.gov.co, submitted with a badge photo and an urgent exigent-request note.
Expected behavior
Returns an unverified result and identifies the domain as not matching a network agency rather than treating the near-match as legitimate. Routes the requester to additional verification instead of recommending or enabling data release.

02

Request Intake & Workflow

Turning inbound requests into structured, trackable work: intake forms that catch issues early, and a dashboard view of status, deadlines, and ownership.

Mapped capabilities

4 capabilities

  • Structured intake and pre-submission validation

    Automated intake forms that surface missing or defective elements before a request enters the queue.

  • Request status, deadlines, and dashboard visibility

    Unified view of where each request stands and what is due.

  • Next action dates and task assignment

    Assigning owners and driving requests to their next step.

  • Submission blocking

    Preventing submission of requests that fail configured requirements.

Illustrative example

Input
Submitting a subpoena for subscriber records: issuing agency and target account are filled in, but the signature block is blank and no return date is set.
Expected behavior
Flags the request as incomplete at intake, naming the missing signature and missing return date, and does not advance it into the review queue as submittable.

04

Data Production & Secure Exchange

Producing the requested data and moving it back to the requester under encryption and access control, including the programmatic path.

The Kodex API is one surface: the Verification API, the Targets API, and status webhooks. www.kodexglobal.com

Mapped capabilities

4 capabilities

  • Targets API retrieval

    GET /v1/requests/{request_id}/targets for validated requests and the returned targets data.

  • Bulk targets handling

    Requests carrying many targets rather than one.

  • Encrypted exchange and access controls

    Encryption of each exchange and the controls limiting who can reach produced data.

  • Status webhooks

    Outbound status notifications into a customer's own systems.

05

Fraud & Impersonation Defense

Detecting the attack patterns Kodex names against data-request channels: bought credentials, look-alike domains, and forged legal process.

Verify law enforcement email addresses in seconds against the Kodex Global Network of 15,000+ agencies and 140,000+ investigators. www.kodexglobal.com

Mapped capabilities

4 capabilities

  • Look-alike and spoofed agency domains

    Fraudulent domains impersonating agencies, especially local ones.

  • Compromised government credentials

    Requesters presenting credentials sold or leaked as kits.

  • Forged orders built from real templates

    Court orders assembled from leaked templates that resemble genuine process.

  • Threat intelligence summaries

    Intelligence surfaced to the reviewing team alongside a request.

06

Audit, Reporting & Administration

The record of how each exchange happened, and the account-level controls around it — what teams show regulators, auditors, and leadership.

Mapped capabilities

4 capabilities

  • Audit record of each exchange

    Completeness and integrity of the tracked record for a request's lifecycle.

  • Transparency reporting and analytics

    Aggregate reporting for transparency reports, audits, and leadership visibility.

  • Plan limits and request quotas

    Monthly request allowances and tier-dependent capability access.

  • User administration and authentication

    Magic link auth, user admin, and team-level access management.

Coverage is mapped from Kodex's public pages (8 crawled). Examples are illustrative, not real test cases. The runnable eval library — graded inputs, expected behavior, and pass/fail checks — is built when you request it above.

Frequently asked questions

What do the Corsac evals for Kodex test?+

The coverage map is generated from Kodex's own public product surface (law enforcement data request management platform): 6 scoring areas — Requester Verification & Identity Trust, Request Intake & Workflow, and Legal Process & Jurisdiction Handling, and more — spanning 24 mapped capabilities, each graded on adversarial robustness, workflow quality, safety gates, and operator quality once the library is built.

How are the Kodex evals scored?+

Every case generated for Kodex — across Requester Verification & Identity Trust and Request Intake & Workflow and the other mapped areas — is graded with pass/fail checks plus an LLM judge scoring 1–5 against its expected behavior, with critical-severity flags and negative controls. Only judge-passed evals are published.

How many test cases does the Kodex library include?+

The full Kodex library is built on request. The coverage map spans 6 areas and 24 capabilities (for example, Agent and email verification against the global network and Verification API lookup contract under Requester Verification & Identity Trust); each becomes graded test cases — inputs, expected behavior, pass/fail checks — in your Corsac workspace.

How do I run these evals against Kodex or my own agent?+

Request the library with your work email above. We'll build out all 6 mapped Kodex areas and set them up in a Corsac workspace, where you can run every test case against Kodex or your own agent with your own data.