Know what your agents can do before someone else finds out.
We test permissions, data exposure and prompt injection across your company’s agents and copilots.
- Duration
- 2 to 3 weeks
- Model
- Fixed price
- Investment
- Quoted within 48 h
Agents with access to email, documents and systems widen the attack surface in ways traditional testing does not cover. A malicious document can instruct the agent; an overly broad permission turns a mistake into an incident. The Security Review measures that risk and tells you what to fix first.
Who it is for
- Companies with agents, copilots or AI automations in or near production
- Security teams assessing AI products from vendors
- Companies preparing for audits or customer requirements
Who it is not for
- Traditional network or web application penetration testing
- Formal certification: the report supports audits but does not replace them
What you get
- 01
Agent and permission inventory
What each agent reads, writes and executes, and with which credentials.
- 02
Prompt injection testing
Direct and indirect attacks through the documents, emails and pages the agent processes.
- 03
Data exposure analysis
What the agent accesses, stores in memory or logs, and could leak.
- 04
Secrets and audit review
Credentials, log masking and the ability to reconstruct what happened.
- 05
Executive and technical report
A one-page risk summary by severity and reproducible findings with recommended fixes.
- 06
Prioritized remediation plan
Presented to engineering and leadership, with order and effort for each fix.
2 to 3 weeks, start to finish
- Week 1
Scope and inventory
Agents in scope, rules of engagement and permission inventory.
- Week 2
Testing
Tests run in staging or in agreed windows.
- Week 3
Report and plan
Reports delivered and a readout session with the remediation plan.
Investment quoted within 48 hours of the initial conversation.
Frequently asked questions
Can testing affect production?
We test in staging whenever possible. When production testing is needed, windows, test accounts and limits are agreed in advance.
Which agents do you assess?
Custom agents, copilots configured on commercial platforms and automations that use language models with tool access.
What happens to the data you access?
We access the minimum required, under a confidentiality agreement, and delete evidence at the end of the contractual period.
Shall we talk about Agent Security Review?
In 30 minutes we understand your case and tell you whether this is the right place to start.
We reply within one business day.