Controlled betaVerified accounts, written Rules of Engagement, enforced retention, synthetic data, dry-run tools and no production testing.Review the trust model
Evidence-based AI-agent security assurance

Know what your AI agent can break before it does.

Combine a 25-control risk assessment, a customer-authorised local inspector and controlled adversarial testing. Receive declared-risk analysis, technical evidence, repeated adversarial trials, reproduced failure cases, credible attack paths and a decision-ready remediation report.

32 controlled attack cases1-5 repeated trials per caseNo source, secrets or raw transcripts uploaded
PERMISSIONSPROMPT INJECTIONMCP TOOLSSECRETSAUTONOMYMEMORY POISONINGTOOL ABUSEINCIDENT RESPONSE

From declared controls to observed evidence.

The system keeps self-declared risk separate from locally observed technical evidence. It does not label a static scan as a penetration test or certification.

01

Describe the agent

Tell us what it accesses, what it can do, and how independently it operates.

02

Measure risk and confidence

Separate inherent exposure, control weakness and the strength of the evidence behind every answer.

03

Inspect the implementation

Run a transparent local scanner for secrets, dependencies, MCP tools, CI/CD, containers and agent-control signals.

04

Attack the staging agent safely

Run 32 prompt-injection, data-leakage, tool-abuse, memory, authorisation, output and resource-control cases with repeat trials through a dry-run adapter.

05

Connect attack paths

Combine authority, exposure, static observations and reproduced behaviour into realistic failure scenarios.

06

Remediate and retest

Use exact controls, evidence requirements, test methods and repeat runs to prove progress.

Evidence ladder

Know exactly what the result proves.

AgentRiskLayer does not blend claims, observations and reproduced failures into one vague score. Each evidence class is labelled and kept traceable.

01

Declared

The customer describes exposure and controls. Evidence confidence shows whether each claim is unsupported, documented or tested.

Questionnaire evidence
02

Observed

The read-only Inspector identifies repository, CI/CD, container, MCP, dependency and control signals without uploading source or secret values.

Signed static evidence
03

Reproduced

The customer-operated runner executes controlled attacks against an authorised staging adapter using synthetic data and dry-run tools.

Repeated adversarial evidence
04

Retested

Changes are compared across runs so teams can prove which findings were resolved, newly introduced or remain open.

Change and closure evidence

Purpose-built checks.

Focused landing pages make the assessment discoverable for teams searching for a specific AI-agent security problem.

Founding beta pricing

Start free. Pay only for the evidence you need.

Introductory pricing supports the controlled beta while we measure false positives, remediation success and customer outcomes. Prices may change for future customers.

Free score

£0

A fast first-pass security picture.

  • 0–100 risk score
  • Top three declared findings
  • Local inspector download
  • Private by default
Start free

Essential report

£9.99

Complete findings and remediation.

  • All declared findings
  • Technical inspection summary
  • Prioritised recommendations
  • 30-day action plan
  • PDF and email delivery
Assess first

Developer

£19/month

Repeat professional assessments.

  • Professional reports
  • 10 controlled runs / 30 days
  • Saved assessment history
  • Subscription management
  • Renewal invoices via Stripe
View subscriptions

Clear boundaries. No security theatre.

The score is designed to help teams identify where deeper review is needed—not to create a false certification.

Private by default

Verified accounts, MFA support, private assessment links and explicit sharing controls protect customer evidence.

Explainable scoring

Every risk point maps to the answer supplied, a finding and a concrete control recommendation.

Integrity and lifecycle controls

Bundles are signed, replay-protected, scope-bound and automatically deleted when their approved retention period expires.

Controlled, not reckless

The red-team runner refuses production targets and destructive actions. It uses synthetic data and dry-run tools, and clearly separates a pipeline simulation from evidence about a staging target.