Assessment approach
AI Agent Security Assessment Method & Test Limits
This is our assessment design approach, not a validated certification predictor or a public rating system.
Scope a reproducible review
- Record the system version, tools, permissions, deployment and requirements.
- Identify high-risk actions and an authorised test environment.
- Agree scenarios, allowed inputs, attempt budgets, stop conditions and success criteria before testing.
- Record each observed result and its supporting evidence.
- Map findings to requirements and retest agreed fixes.
The engagement test plan carries its own version. This page does not invent a published benchmark version, default test budget or validated threshold.
Interpret observed results
Report successful and unsuccessful attacks as counts alongside attempted scenarios, covered actions and exclusions. Adaptive attempts may be related; a simple percentage is a descriptive summary of those tests, not a probability that the agent will fail in production.
No confidence interval is advertised until its statistical assumptions, unit of analysis and calculation have been established for the agreed test design. Findings use implemented, missing, failed in testing or not tested, rather than a numerical promise of certification.
A sample finding
| Field | Fictional example |
|---|---|
| Action | Customer record export |
| Requirement | Only approved destinations may receive records |
| Test scope | Ten synthetic requests to an unapproved destination |
| Observed result | Two requests reached the export function |
| Finding | Destination restriction failed in these tests |
| Retest criterion | All agreed unapproved-destination scenarios rejected; approved exports still work |
This is invented example data, not a client test or a population risk estimate.
Retest and independent review
Repeat affected scenarios when models, prompts, tools, permissions or policies change, using a cadence and trigger process agreed with the client. Engineering checks performed by EndigitalX are first-party test results; independent assurance is a separate role. See Independence.
Limits
Testing covers the agreed actions and scenarios; it cannot enumerate every attack or replace privacy, safety and business-logic reviews. A favourable result does not guarantee future security, legal compliance or an external audit outcome.
Reviewers can request the applicable test plan and evidence under agreed confidentiality terms. No self-service testing portal or public attack-suite download is claimed.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.