Services · Gate Readiness Assessment
Find the control gaps before your security review.
A scoped assessment of AI agent actions, permissions and review evidence. Production access is optional; active testing needs separate authorisation.
What the engagement covers
Agent and tool inventory
In-scope agents, identities, models, prompts, tools, MCP servers and data flows, with explicit coverage limits.
Control mapping
A requirement-by-requirement record of implemented, missing and untested controls against your agreed review criteria.
Authorised test results
Reproducible scenarios for the high-risk actions in scope, with system version, attempt counts and observed outcomes.
Prioritised findings
Impact, evidence, a named remediation owner and suggested acceptance tests. The report belongs to the client.
Scope and responsibilities
Supply architecture and configuration exports, an agreed requirements list, and a technical contact. We prefer a test environment with synthetic data. Inventory collection is read-only; active tests are explicitly authorised with allowed actions, time windows, stop conditions and a recovery plan.
A production test requires additional written approval. Workload, dependencies and access determine the delivery schedule; a small scope may fit one to three weeks, confirmed in the proposal.
A practical example
A customer-care agent can read account data and issue refunds. The assessment checks who can invoke its tools, whether exports are bounded, whether refund limits are enforced outside the model, and whether decisions can be reconstructed.
The resulting report records observed failures and untested paths. It does not predict certification from a single attack-success percentage.
Inspect a sample report
View a fictional control review with test counts, evidence and open findings. It shows the format, rather than a client outcome.
Request a scoping conversation
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.