Making it safe to give agents real access
Enterprises are handing AI agents credentials, tools and customer data faster than anyone can check what that access means. We answer one question for those teams: what can this agent actually do, and what happens when someone tries to make it do something else?
How we think about agent security
It shares vocabulary with the work we have all been doing for years, and almost none of the assumptions.
The boundary moved
For thirty years the security boundary was the code path: what the program is allowed to execute. An agent decides in language what to execute next, so the boundary now runs through untrusted text, and almost nothing in a standard security program inspects that.
Access is the real risk
The failure that matters is rarely a jailbroken model saying something embarrassing. It is an agent with a broad service account, a tool that sends mail, and a document that told it to. What turns a mistake into an incident is capability.
Reports do not remove risk
A report that lands on an already full backlog changes nothing. A security engagement should end with the exposure gone and a test that fails if it comes back, which means staying through remediation rather than documenting it and leaving.
Six things we hold to
We show the evidence
Every finding arrives with the transcript and the payload that produced it. If we cannot reproduce it, we do not report it.
We stay for the fix
We measure an engagement by what an attacker can no longer do at the end of it, not by the length of the report.
No vendor commissions
We do not resell security products, so nothing in our remediation advice is steered by a license we would earn.
Only the data we need
We work from the least data that lets us do the job, under a written scope, and return or destroy engagement data on request.
Plain language
Executives get a read they can act on. Engineers get the detail they need. Neither gets a wall of severity scores.
We hand the work over
The attack suite, the threat model and the reasoning behind each fix are yours to keep. You should be able to run this yourselves.
Who runs the work
Academic security research supplies the new attack classes. We turn them into tests that actually work against your agents.

Dr. Benjamin Yan
Founder & CEO
Cybersecurity and machine-learning security researcher, and a professor at Michigan State University, where his lab works on adversarial machine learning and the security of AI-driven systems.
- Published research in adversarial ML and AI system security
- Leads the methodology behind our agent threat models
- Federally funded research background in security and privacy
Talk to the people who would do the work
No sales engineer in the middle. The scoping call is with the team that runs the assessment.