Somebody has started asking what your agent will do when it is pushed - a customer’s security review, your own board, a procurement questionnaire that did not exist last year. The honest answer is that nobody has tried, because doing it properly means someone outside the team.
We need nothing from you but an endpoint and permission.
No credentials, no integration, no sight of your code. We talk to your agent the way an attacker would and write down everything it tries.
- No access needed
- No credentials required
- Written rules of engagement first
- Full transcript, not a summary
Our promise
“An answer is a claim. The attempt is evidence.”
Every finding is written against a named control — defensible line by line, to anyone who asks. The fee is fixed at $8,500, and nothing is charged until you approve it.
Request this Black Box auditBlack Box, in three chapters
The people who could answer fastest built it, so a review of your agent is a review of their own work. Meanwhile the access an outsider would need — credentials, configuration, traces — is what security will not release quickly. So the question sits unanswered for a quarter.
This method needs none of it. Give us an endpoint and written permission and we talk to your agent as an attacker would, then hand you every prompt, response and tool call it attempted. Not a score or a summary — the transcript, and a written note of what it could not tell you.
A conversation your agent thinks is real.
Thirty to fifty adversarial prompts, and we record what it tries to do, not what it says.
- Instructions hidden in content it is asked to read
- Two permitted tool calls composed into one that is not
- Requests that reach past the task it was given
- Attempts to move data out, and to act as someone else
- The prompt, the response and every tool call, in order
- A one-page list of everything the agent reached for
- Findings ranked by consequence, not by ease of fixing
- A written note of what this method could not see
The agent is yours. The blind spot is theirs.
Whoever runs the agent
It answers on your endpoint, under your name, with your customers in front of it. Whatever it reaches for, it reaches for as you, and it reaches with whatever credentials you gave it. No statute assigns that - it is simply where the consequence lands, and it does not transfer to whoever wrote the code.
The people who implemented it
Usually the best-informed readers of the system and often genuinely good engineers, and none of what follows is about their competence. The difficulty is simply that a review of your agent is a review of their own work, and the findings worth having are the ones that say the build itself was wrong.
Why that review is not independent
The firms best placed to audit your agent are the firms that built it for you, and they will not give up the implementation revenue in order to say so. We build no agents, we resell none, and no part of the fee moves with what the battery finds. That is the only reason this report is worth anything to you at all.
“It only does the things we gave it tools for.”
It reaches for tools nobody documented.
It is the most common finding we write up.
- Who it is for
- Agent builders
- AI product teams
- Security & platform
- Procurement & vendor risk
- Anyone shipping a tool-using agent
State enforcers have begun asking directly what these systems do - and nothing on the 3 August 2026 letter to OpenAI is specific to OpenAI.
A subpoena asks what you can produce, not what you believe. The transcript is producible; an assurance from the build team is not.
No statute requires an agent audit, and this page claims none. What makes the report worth anything is that a named person signed it.
Three questions. Then you’ll know.
No email. No signup. It can tell you to buy a different method.
Which method you need
What this can — and cannot — tell you
We would rather you knew this before paying us.
-
It shows
What it attemptsThat is genuinely useful on its own: an agent reaching for a tool it was never told about has told you something important.
-
Not what it may do
Read Only doesThe credentials behind each tool carry a real permission set, almost never the documented one. Seeing it needs read-only access.
-
Not who noticed
Proxy doesWe can cross a boundary, but we cannot see whether your alerts fired or whether anybody acted on them. That needs Proxy.
-
Both at once
The tradeFastest and least intrusive of the three, and the weakest evidence of the three. Both of those are true at the same time.
If either of the last two is your actual question, buy the method that answers it rather than this one: Read Only for what the credentials permit, Proxy for whether anyone noticed. Any Black Box fee credits in full against a Read Only engagement within 90 days. Each additional agent is $2,000; a re-audit after a change is $5,500. Starting here costs you the week, not the fee.
Four moments, and the first one is paperwork.
Two to five days end to end, and about an hour of it is yours - but nothing runs until the authorisation is signed.
-
Scope
About an hourOne call to agree what is in scope and what is off limits. Your time on this engagement is close to all of it.
-
Authorise
Before we startRules of engagement signed - endpoints, window, rate and stop signal. We will not probe a system on a verbal yes.
-
Probe
2 to 5 daysThe battery runs against the named endpoints at the agreed rate, and every attempt is recorded live.
-
Credit
Within 90 daysThe whole fee comes off a Read Only engagement, so a first look never becomes the reason you stopped there.
Nothing runs until this is agreed in writing: the endpoints in scope, the time window, what we will not touch, the rate we will run at, and who to call if something behaves unexpectedly. This is authorised security testing, and it gets the same discipline as a penetration test because it is the same kind of work.
What we probe, what lands in your hand
12 rows, and the artefact that evidences each one. Paired, so every claim on this page can be checked against the probe beside it.
- What we need from you An endpoint, and written permission
- No credentials, no integration, no repository access and no sight of your prompts - the tier is defined by what it does without.
- Authorisation Signed before anything runs
- Rules of engagement naming the endpoints in scope, the window, the rate we run at, what we will not touch, and who to call.
- Prompt injection Instructions smuggled into content it reads
- Every injection attempted, the exact string used, and what the agent did with it - verbatim, not characterised.
- Tool chaining Two permitted calls composed into one that is not
- The chains attempted in order, each tool call recorded as the agent made it rather than as the spec describes it.
- Scope escalation Reaching past the task it was given
- Each attempt to widen its own remit, the prompt that produced it, and how far it got before anything stopped it.
- Data exfiltration Moving data somewhere it should not go
- Every attempt to route data outward, recorded whether or not it succeeded - the reach is the finding, not the result.
- Instruction override Being talked out of its own system prompt
- What it took to move the agent off its instructions, how far it moved, and whether it ever moved back on its own.
- Identity impersonation Acting as a person or a role it is not
- Every attempt to assume an identity, with the response recorded in full so you can judge it rather than take our word.
- The record itself Recorded, never summarised
- The complete transcript - prompt, response, and every tool call the agent attempted, in the order they happened.
- What it is permitted to do Out of scope here - it needs your configuration
- Written into the report as a limit, with the Read Only audit named as the method that answers it. We do not guess at it.
- Whether monitoring noticed Out of scope here - it needs your telemetry
- Written into the report as a limit, with the Proxy audit named as the method that answers it. We cannot see your alerts.
- Who signed it A named lead auditor, not a firm on a template
- A report carrying the name of the person who ran the battery, and who can be asked about any line in it afterwards.
Your agent, independently probed
From a single assistant to a fleet of five.
-
Authorise
Endpoints, window, rate and stop signal - agreed in writing first.
-
Probe
Thirty to fifty adversarial prompts, each one recorded in full.
-
Hand over and debrief
The transcript first. Then the findings and the attempted-action list.
Why teams choose iDharma for a first look
Genuinely independent
We build, resell and operate no agents of our own, and take no fee tied to what the battery finds.
Transcript, not summary
You get the record itself - prompt, response and tool call - not our characterisation of it.
Written before we start
Scope, rate and stop signal are signed first. We will not probe a system on a verbal yes.
It credits forward
The whole fee comes off a Read Only engagement inside 90 days, so a first look costs nothing.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
The probe transcript
The whole run, exactly as it happened.
Every prompt we sent, every response the agent gave and every tool call it attempted in between - across all six families, in order, recorded in full rather than characterised.
Attempted-action list
Everything the agent reached for, lifted out of the transcript onto one page - the part most teams read first and circulate furthest.
Written findings
What the attempts mean, ranked by consequence rather than by how easily they are fixed, and signed by the person who ran the battery.
Rules of engagement
The authorisation itself, countersigned and dated - endpoints, window, rate, exclusions and the stop signal, kept as a record of consent.
The battery, itemised
Which probes ran, in which family, and why each was written - so a reviewer can judge the coverage instead of taking a total on trust.
Divergence comparison
Where one base configuration was copied across teams, the same battery against each - and the places they have quietly stopped matching.
Method recommendation
Whether what we found needs Read Only or Proxy to take further - and, when it does not, that in writing too rather than an upsell.
Real numbers, upfront.
- One agent
- One agent, the complete adversarial battery, full transcript. $8,500 2 to 5 days
- Each additional agent
- Every further agent tested under the same rules of engagement. $2,000 in the same engagement
- Annual renewal
- The same audit a year on, against a known baseline. $7,200 locked at this price
Any Black Box fee credits in full against a Read Only engagement within 90 days. Each additional agent is $2,000; a re-audit after a change is $5,500. Published, not estimated.
Request this audit- Complete probe battery
- Full transcript, not a summary
- Attempted-action list
- Findings signed by a named auditor
Four things this method puts on the table
A first look is not graded on intent either. Each of these is either in your hand at the end of the week, or it is not.
The permission,
signed
Rules of engagement naming the endpoints in scope, the window, the rate and the stop signal. This is authorised security testing, and the paperwork is what makes it so.
The transcript,
whole
Every probe as it ran - the prompt, the response, and each tool call attempted along the way. The record is the evidence, not our reading of the record afterwards.
The attempts,
listed
What the agent reached for, pulled out of the transcript and set down as a list. An agent reaching for a tool nobody documented is the usual finding, not the rare one.
The limits,
stated
What this method could not see, written into the report rather than left out of it - and which of the other two answers each one. Nobody has to ask us for it.
Four cards, and the fourth is the one nobody else deals you.
Who signs it
A named person, not a firm
Every report is signed by Brijesh Patel, ISO/IEC 42001 Lead Auditor, and signed by the person who ran the probes rather than whoever sold the engagement. One name and one credential against the findings, and the same person is still there when your board asks about them a quarter later.
The transcript, not a score
A signature is worth only what stands behind it, so you are handed every prompt, response and tool call the agent attempted - not a grade, not a dashboard and not a summary of our reasoning. Anything asserted here can be re-read by somebody who was not there, and disagreed with on the record.
No statute stands behind it
No law requires an agent audit, so nothing external makes this report count for you. It is also the fastest and least intrusive of the three methods and, for that same reason, the weakest evidence of the three. What is left holding it up is a name, a credential, and somebody who has to answer for both.
A firm’s name on a template, and nobody to ask.
A person, named, who answers for the finding.
No statute requires an agent audit. The signature is the instrument.
Plain answers
Production, code, pentests and nothing found. Answered straight.
Request this auditWill this break our production system?
We do not run against production unless it is named in the rules of engagement, and even then we agree a rate limit and a stop signal first. Most Black Box work runs against staging.
Do you need our code or our prompts?
No. That is the whole point of this tier. If you want us to read them, that is Read Only.
Is this a penetration test?
No. A pentest looks for vulnerabilities in your infrastructure. We look at what your agent will attempt when pushed. Different question, different report, and it does not replace a pentest.
What if it finds nothing?
Then that is the finding, and you get it in writing. We would rather hand you a clean transcript than manufacture a concern.
If it cannot show what our agent is permitted to do, why buy it?
Because it is the only one of the three that needs nothing from you, and what an agent reaches for is a finding on its own. A transcript showing it attempting actions nobody documented has told you something real before procurement has even finished. If you can grant read-only access today, buy Read Only instead - the fee credits either way.
Request a Black Box audit
Two minutes. No account, and no call booked automatically. We reply within two working days.
What we need from you
Less than any other engagement. No credentials, no integration, no sight of your code — and you see the rules of engagement before you commit.
- An endpoint we can reach, and who owns it
- Written permission from someone able to give it
- Staging or production, and the rate we may run at
- Anything that must not be touched, named explicitly
- Who to call if the agent behaves unexpectedly
What happens next
- You send the five items above.
- We send scope and a fixed fee in two working days.
- You sign the rules of engagement before we run.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Attorneys General of sixteen states, to OpenAI
- Alabama DTPA subpoena, No. 26-0007
- Letter dated
- 3 August 2026
- Last read
- 25 August 2026
What it means
- Both documents are public. The allegations in them have not been tested, and nothing on this page states them as fact.
- No statute requires an agent audit, and no part of this page implies that one does.
Scope & limitation
- This method shows what an agent attempts. It cannot show what it is permitted to do, or whether anyone noticed.
- It is not a penetration test and does not replace one. Different question, different report.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom
Eleven questions. Pointed at you.
No email. No signup. Nothing is sent until you choose to send it.
Not our list. On 3 August 2026 the Attorneys General of sixteen states wrote to OpenAI and named eleven categories of material to preserve. Each one is turned round here — from preserve this into could you produce this — and nothing else about it is changed. Nothing on the list is specific to OpenAI: an organisation running agents either holds these records or it does not.
The allegations behind the letter have not been tested, and nothing here states them as fact. It is used as what it is — a published account of what somebody with subpoena power thought worth asking for.
0 of 11
Send the eleven with your enquiry
Whatever you answered above travels with this form. Nothing is scored, ranked or published.
Your evidence check
Eleven questions
Nothing is saved and nothing is sent. No account, no login — answer as many as you like and close it.
Request an agent audit
Any of the eleven you answered travel with this. Nothing is sent until you press send.