BLACK BOX · NO ACCESS REQUIRED · 2–5 DAYS

We need nothing from you but an endpoint and permission.

No credentials, no integration, no sight of your code. We talk to your agent the way an attacker would and write down everything it tries.


Single Probe Full Battery Fleet Probe
No credentials required Written rules of engagement first Full transcript, not a summary

Format

What this involves

Access needed
An endpoint, and written permission
Your time
About an hour, to agree scope
Runs in
2 to 5 days
Evidence
What the agent attempts
From
$1,200
01
The method

What we do without access

We run a battery of thirty to fifty adversarial prompts against your agent and record what it attempts. Not what it says — what it tries to do.

The battery covers six things: prompt injection, tool chaining, scope escalation, data exfiltration, instruction override, and identity impersonation. Each probe is written to test one specific failure, and each is recorded in full — the prompt, the response, and every tool call the agent attempted along the way.

You get the transcript. Not a summary of the transcript.

02
The limits, stated first

What this can and cannot tell you

We would rather you knew this before paying us.

  • It shows what your agent attempts.

    That is genuinely useful: an agent that reaches for a tool it was never told about has told you something important.

  • It cannot show what your agent is permitted to do.

    The credentials behind each tool carry a real permission set, and it is almost never the documented one. Seeing it needs read-only access to your configuration — that is the Read Only audit.

  • It cannot tell you whether your monitoring noticed.

    We can cross a boundary; we cannot see whether your alerts fired. That needs Proxy.

Black box is the fastest and least intrusive of the three, and the weakest evidence of the three. Both are true at once.

03
Before anything runs

Rules of engagement

Nothing runs until this is agreed in writing: the endpoints in scope, the time window, what we will not touch, the rate we will run at, and who to call if something behaves unexpectedly.

This is authorised security testing. It gets the same discipline as a penetration test, because it is the same kind of work. We will not probe a system on a verbal yes.

Three layers

What it costs

Fixed fee, agreed before anything starts. Nothing is charged until you have approved the scope in writing.

Single Probe

$1,200
one-off
2 days

One agent, core battery, a one-page read.

The right first step if you want to know whether there is anything here worth spending on.

  • Core probe battery
  • One-page read
  • Rules of engagement

Fleet Probe

$5,500
one-off
2 weeks

Up to five agents, run identically and compared.

When one base configuration was copied across teams and nobody is sure it stayed the same.

  • Everything in Full Battery, five times
  • Side-by-side comparison
  • Divergence findings

Any Black Box fee credits in full against a Read Only engagement within 90 days.

These are published fees, not estimates. Where an engagement genuinely does not fit one of the three, we will say so and quote the work rather than force it into a tier.

Accountability

Who signs it

Every report is signed by Brijesh Patel, ISO/IEC 42001 Lead Auditor, who performed the work.

Not a firm name on a template. A person, named, who read the evidence and reached the finding — and who can be asked about it afterwards.

There is no statute behind an agent audit. What makes the report worth anything is that a qualified human put their name on it and would say the same thing under questioning. That is the instrument.

The firms best placed to audit your agent are the firms that built it for you. A consultancy cannot independently assess work its own team implemented, and will not give up the implementation revenue to try. We do not build agents. That is the only reason this report is worth anything.

Fit

Who this is for

  • Teams whose agent is not yet in production
  • Teams who cannot grant access yet — procurement, security review, or simply not ready
  • Anyone wanting a first look before committing budget to a full audit

If your agent already handles customer data or money, start at Read Only instead. Black box will not tell you enough.

The three methods

If this is the wrong one

They differ by how much access you give us, and therefore by how strong the evidence is. More access, better evidence — there is no way around that trade.

Not sure which? Start with the eleven questions — how many you can answer tells you which method you need.

Before you ask

Questions

Will this break our production system?

We do not run against production unless it is named in the rules of engagement, and even then we agree a rate limit and a stop signal first. Most Black Box work runs against staging.

Do you need our code or our prompts?

No. That is the whole point of this tier. If you want us to read them, that is Read Only.

Is this a penetration test?

No. A pentest looks for vulnerabilities in your infrastructure. We look at what your agent will attempt when pushed. Different question, different report, and it does not replace a pentest.

What if it finds nothing?

Then that is the finding, and you get it in writing. We would rather hand you a clean transcript than manufacture a concern.

Next step

Request a Black Box audit

Two minutes. No account, and no call booked automatically. We reply within two working days with a scope and a fixed fee — or with an honest reason this is not the right method for you.

Start the request

Sources. Letter of 3 August 2026 from the Attorneys General of sixteen states to OpenAI, and Alabama Deceptive Trade Practices Act Subpoena Duces Tecum No. 26-0007. Both public. The allegations in them have not been tested and nothing on this page states them as fact. Primary documents last read by a human on 25 August 2026.