BLACK BOX · NO ACCESS REQUIRED · 2–5 DAYS

We need nothing from you but an endpoint and permission.

No credentials, no integration, no sight of your code. We talk to your agent the way an attacker would and write down everything it tries.


A reviewer with curly dark hair, in a charcoal blazer, a closed notebook at the edge of the desk, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
We watch what it reaches for, not what it says
One agent Each additional agent Annual renewal

Our promise

“An answer is a claim. The attempt is evidence.”

Every finding is written against a named control — defensible line by line, to anyone who asks. The fee is fixed at $8,500, and nothing is charged until you approve it.

Request this Black Box audit
The brief

Black Box, in three chapters

The Ask

Somebody has started asking what your agent will do when it is pushed - a customer’s security review, your own board, a procurement questionnaire that did not exist last year. The honest answer is that nobody has tried, because doing it properly means someone outside the team.

The Gap

The people who could answer fastest built it, so a review of your agent is a review of their own work. Meanwhile the access an outsider would need — credentials, configuration, traces — is what security will not release quickly. So the question sits unanswered for a quarter.

The Bench

This method needs none of it. Give us an endpoint and written permission and we talk to your agent as an attacker would, then hand you every prompt, response and tool call it attempted. Not a score or a summary — the transcript, and a written note of what it could not tell you.

What a probe is

A conversation your agent thinks is real.

Thirty to fifty adversarial prompts, and we record what it tries to do, not what it says.

What we send at it № 01
  • Instructions hidden in content it is asked to read
  • Two permitted tool calls composed into one that is not
  • Requests that reach past the task it was given
  • Attempts to move data out, and to act as someone else
Black Box · iDharma · Authorised probe
What comes back № 02
  • The prompt, the response and every tool call, in order
  • A one-page list of everything the agent reached for
  • Findings ranked by consequence, not by ease of fixing
  • A written note of what this method could not see
Black Box · iDharma · Authorised probe
Whose system is it

The agent is yours. The blind spot is theirs.

You

Whoever runs the agent

It answers on your endpoint, under your name, with your customers in front of it. Whatever it reaches for, it reaches for as you, and it reaches with whatever credentials you gave it. No statute assigns that - it is simply where the consequence lands, and it does not transfer to whoever wrote the code.

Your builder

The people who implemented it

Usually the best-informed readers of the system and often genuinely good engineers, and none of what follows is about their competence. The difficulty is simply that a review of your agent is a review of their own work, and the findings worth having are the ones that say the build itself was wrong.

The catch

Why that review is not independent

The firms best placed to audit your agent are the firms that built it for you, and they will not give up the implementation revenue in order to say so. We build no agents, we resell none, and no part of the fee moves with what the battery finds. That is the only reason this report is worth anything to you at all.

What most teams assume

“It only does the things we gave it tools for.”

What the transcript shows

It reaches for tools nobody documented.

It is the most common finding we write up.

  • Who it is for
  • Agent builders
  • AI product teams
  • Security & platform
  • Procurement & vendor risk
  • Anyone shipping a tool-using agent
Why this matters in 2026
A printed transcript held flat under a sheet of glass on a dark desk, a magnifier and a fountain pen laid across it, with one passage marked: the record of what a system attempted, read line by line after the fact.
01 Agents now hold real credentials and call real tools. What one reaches for stopped being a curiosity the moment it could spend money or move data on your behalf.
02

State enforcers have begun asking directly what these systems do - and nothing on the 3 August 2026 letter to OpenAI is specific to OpenAI.

03

A subpoena asks what you can produce, not what you believe. The transcript is producible; an assurance from the build team is not.

04

No statute requires an agent audit, and this page claims none. What makes the report worth anything is that a named person signed it.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. It can tell you to buy a different method.

0 of 3

Read-only access -

Today, not in principle. Config, credential scopes and traces. If that is a security review away, this method is the one that needs none of it.

Reaches something real -

This is the one that changes the answer. Where an agent can already move money or data, what it attempts stops being enough - you need to know what it is permitted to do.

Detection in question -

We can cross a boundary; we cannot see your alerts. If the question is whether anyone would have noticed, that needs a proxy sitting in the path.

The limits, stated first

What this can — and cannot — tell you

We would rather you knew this before paying us.

  1. It shows

    What it attempts

    That is genuinely useful on its own: an agent reaching for a tool it was never told about has told you something important.

  2. Not what it may do

    Read Only does

    The credentials behind each tool carry a real permission set, almost never the documented one. Seeing it needs read-only access.

  3. Not who noticed

    Proxy does

    We can cross a boundary, but we cannot see whether your alerts fired or whether anybody acted on them. That needs Proxy.

  4. Both at once

    The trade

    Fastest and least intrusive of the three, and the weakest evidence of the three. Both of those are true at the same time.

Before you pay

If either of the last two is your actual question, buy the method that answers it rather than this one: Read Only for what the credentials permit, Proxy for whether anyone noticed. Any Black Box fee credits in full against a Read Only engagement within 90 days. Each additional agent is $2,000; a re-audit after a change is $5,500. Starting here costs you the week, not the fee.

The engagement

Four moments, and the first one is paperwork.

Two to five days end to end, and about an hour of it is yours - but nothing runs until the authorisation is signed.

  1. Scope

    About an hour

    One call to agree what is in scope and what is off limits. Your time on this engagement is close to all of it.

  2. Authorise

    Before we start

    Rules of engagement signed - endpoints, window, rate and stop signal. We will not probe a system on a verbal yes.

  3. Probe

    2 to 5 days

    The battery runs against the named endpoints at the agreed rate, and every attempt is recorded live.

  4. Credit

    Within 90 days

    The whole fee comes off a Read Only engagement, so a first look never becomes the reason you stopped there.

The rule

Nothing runs until this is agreed in writing: the endpoints in scope, the time window, what we will not touch, the rate we will run at, and who to call if something behaves unexpectedly. This is authorised security testing, and it gets the same discipline as a penetration test because it is the same kind of work.

Coverage & evidence

What we probe, what lands in your hand

12 rows, and the artefact that evidences each one. Paired, so every claim on this page can be checked against the probe beside it.

What we need from you An endpoint, and written permission
No credentials, no integration, no repository access and no sight of your prompts - the tier is defined by what it does without.
Authorisation Signed before anything runs
Rules of engagement naming the endpoints in scope, the window, the rate we run at, what we will not touch, and who to call.
Prompt injection Instructions smuggled into content it reads
Every injection attempted, the exact string used, and what the agent did with it - verbatim, not characterised.
Tool chaining Two permitted calls composed into one that is not
The chains attempted in order, each tool call recorded as the agent made it rather than as the spec describes it.
Scope escalation Reaching past the task it was given
Each attempt to widen its own remit, the prompt that produced it, and how far it got before anything stopped it.
Data exfiltration Moving data somewhere it should not go
Every attempt to route data outward, recorded whether or not it succeeded - the reach is the finding, not the result.
Instruction override Being talked out of its own system prompt
What it took to move the agent off its instructions, how far it moved, and whether it ever moved back on its own.
Identity impersonation Acting as a person or a role it is not
Every attempt to assume an identity, with the response recorded in full so you can judge it rather than take our word.
The record itself Recorded, never summarised
The complete transcript - prompt, response, and every tool call the agent attempted, in the order they happened.
What it is permitted to do Out of scope here - it needs your configuration
Written into the report as a limit, with the Read Only audit named as the method that answers it. We do not guess at it.
Whether monitoring noticed Out of scope here - it needs your telemetry
Written into the report as a limit, with the Proxy audit named as the method that answers it. We cannot see your alerts.
Who signed it A named lead auditor, not a firm on a template
A report carrying the name of the person who ran the battery, and who can be asked about any line in it afterwards.
How it runs

Your agent, independently probed

From a single assistant to a fleet of five.

  1. Authorise

    Endpoints, window, rate and stop signal - agreed in writing first.

  2. Probe

    Thirty to fifty adversarial prompts, each one recorded in full.

  3. Hand over and debrief

    The transcript first. Then the findings and the attempted-action list.

Request this audit
An auditor in a light grey trouser suit over a white T-shirt, with long dark hair, standing against a warm pale wall and pointing into the open space alongside.
The transcript is not negotiable - that is what you are buying.
Struck in your favour

Why teams choose iDharma for a first look

Genuinely independent

We build, resell and operate no agents of our own, and take no fee tied to what the battery finds.

Transcript, not summary

You get the record itself - prompt, response and tool call - not our characterisation of it.

Written before we start

Scope, rate and stop signal are signed first. We will not probe a system on a verbal yes.

It credits forward

The whole fee comes off a Read Only engagement inside 90 days, so a first look costs nothing.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

The probe transcript

The whole run, exactly as it happened.

Every prompt we sent, every response the agent gave and every tool call it attempted in between - across all six families, in order, recorded in full rather than characterised.

List

Attempted-action list

Everything the agent reached for, lifted out of the transcript onto one page - the part most teams read first and circulate furthest.

Report

Written findings

What the attempts mean, ranked by consequence rather than by how easily they are fixed, and signed by the person who ran the battery.

Signed

Rules of engagement

The authorisation itself, countersigned and dated - endpoints, window, rate, exclusions and the stop signal, kept as a record of consent.

Method

The battery, itemised

Which probes ran, in which family, and why each was written - so a reviewer can judge the coverage instead of taking a total on trust.

Each additional agent

Divergence comparison

Where one base configuration was copied across teams, the same battery against each - and the places they have quietly stopped matching.

Memo

Method recommendation

Whether what we found needs Read Only or Proxy to take further - and, when it does not, that in writing too rather than an upsell.

Format & fee

Real numbers, upfront.

One agent
One agent, the complete adversarial battery, full transcript. $8,500 2 to 5 days
Each additional agent
Every further agent tested under the same rules of engagement. $2,000 in the same engagement
Annual renewal
The same audit a year on, against a known baseline. $7,200 locked at this price

Any Black Box fee credits in full against a Read Only engagement within 90 days. Each additional agent is $2,000; a re-audit after a change is $5,500. Published, not estimated.

Request this audit
Black Box · One agent $8,500 one-off
  • Complete probe battery
  • Full transcript, not a summary
  • Attempted-action list
  • Findings signed by a named auditor
Show your hand

Four things this method puts on the table

A first look is not graded on intent either. Each of these is either in your hand at the end of the week, or it is not.

The permission,
signed

Rules of engagement naming the endpoints in scope, the window, the rate and the stop signal. This is authorised security testing, and the paperwork is what makes it so.

The transcript,
whole

Every probe as it ran - the prompt, the response, and each tool call attempted along the way. The record is the evidence, not our reading of the record afterwards.

The attempts,
listed

What the agent reached for, pulled out of the transcript and set down as a list. An agent reaching for a tool nobody documented is the usual finding, not the rare one.

The limits,
stated

What this method could not see, written into the report rather than left out of it - and which of the other two answers each one. Nobody has to ask us for it.

Four cards, and the fourth is the one nobody else deals you.

Accountability

Who signs it

The signature

A named person, not a firm

Every report is signed by Brijesh Patel, ISO/IEC 42001 Lead Auditor, and signed by the person who ran the probes rather than whoever sold the engagement. One name and one credential against the findings, and the same person is still there when your board asks about them a quarter later.

The evidence

The transcript, not a score

A signature is worth only what stands behind it, so you are handed every prompt, response and tool call the agent attempted - not a grade, not a dashboard and not a summary of our reasoning. Anything asserted here can be re-read by somebody who was not there, and disagreed with on the record.

The catch

No statute stands behind it

No law requires an agent audit, so nothing external makes this report count for you. It is also the fastest and least intrusive of the three methods and, for that same reason, the weakest evidence of the three. What is left holding it up is a name, a credential, and somebody who has to answer for both.

Not this

A firm’s name on a template, and nobody to ask.

This

A person, named, who answers for the finding.

No statute requires an agent audit. The signature is the instrument.

FAQ

Plain answers

Production, code, pentests and nothing found. Answered straight.

Request this audit
Will this break our production system?

We do not run against production unless it is named in the rules of engagement, and even then we agree a rate limit and a stop signal first. Most Black Box work runs against staging.

Do you need our code or our prompts?

No. That is the whole point of this tier. If you want us to read them, that is Read Only.

Is this a penetration test?

No. A pentest looks for vulnerabilities in your infrastructure. We look at what your agent will attempt when pushed. Different question, different report, and it does not replace a pentest.

What if it finds nothing?

Then that is the finding, and you get it in writing. We would rather hand you a clean transcript than manufacture a concern.

If it cannot show what our agent is permitted to do, why buy it?

Because it is the only one of the three that needs nothing from you, and what an agent reaches for is a finding on its own. A transcript showing it attempting actions nobody documented has told you something real before procurement has even finished. If you can grant read-only access today, buy Read Only instead - the fee credits either way.

Next step

Request a Black Box audit

Two minutes. No account, and no call booked automatically. We reply within two working days.

What we need from you

Less than any other engagement. No credentials, no integration, no sight of your code — and you see the rules of engagement before you commit.

  1. An endpoint we can reach, and who owns it
  2. Written permission from someone able to give it
  3. Staging or production, and the rate we may run at
  4. Anything that must not be touched, named explicitly
  5. Who to call if the agent behaves unexpectedly

What happens next

  1. You send the five items above.
  2. We send scope and a fixed fee in two working days.
  3. You sign the rules of engagement before we run.
Start the request
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Attorneys General of sixteen states, to OpenAI
  • Alabama DTPA subpoena, No. 26-0007
Letter dated
3 August 2026
Last read
25 August 2026

What it means

  • Both documents are public. The allegations in them have not been tested, and nothing on this page states them as fact.
  • No statute requires an agent audit, and no part of this page implies that one does.

Scope & limitation

  • This method shows what an agent attempts. It cannot show what it is permitted to do, or whether anyone noticed.
  • It is not a penetration test and does not replace one. Different question, different report.

Something on this page out of date?

Tell us
Schedule of requests

Eleven questions. Pointed at you.

No email. No signup. Nothing is sent until you choose to send it.

Where the eleven come from

Not our list. On 3 August 2026 the Attorneys General of sixteen states wrote to OpenAI and named eleven categories of material to preserve. Each one is turned round here — from preserve this into could you produce this — and nothing else about it is changed. Nothing on the list is specific to OpenAI: an organisation running agents either holds these records or it does not.

The allegations behind the letter have not been tested, and nothing here states them as fact. It is used as what it is — a published account of what somebody with subpoena power thought worth asking for.

0 of 11

The incident record -

What a no means. No per-action trace. A summary is not a record.

How you found out -

What a no means. No independent detection. Discovery depends on a third party.

Which model ran -

What a no means. Model provenance not recorded per run.

Your own review -

What a no means. No written review, or a review that diverges from public statements.

Credential use -

What a no means. Credential discovery and reuse is untracked.

Offensive evaluations -

What a no means. Offensive testing runs without a named authoriser.

Prior incidents -

What a no means. No incident history. "None that we know of" is not an answer.

Self-persistence -

What a no means. Agent-written artefacts are not inspected.

Evaluation safety policy -

What a no means. No dated policy. A policy written after the fact proves nothing.

Concerns raised -

What a no means. Internal concerns are discoverable and unmanaged. Usually the sharpest exposure.

Who knew -

What a no means. No named custodians.

Request an audit

Send the eleven with your enquiry

Whatever you answered above travels with this form. Nothing is scored, ranked or published.

What we need from you

Nothing you do not already have. Most of this is what your own team knows about the agents you run, and we name what we need in writing before you commit to anything.

  1. Which agents you run, and what each one decides
  2. How many there are, and whether any are in production
  3. What each can reach - tools, APIs, the data behind
  4. Whether it acts under its own identity or a person's
  5. Your target date for a read, if you have one

What happens next

  1. You send this, with whatever you answered above.
  2. We read it and reply within two working days.
  3. Nothing is charged until you approve the scope.

Your answers to the eleven will be attached.

Request an agent audit

Send your enquiry

Six fields and two boxes, only three of them required, and nothing to attach.

Your answers to the eleven will be attached.