We need nothing from you but an endpoint and permission.
No credentials, no integration, no sight of your code. We talk to your agent the way an attacker would and write down everything it tries.
Format
What this involves
- Access needed
- An endpoint, and written permission
- Your time
- About an hour, to agree scope
- Runs in
- 2 to 5 days
- Evidence
- What the agent attempts
- From
- $1,200
What we do without access
We run a battery of thirty to fifty adversarial prompts against your agent and record what it attempts. Not what it says — what it tries to do.
The battery covers six things: prompt injection, tool chaining, scope escalation, data exfiltration, instruction override, and identity impersonation. Each probe is written to test one specific failure, and each is recorded in full — the prompt, the response, and every tool call the agent attempted along the way.
You get the transcript. Not a summary of the transcript.
What this can and cannot tell you
We would rather you knew this before paying us.
-
It shows what your agent attempts.
That is genuinely useful: an agent that reaches for a tool it was never told about has told you something important.
-
It cannot show what your agent is permitted to do.
The credentials behind each tool carry a real permission set, and it is almost never the documented one. Seeing it needs read-only access to your configuration — that is the Read Only audit.
-
It cannot tell you whether your monitoring noticed.
We can cross a boundary; we cannot see whether your alerts fired. That needs Proxy.
Black box is the fastest and least intrusive of the three, and the weakest evidence of the three. Both are true at once.
Rules of engagement
Nothing runs until this is agreed in writing: the endpoints in scope, the time window, what we will not touch, the rate we will run at, and who to call if something behaves unexpectedly.
This is authorised security testing. It gets the same discipline as a penetration test, because it is the same kind of work. We will not probe a system on a verbal yes.
Three layers
What it costs
Fixed fee, agreed before anything starts. Nothing is charged until you have approved the scope in writing.
Single Probe
One agent, core battery, a one-page read.
The right first step if you want to know whether there is anything here worth spending on.
- Core probe battery
- One-page read
- Rules of engagement
Full Battery
One agent, complete battery, full transcript.
When you need the whole picture of what the agent will reach for under pressure.
- Complete probe battery
- Full transcript
- Attempted-action list
- Written findings
Fleet Probe
Up to five agents, run identically and compared.
When one base configuration was copied across teams and nobody is sure it stayed the same.
- Everything in Full Battery, five times
- Side-by-side comparison
- Divergence findings
Any Black Box fee credits in full against a Read Only engagement within 90 days.
These are published fees, not estimates. Where an engagement genuinely does not fit one of the three, we will say so and quote the work rather than force it into a tier.
Accountability
Who signs it
Every report is signed by Brijesh Patel, ISO/IEC 42001 Lead Auditor, who performed the work.
Not a firm name on a template. A person, named, who read the evidence and reached the finding — and who can be asked about it afterwards.
There is no statute behind an agent audit. What makes the report worth anything is that a qualified human put their name on it and would say the same thing under questioning. That is the instrument.
Fit
Who this is for
- Teams whose agent is not yet in production
- Teams who cannot grant access yet — procurement, security review, or simply not ready
- Anyone wanting a first look before committing budget to a full audit
If your agent already handles customer data or money, start at Read Only instead. Black box will not tell you enough.
The three methods
If this is the wrong one
They differ by how much access you give us, and therefore by how strong the evidence is. More access, better evidence — there is no way around that trade.
Black Box
No credentials, no integration, no sight of your code. We talk to your agent the way an attacker would and write down everything it tries.
Read Only
The two lists are never the same, and almost nobody has ever put them side by side. This is the audit that does.
Proxy
Most teams find out from someone outside. This is the tier that changes that.
Not sure which? Start with the eleven questions — how many you can answer tells you which method you need.
Before you ask
Questions
Will this break our production system?
We do not run against production unless it is named in the rules of engagement, and even then we agree a rate limit and a stop signal first. Most Black Box work runs against staging.
Do you need our code or our prompts?
No. That is the whole point of this tier. If you want us to read them, that is Read Only.
Is this a penetration test?
No. A pentest looks for vulnerabilities in your infrastructure. We look at what your agent will attempt when pushed. Different question, different report, and it does not replace a pentest.
What if it finds nothing?
Then that is the finding, and you get it in writing. We would rather hand you a clean transcript than manufacture a concern.
Next step
Request a Black Box audit
Two minutes. No account, and no call booked automatically. We reply within two working days with a scope and a fixed fee — or with an honest reason this is not the right method for you.
Sources. Letter of 3 August 2026 from the Attorneys General of sixteen states to OpenAI, and Alabama Deceptive Trade Practices Act Subpoena Duces Tecum No. 26-0007. Both public. The allegations in them have not been tested and nothing on this page states them as fact. Primary documents last read by a human on 25 August 2026.