Would you know if your agent left?
Most teams find out from someone outside. This is the tier that changes that.
Format
What this involves
- Access needed
- A proxy between agent and tools
- Your time
- Half a day to deploy, then none
- Runs in
- Continuous
- Evidence
- What the agent is doing now
- From
- $6,500
One fact, stated plainly
In their letter of 3 August 2026, sixteen State Attorneys General state that during July 2026 testing an OpenAI agent escaped what should have been an isolated environment and conducted a multi-day intrusion — and that OpenAI was unaware its agent had escaped until Hugging Face detected the intrusion and reported it.
We have not verified those events and we do not repeat them as fact. The allegations have not been tested.
But the question they raise is a fair one to ask of any agent, and it is not a question about OpenAI.
How the capture works
We sit between your agent and its tools and record every call it makes.
-
What we log
The call, its arguments, the tool that received it, the response, the identity it ran under, and the timestamp.
-
What we do not log
Anything you exclude in the scoping document. Fields, tools and paths can be redacted at the proxy before anything is written.
-
Where it is stored
In the region you specify, encrypted, for the retention period you set. Default is 90 days, and you can set it shorter.
-
How it comes out
You can export or delete the entire capture at any time. Termination deletes it within 30 days.
What we take on when we do this
Sitting in your call path makes us a data processor. That is a real obligation, so here is what it means rather than a reassurance that it is fine.
-
A data processing agreement
Signed before anything is deployed.
-
A stated retention period
Set by you, not by us.
-
A defined breach notification duty
With a named contact and a stated timeframe.
-
Our own security posture, in writing
Including where we are, and are not, independently assessed.
We audit other people's systems for a living. It would be incoherent to ask for access to yours without saying what we do with it.
What continuous capture catches that the other two cannot
-
Boundary crossings, as they happen
Not reconstructed afterwards from logs that may not exist.
-
Credential use in real time
Including credentials the agent found rather than was given.
-
Monitoring being disabled
An agent that can reach the thing watching it is a specific and testable risk.
-
Behaviour drift between releases
The same agent, doing different things, after a change nobody flagged.
Black Box shows what your agent attempts once. Read Only shows what it is permitted to do. Only continuous capture shows what it is doing now.
The quarterly certificate
-
What it says
The period covered, the agents in scope, the capability boundary as it stood, what was observed against it, what changed since the last certificate, and the auditor's signature.
-
What it does not say
That you are compliant with anything, that your agent is safe, or that nothing will go wrong.
-
Who it is for
A customer's security review, an insurer, a board paper, or your own record. It is evidence, not a claim.
Three layers
What it costs
Fixed fee, agreed before anything starts. Nothing is charged until you have approved the scope in writing.
Capture Window
Fourteen days of recorded traffic and one report.
The right way to try this before committing to anything ongoing.
- 14 days continuous capture
- One written report
- Export of the full capture
Standing Assay
Continuous capture, certificate re-issued every quarter.
Agents in production where somebody has to be able to answer for them.
- Continuous capture
- Quarterly signed certificate
- Change findings each quarter
- Cancel at the end of any quarter
Programme
Continuous capture, a monthly review call, an annual certificate.
When the agents are a board-level question rather than an engineering one.
- Everything in Standing Assay
- Monthly review call
- Annually re-issued certificate
- Named auditor on call
A Capture Window credits in full against the first quarter of a Standing Assay.
These are published fees, not estimates. Where an engagement genuinely does not fit one of the three, we will say so and quote the work rather than force it into a tier.
Accountability
Who signs it
Every report is signed by Brijesh Patel, ISO/IEC 42001 Lead Auditor, who performed the work.
Not a firm name on a template. A person, named, who read the evidence and reached the finding — and who can be asked about it afterwards.
There is no statute behind an agent audit. What makes the report worth anything is that a qualified human put their name on it and would say the same thing under questioning. That is the instrument.
Fit
Who this is for
- Agents in production touching customer data, money, or systems that matter
- Teams that have already had a near miss
- Anyone whose board has asked the question in the headline and did not like how long the answer took
The three methods
If this is the wrong one
They differ by how much access you give us, and therefore by how strong the evidence is. More access, better evidence — there is no way around that trade.
Black Box
No credentials, no integration, no sight of your code. We talk to your agent the way an attacker would and write down everything it tries.
Read Only
The two lists are never the same, and almost nobody has ever put them side by side. This is the audit that does.
Proxy
Most teams find out from someone outside. This is the tier that changes that.
Not sure which? Start with the eleven questions — how many you can answer tells you which method you need.
Before you ask
Questions
What does this do to latency?
Single-digit milliseconds per call in normal operation. We measure it during onboarding and give you the number for your own environment before you commit.
What happens if you go down?
Fail-open by default: if the proxy is unavailable, calls pass through unrecorded and we tell you there is a gap in the record. Your agent keeps working. You can choose fail-closed instead, and we will make sure you understand what that means before you do.
Can we turn it off?
Yes, at any time, without asking us. It is your infrastructure.
Who can see the recordings?
Named auditors on your engagement, and nobody else. The list of names is in the data processing agreement and you are told when it changes.
Next step
Request a Proxy audit
Two minutes. No account, and no call booked automatically. We reply within two working days with a scope and a fixed fee — or with an honest reason this is not the right method for you.
Sources. Letter of 3 August 2026 from the Attorneys General of sixteen states to OpenAI, and Alabama Deceptive Trade Practices Act Subpoena Duces Tecum No. 26-0007. Both public. The allegations in them have not been tested and nothing on this page states them as fact. Primary documents last read by a human on 25 August 2026.