Frequently Asked Questions
Scope, safeguards, evidence, deliverables, and engagement terms.
Before commissioning a diagnostic.
We define the service boundaries and limitations clearly before testing.
Is this a general AI model evaluation?
No. We do not grade knowledge, writing, translation, or benchmark performance. We test whether the connected agent stays within authorization, data, action, tool, and destination boundaries.
How is this different from penetration testing?
The emphasis is on unexpected reachability through legitimate users, legitimate features, and legitimate integrations rather than exploiting a software vulnerability.
Can testing be performed in production?
Yes, when targets, timing, stop conditions, recovery, dedicated accounts, and approvals are agreed in advance. Test or mock environments are preferred.
Do you require production API keys or full logs?
Not by default. Mock data, dedicated accounts, short-lived credentials, and targeted evidence are preferred.
What do the findings include?
The tested request, expected and actual behavior, boundary crossed or preserved, prerequisites, repeatability, evidence, business impact, and remediation priority.
Does the service certify that the system is safe?
No. It verifies agreed scenarios under the documented configuration, permissions, model, and date. Changes may require retesting.
Are NDAs supported?
Yes. A non-disclosure agreement can be completed before detailed system information is shared.
A high-level description is enough for an initial discussion.
Tell us the agent purpose, users, connected systems, and boundary concerns.