Engagements
Engagements
Scoped to how far along your agent adoption is. Pricing is quoted per engagement after a short discovery call — no two agent stacks are alike.
Starter Assessment
Small teams exploring agent security.
Contact for quote
- Intake questionnaire
- 30-minute call
- High-level risk report
- Recommended next steps
Team Assessment
Teams actively using coding agents or MCP servers.
Contact for quote
- Repo / config review
- MCP / config review
- Workflow mapping & risk scoring
- Detailed report + 60-minute review call
Secure Setup
Teams that want implementation help.
Contact for quote
- Sandbox / devcontainer setup
- Permission policy baseline
- Logging & kill-switch pattern
- Team usage guide + follow-up support
Prefer to talk first? Book a discovery call.
Questions
FAQ
Is this a penetration test?
No. This is an advisory assessment of your own approved systems, configurations, workflows, and agent usage. It is not unauthorized testing or exploit development.
Do you need access to our code?
Often a read-only or scoped, temporary view is enough — and frequently we can work from configs and a walkthrough. Access is handled case-by-case and you control removal.
What tools do you support?
Claude Code, OpenAI Codex, Cursor, GitHub Copilot agents, local agents, MCP servers, RAG/chatbots, and custom internal AI workflows.
Do you test production systems?
We focus on configuration, workflow, and access review. We do not run intrusive tests against production unless you explicitly scope and authorize it.
How long does an assessment take?
A Starter Assessment is typically a few days; a Team Assessment usually runs one to two weeks depending on the size of your agent footprint.
Do you store customer data?
We store the contact details you submit so we can follow up. Please do not send secrets, credentials, or sensitive code through forms or email. Reports can be deleted on request.
Can you help us implement fixes?
Yes. The Secure Setup engagement is done-for-you implementation: sandboxing, permission baselines, logging, and kill-switch patterns.
Is this only for software companies?
No. Any team connecting AI to Slack, email, docs, GitHub, databases, or customer data has agent-security exposure worth reviewing.
What is MCP security?
MCP (Model Context Protocol) servers give agents tools and data. Each connected server is part of your supply chain — its provenance, permissions, and tool descriptions all affect what an agent can be tricked into doing.
What happens after the assessment?
You get a prioritized remediation plan and a review call. From there you can implement fixes yourself, engage us for Secure Setup, or join the scanner waitlist for ongoing monitoring.
Find out what your agents can actually reach.
Start with an assessment, or book a 30-minute discovery call to talk through your setup. No code or secrets required to get started.