Adversarial Testing
A website, a piece of software, or an agent that is already live. We look from the outside, with a login, or at what the agent will give up, and we write down what gave way. The packet is dated and scoped. We do not promise the system is clean. Nothing probes until the target is confirmed yours, in writing.
What's in scope.
The boundary of the engagement is set in writing before work begins.
A website, a piece of software, or an agent that is already live. We look from the outside, with a login, or at what the agent will give up, and we write down what gave way. The packet is dated and scoped. We do not promise the system is clean. Nothing probes until the target is confirmed yours, in writing.
Nothing probes until the target is confirmed yours, in writing. The packet is dated and scoped. We do not promise the system is clean.
How a test runs.
The same rule on every surface. The depth is the one you asked for.
Yours, in writing, before anything probes.
We confirm the target is yours. Reconnaissance that only observes what is already public can start then. Anything that probes waits for a signed statement of work.
The depth you asked for.
Outside-in is the external exposure report. Signed in, or with the source, is software assurance. A live agent is its own engagement: one public surface or one role.
A dated packet, not a certificate.
You leave with what we tried, what we found, and the step that closes it. One retest of those fixes is included when the subject is one agent. We do not certify the system.
What you'll receive.
The external exposure report, $3,000. What a stranger can already see. The account of that look stays on the exposure report.
Software assurance. $6,500 to open, then $165 an hour. The signed statement of work names the depth.
One live agent
Current rateOne agent, one public surface or one role, $8,000. Prompt injection, tool misuse, and what it gives up. A written packet, and one retest of the fixes. A wider surface uses Software & AI Automation terms: $10,000 to open, then $220 an hour.
One live agent, one public surface or one role, $8,000. Current rate. We confirm it on the invoice before any work starts. The figure can change until that invoice is sent. A wider surface uses Software & AI Automation terms.
$8,000 fixed
Common questions.
- What do you test?
- A website, a piece of software, or an agent that is already live. From the public internet, the external exposure report is $3,000. With a login or with the source, software assurance opens on Software Development terms, $6,500 then $165 an hour. One live agent is $8,000.
- How much does a test of one live agent cost?
- $8,000 for one agent, one public surface or one role, a written packet, and one retest of the fixes. Current rate. We confirm it on the invoice before any work starts. The figure can change until that invoice is sent. A second agent, or an agent with many tools and other agents behind it, uses Software & AI Automation terms: $10,000 to open, then $220 an hour.
- Is this a penetration test?
- The word belongs in the signed statement of work when that is the engagement. Black box, grey box, and white box stay on software assurance. A live agent is its own engagement. We do not put the word on a scan PDF.
- Do you promise the system is clean?
- No. You get a dated, scoped packet: what we tried, what we found, and the step that closes it. Nothing probes until the target is confirmed yours, in writing.