Sensitive data flows
Can attacker-controlled input make the agent send sensitive data out?
- Customer record
- Report creation
- External message
Adversarial testing of your agent’s tools, authority, and action paths.
What Themis tests
Can attacker-controlled input make the agent send sensitive data out?
Can one record turn into access to many?
Can the agent act without the approval it should need?
Can individually allowed steps combine into an unsafe outcome?
Can attacker input change the intended recipient or destination?
How it works
Connect the agent’s action boundary.
Map available tools and capabilities.
Confirm what the agent is allowed to do.
Run adversarial scenarios.
Receive findings and evidence.
Themis generates the initial capability and authority model. Your team confirms it.
Sample reports
Confirmed finding
See what a confirmed security finding looks like.
View sampleNo major issue found
See what you receive when no major issue is found.
View sampleReal reports generated from the Themis reference-agent assessment pipeline.
The Themis assessment engine has been evaluated against AgentDojo, AgentHazard, and a live MCP-based AI agent.
For a standard assessment.
State changes can be verified when a sandbox is provided.
What you get
If no major issue is found, you receive an Assessment Coverage Report.
What next
Neither is required. They solve different problems: runtime authorization of live actions, and re-testing as the agent changes.
FAQ
A way for Themis to reach the agent's tool-calling boundary (MCP is one currently supported path), a test environment or test accounts for it to act in, and someone on your team to confirm the generated authority draft. Test credentials are scoped to that environment.
No. A standard assessment can use staging systems, test accounts, synthetic data, and sandboxed integrations.
You receive an Assessment Coverage Report documenting what was tested, the evidence obtained, and the assessment limits.
Repeated actions that only cross a limit in combination are not currently evaluated. Multi-agent systems are outside the standard assessment path.
Timing is confirmed during technical preflight once the connection path and test environment are known.
Assessment data is used to perform the agreed security evaluation. Access, retention, and handling of customer data are defined as part of the engagement.
Where agreed, Themis may retain generalized or de-identified security knowledge such as:
We do not treat customer confidential information as reusable product data.
Credentials. Test credentials should be scoped to the agreed assessment environment and permissions.
Answer four short questions. We’ll tell you if the current assessment path fits your agent.
Check support