AI Agent Security Assessment

See what an attacker can make your agent do.

Adversarial testing of your agent’s tools, authority, and action paths.

Pricing
From $5,000 per agent
Scope
One agent · One supported test environment · Up to 300 adversarial executions

Five ways agents can cross boundaries.

Sensitive data flows

Can attacker-controlled input make the agent send sensitive data out?

  1. Customer record
  2. Report creation
  3. External message

Scope expansion

Can one record turn into access to many?

  1. Current customer
  2. Customer directory

Approval bypass

Can the agent act without the approval it should need?

Refund ≤ $500
Automatic
Refund > $500
Approval required

Unsafe action chains

Can individually allowed steps combine into an unsafe outcome?

  1. READ
  2. TRANSFORM
  3. SEND

Destination substitution

Can attacker input change the intended recipient or destination?

  1. Address on file
  2. Attacker-supplied address

Connect → Discover → Confirm → Test → Report

  1. 01

    Connect

    Connect the agent’s action boundary.

  2. 02

    Discover

    Map available tools and capabilities.

  3. 03

    Confirm

    Confirm what the agent is allowed to do.

  4. 04

    Test

    Run adversarial scenarios.

  5. 05

    Report

    Receive findings and evidence.

Themis generates the initial capability and authority model. Your team confirms it.

See the assessment output.

Confirmed finding

Sample Finding Report

See what a confirmed security finding looks like.

View sample

No major issue found

Sample Clean Report

See what you receive when no major issue is found.

View sample

Real reports generated from the Themis reference-agent assessment pipeline.

The Themis assessment engine has been evaluated against AgentDojo, AgentHazard, and a live MCP-based AI agent.

Safe testing

Sensitive actions can be intercepted

Staging and test environments are supported

Production access is not required

For a standard assessment.

State changes can be verified when a sandbox is provided.

Everything needed to act.

  • Capability map
  • Authority baseline
  • Security findings
  • Evidence
  • Remediation guidance
  • Regression check

If no major issue is found, you receive an Assessment Coverage Report.

Common questions

What agents are supported?

A way for Themis to reach the agent's tool-calling boundary (MCP is one currently supported path), a test environment or test accounts for it to act in, and someone on your team to confirm the generated authority draft. Test credentials are scoped to that environment.

Does Themis need production access?

No. A standard assessment can use staging systems, test accounts, synthetic data, and sandboxed integrations.

What happens if nothing serious is found?

You receive an Assessment Coverage Report documenting what was tested, the evidence obtained, and the assessment limits.

What is not covered in the current version?

Repeated actions that only cross a limit in combination are not currently evaluated. Multi-agent systems are outside the standard assessment path.

How long does an assessment take?

Timing is confirmed during technical preflight once the connection path and test environment are known.

How we handle assessment data

Assessment data is used to perform the agreed security evaluation. Access, retention, and handling of customer data are defined as part of the engagement.

Where agreed, Themis may retain generalized or de-identified security knowledge such as:

  • attack patterns
  • authority abstractions
  • semantic mappings
  • false-positive patterns
  • methodology improvements

We do not treat customer confidential information as reusable product data.

Credentials. Test credentials should be scoped to the agreed assessment environment and permissions.

Check if your agent is supported

Answer four short questions. We’ll tell you if the current assessment path fits your agent.

Check support