Research & Advisory

For unusual architectures, systems the standard assessment does not yet support, threat modelling, deeper or manual security research, and custom questions.

Expert service · Scoped engagement

Some questions do not fit a standard assessment.

The AI Agent Security Assessment covers a defined set of action-boundary tests for supported agents. Some systems, and some questions, need a researcher.

The agent uses a tool-calling architecture the standard assessment does not observe today.
The system is multi-agent, custom-orchestrated, or otherwise unusual.
You need a threat model before deciding what to build or test.
A specific incident, failure mode, or design question needs manual investigation.

What we take on

Scoped per engagement.

Unusual architectures
Multi-agent, custom orchestration, non-standard tool frameworks.
Unsupported systems
Agents outside the current assessment path, reviewed manually.
Threat modelling
Assets, actors, and outcomes worth preventing, written down.
Manual security research
Deeper investigation of a specific system, failure mode, or question.
Custom questions
Questions that do not map to a defined product.

How an engagement runs

Scoped up front; researcher-led; delivered as written findings.

01
Scope
We agree the question, the system boundary, and the deliverable.
02
Research
Manual analysis and, where a system is available, controlled testing under agreed Rules of Engagement.
03
Deliver
Written findings and recommendations, with limitations stated.

What you receive

Written findings
The answer to the scoped question, with evidence and limitations.
Recommendations
What to change, and why.

Expert services are optional additional capacity, not a tier of the AI Agent Security Assessment.

Why Themis

Security research background
PhD-level security research with peer-reviewed work at IEEE S&P and ACM CCS.
Authority-centred method
The same thesis behind the assessment: authority, not just prompts.
Honest limits
Findings state what was and was not established.

Questions we get asked

Is my agent unsupported?

Use the support check. If the standard assessment path does not observe your tool-calling architecture today, we say so and can scope manual research instead.

Do you publish research from engagements?

Not without written consent. Public research is published separately at /research.

Have a question that does not fit a product?

Tell us the system and the question. We will scope it or tell you it is not a fit.