Engagements

Priced per engagement, agreed before we start

Three ways to work with us. Each is a fixed fee for a scope we agree in writing, and most teams start with one agent and widen from there.

Fixed fee, 3-4 weeks

Assessment

Find out what your agents can do

An adversarial assessment of one agent or a small fleet, across permissions, tool use, prompt-injection exposure and data leakage.

  • Inventory workshop and agent threat model
  • Hands-on adversarial testing across all four domains
  • A prompt-injection corpus built from your own untrusted inputs
  • Ranked findings with reproductions and evidence
  • An executive briefing plus a technical appendix
  • A sequenced remediation plan your engineers can act on
Scope an assessment
Most common

Fixed fee, 5-8 weeks

Assess + remediate

Close the findings, then prove it

The assessment, plus hands-on remediation with your engineers and a verification re-test that shows each attack failing.

  • Everything in the Assessment
  • Fixes implemented as pull requests and configuration in your repos
  • Least-privilege identities and just-in-time credentials for agents
  • Tool guardrails, approval gates and egress controls
  • A verification re-test showing the before and after for each finding
  • The regression attack suite handed over, plus a team enablement session
Scope an engagement

Annual, built on your baseline

Continuous assurance

Keep it true as the agents change

Ongoing monitoring and testing so a tool added on Monday does not quietly undo the work.

  • Everything in Assess + remediate
  • Live agent, tool and data-source inventory with drift alerts
  • Your attack suite running as a gate in CI
  • Runtime anomaly signal on tool chains and egress
  • A quarterly red-team refresh as new attack classes appear
  • Evidence exports for customer security reviews and auditors
Talk to us

Not sure which one you need?

Start with a 30 minute scoping call. No charge and no obligation. We walk through your agent architecture and tell you where the exposure probably sits.

Book the call
Compare

What each engagement covers

CapabilityAssessmentAssess + remediateContinuous assurance
Agent, tool and data inventory
Adversarial testing across four domains
Ranked findings with reproductions
Remediation plan
Fixes implemented with your engineers
Verification re-test
Regression suite handed over
Drift alerts on new tools and scopes
Attack suite running in CI
Runtime anomaly signal
Quarterly red-team refresh
Evidence exports for auditsOn request
What moves the number

How an engagement gets priced

So the number on your proposal is not a surprise.

01

How many agents, and how coupled

One customer-facing agent is a different job from twelve that call each other. We scope by agent and by the tool surface behind it.

02

The size of the tool surface

Ten tools with tight schemas take less time than sixty tools, three MCP servers and a code interpreter.

03

Which environment we test

A faithful staging replica is the fastest path. Testing in production takes longer because it runs under tighter rules of engagement.

04

How far remediation goes

Advisory support costs less than our engineers writing, reviewing and shipping the fixes alongside yours.

05

Evidence requirements

If findings feed a customer security review, an audit or a regulatory filing, expect extra time on documentation.

Commercials

Common questions

Get a scope and a number

Tell us what your agents do and what they can reach. You get a written scope and a fixed fee, usually within a few days of the call.