Assurance Report
Know how your agent reacts — before an attacker finds out
A one-time, independent security assessment of your production agent. We run the full attacks.ai honeypot against it privately, then hand you a forwardable attestation of exactly how it behaved — benchmarked against the current frontier of flagship models.
Ship it once, or keep it honest — roll into continuous assurance and re-test every deploy.
What you get
One report. No SDK. No access to your keys.
Independent agentReaction verdict
A behavioral fingerprint of your agent on the 6-class resistance ladder — Refused, Escape-valve, Detected-but-disclosed, Engaged, or Endorsed. The honest signal, not a synthetic score.
Forwardable attestation
A signed, self-contained report you can send to a customer, a partner, or your own security team as third-party evidence of how your agent handles adversarial web content.
Benchmarked against the frontier
Your agent’s reaction placed side-by-side with the current flagship models we track, so the result reads as a percentile, not an isolated number.
Every finding mapped
Prompt injection, data exfiltration, excessive agency, and credential confusion — each finding cross-referenced to the OWASP LLM Top 10, MITRE ATLAS, and the TRACTS framework.
How it works
Private by default
You point your agent at us
On a private, unbranded domain — no “attacks.ai” cue in the environment. Your agent walks documentation the way it would in production.
We run the honeypot
The full passive probe suite fires inside the content. Nothing executes against your infrastructure; no credentials or PII are collected.
You get the attestation
Within days: the agentReaction verdict, every finding with remediation, and the frontier benchmark — as a report you own and can forward.
See how your agent really reacts
$300 one-time. Independent. Forwardable. No platform parent, no lock-in.