Engagement & Process

Solution audit
Mapped the agent end to end: input entry points, callable tools, identity permissions, memory reads and writes. Most findings came from here; none were about the model.
Red-teaming
Live attacks: indirect injection, multi-turn escalation, memory poisoning, tool-call manipulation. Each finding re-run several times before it counted.
Evaluation suite
200 tests built with Promptfoo and DeepEval: injection refusal, data-exfiltration blocking, tool-call validation, PII handling, retrieval faithfulness.
AIVSS scoring
CVSS severity + AARS agentic amplification, used to rank where risk concentrated so remediation hit the right components first.
What We Delivered




