Security evidence for tool-connected AI agents

Before your AI agent reaches production, know what it can do—and prove the controls worked.

Start with one real agent. Map what it can access and change, verify the controls around it, and keep the evidence behind a proceed, hold or do-not-deploy decision.

5–10 minute first risk check No card to start £99 once for the full assessment package
One connected security journey for teams building or using AI agents.
Evidence before claimsDeclared and observed facts stay separate.
Human approval where it mattersHigh-impact actions can require exact approval.
Retest before closureImplementation evidence is not treated as a passed test.
The buying moment

Assess when the agent has real authority and the decision matters.

AgentRiskLayer is built for agents that can reach business systems, sensitive data or consequential tools—not for a simple chatbot that only drafts text.

01

Before production

The agent is about to reach customers, internal systems or real tools and you need a defensible deployment decision.

02

After a material change

A new model, MCP server, permission, tool, data source or autonomy mode may invalidate earlier evidence.

03

When a customer asks for proof

A buyer, security reviewer or client wants evidence of what was checked—not another unsupported security claim.

04

After a fix

A material weakness was remediated and the exact failure needs to be retested before it can be closed.

One product, three jobs

Assess. Control. Prove.

Start with the deployment decision. Reveal deeper security detail only when a developer, security reviewer or auditor needs it.

01

Assess

Understand what the agent can access, what can influence it and what could happen if it fails or is attacked.

  • Guided risk assessment
  • Technical inspection
  • Controlled red-team evidence
02

Control

Put enforceable boundaries around prompts, outputs and tool calls before an unsafe action reaches a real system.

  • Versioned runtime policy
  • Exact-action human approval
  • Remediation with ownership
03

Prove

Connect findings, fixes, retests and runtime decisions to the evidence that supports an accountable deployment decision.

  • Evidence-linked retest
  • Decision history
  • Explicit limitations
Evidence becomes a decision

See why the agent is blocked—and what changes the decision.

AgentRiskLayer keeps declarations, observations, supported failures, remediation and exact retests distinct. The interface starts with the decision and next action; technical provenance remains available underneath.

Deployment evidenceIllustrative example
Supported failureApproval boundary can be bypassed

Reproduced under the authorised test scope.

Finding
RemediationBind approval to customer, order and amount

Implementation evidence attached; retest still required.

Retest
RuntimeUnsafe refund attempt stopped

Policy and decision evidence recorded for the controlled example.

Blocked
  1. DeclaredCustomer fact
  2. ObservedTechnical evidence
  3. FindingSupported failure
  4. RemediationChange + proof
  5. RetestExact scope
  6. DecisionWith limitations
Public proof · ARL17K

17,600 attempts. Same workload. Different outcome.

In our safe synthetic benchmark, the intentionally unsafe baseline persisted through 17,600 attempts and executed a simulated privileged action. The protected replay used the same workload and was contained at attempt 26.

17.6K

Unsafe baseline

17,599 failed paths before the final synthetic route executed the simulated action.

26

Protected replay

The breaker opened after 25 denied paths and blocked attempt 26 before credential access.

41/41

Evidence boundary

All ARL17K tests passed. The result is synthetic benchmark evidence—not production or independent assurance.

How it works

From uncertainty to an evidence-backed decision in four steps.

Complete the first risk check in plain English. Add technical evidence and runtime controls only when they are relevant to the agent you are securing.

01 · CHECK

Describe one agent

Record access, data, tools, approval and recovery boundaries.

02 · VERIFY

Inspect and test

Compare declarations with technical evidence and authorised tests.

03 · CONTROL

Fix and protect

Remediate supported findings and stop unsafe runtime actions.

04 · PROVE

Retest and decide

Verify the exact risk again and preserve the evidence behind the decision.

Primary paid step

Start free. Pay £99 when one real agent needs the complete assessment package.

The free check qualifies the risk. The one-off assessment unlocks the full evidence, remediation and exact-retest workflow. Ongoing plans matter only when you need recurring runtime protection or more projects.

Loading current options…
Trust through boundaries

Clear evidence. Clear limitations. No security theatre.

AgentRiskLayer Security Assessments are proprietary assessments against the stated AgentRiskLayer Control Profile. They are not accredited certifications or guarantees that a system is risk-free.

Declared controls remain distinct from observed controls. Unknown or inconclusive information is not automatically turned into a vulnerability. High-impact approvals can be bound to the exact action and parameters. Findings, remediation and retests retain their evidence lineage. Reports state scope, method, limitations and the assessed system version.