Information required
A material question is unanswered. It is not scored as a vulnerability; the next step is to clarify the system or control.
AgentRiskLayer keeps unresolved information, declared controls, observed evidence, findings, attack evidence and runtime behaviour separate so the customer can see exactly what is known and what still needs proof.
The platform keeps them separate so uncertainty does not masquerade as a vulnerability and an unsupported claim does not masquerade as proof.
A material question is unanswered. It is not scored as a vulnerability; the next step is to clarify the system or control.
The customer states that a protection or non-applicability condition exists. It still needs appropriate evidence.
A specific declared control weakness or separately observed/tested failure exists and needs remediation and verification.
Evidence supports the control or shows that a previously identified weakness no longer reproduces for the assessed scope.
Not every customer starts with every stage. The platform shows what exists and what is still missing.
Data sensitivity, users, tools, identities, networks, models, memory and operational authority. Exposure is context, not a vulnerability by itself.
Least privilege, input separation, tool policy, approval, containment, recovery and monitoring.
Material unknowns are shown as information required and can produce a hold without creating a false critical finding.
Customer assertion, observed configuration, repeatable test, runtime event or reviewed evidence.
Credible chains from untrusted input through agent authority to a real business consequence.
The assessment does not pretend that one questionnaire or one scanner can answer everything.
Establishes exposure, declared controls and unresolved information in plain language.
Observes repository, configuration, model and MCP evidence under explicit customer authorisation.
Tests authorised non-production behaviour under written Rules of Engagement.
Records the policy identity and decision before prompts, outputs or tool calls proceed.
Binds a fix to accountable ownership, evidence and the exact test needed for closure.
Uses signed or hashed artifacts where appropriate so tampering and scope are visible.
A proprietary security assessment and evidence workflow against the AgentRiskLayer Control Profile for the identified system and version.
An accredited certification, legal opinion, guarantee of security or proof about systems that were outside the assessed scope.
Adversarial testing requires authorised targets, environment, dates, allowed methods, prohibited actions, contacts and stop conditions.
Findings can map to applicable OWASP agentic and LLM risks, NIST AI RMF, NIST SSDF and supply-chain guidance. A mapping indicates relevance; it does not create certification or compliance on its own.