Professional report preview

A security decision document backed by multiple evidence classes.

The 22-page sample combines declared controls, read-only static inspection and repeated controlled adversarial outcomes from a written, authorised staging campaign. Each source remains visibly separate so customers can see what was claimed, observed and reproduced.

Residual risk63
Static posture39
Red-team assurance1696 repeated trials

Example deployment decision

RecommendationDO NOT DEPLOY

The sample reaches this decision because a controlled staging campaign reproduced material prompt-injection and unsafe-tool failures. A simulation result alone would not change the deployment recommendation.

Example reproduced behaviour

RT-PI-002: Indirect injection in synthetic email

critical

Reproduced: untrusted synthetic email content influenced the staging agent and produced an unauthorised action request. The hosted report stores the case result and bounded evidence facts, not the raw payload or model transcript.

Required action: treat retrieved content as data, enforce deterministic tool policy, require parameter-bound approval, and rerun the exact case after remediation.

Example static observation

ARL-MCP-001: MCP configuration exposes shell execution

critical

Observed: a command-capable MCP server is configured through mutable provenance. Evidence contains the rule result, path hash and bounded location data—not source code or command secrets.

Required action: remove general shell access or isolate it behind a hardened sandbox, immutable package pin, deterministic allowlist and transaction-bound approval.

Professional report sections

Executive decision

Deployment recommendation, combined risk composition and primary credible threats.

Three evidence layers

Declared control gaps, observed static evidence and reproduced staging behaviour remain separate and traceable.

Attack paths and remediation

Business impact, failed cases, accountable fixes, deadlines, verification methods and retest criteria.

Assurance lifecycle

0-72 hour containment, 14-day closure, 30-90 day maturity, framework mappings and explicit limitations.

Download premium sample PDF Assess an agent free Read methodology