Trust centreWhat we inspect, what we store and what we do not claim.
AgentRiskLayer is designed to produce useful security evidence without pretending that a customer-operated static scan or controlled staging campaign is an independent audit or production penetration test.
Customer-controlled execution
The Inspector and Red Team Runner execute on the customer side only after explicit authorisation. Static inspection is read-only; adversarial testing is restricted to local, test or staging adapters, synthetic data and dry-run tools. Staging campaigns require a written Rules of Engagement record bound to the exact assessment, environment, testing window and approved endpoint origin.
Data minimisation
Uploaded evidence contains rule or case results, bounded metadata and fingerprints. The tools are designed to exclude source-file contents, matched credentials, environment-variable values, raw attack prompts and raw target responses.
Integrity and replay controls
Bundles contain SHA-256 and Ed25519 integrity metadata, use short-lived one-time upload tokens and are rejected when replayed, stale, altered or generated by an unpublished release.
Private by default
Assessments and inspection evidence are account-restricted. Public summary links remain disabled until the account owner explicitly enables sharing, and public tokens cannot access technical evidence or paid PDFs.
Transparent policy
The scanner and red-team runner source, release checksums, policy catalogues, adapter example and limitations are public so customers can review what will run before authorising it.
Enforced evidence lifecycle
Red-team evidence is retained for the approved period, then removed by an automated retention worker. A non-sensitive deletion receipt remains. Explicit legal holds are visible and suspend deletion until formally released.
Resilient paid delivery
Confirmed payments grant access transactionally. PDF and email work runs through durable retryable jobs, failed work creates operator alerts, and reconciliation can recover a partially completed purchase without charging the customer again.
Honest assurance label
Reports distinguish declared controls, locally observed static evidence, pipeline simulations and controlled staging evidence. They do not call the result a penetration test, certification, independent audit, breach probability or guarantee of security.
Current security controls
- Asynchronous salted scrypt password hashing, verified email, optional TOTP MFA and recovery codes
- HTTP-only SameSite sessions with idle and absolute expiry and reauthentication for destructive actions
- CSRF protection for browser state changes
- HMAC-hashed, expiring one-time inspection and red-team upload tokens
- Stripe webhook signature verification, durable fulfilment states, retryable report delivery and operator reconciliation
- Request-size limits, persistent trusted-proxy-aware rate limits and strict CSP/security headers
- Private/public token separation and object-level ownership checks
- Persistent data export and account-deletion controls
- Written Rules of Engagement with revocation, exact campaign-window enforcement and endpoint binding
- Automated evidence retention, purge receipts and explicit legal holds
- Database backup creation, SHA-256 manifest and restore verification tooling
Inspection boundary
An accepted bundle demonstrates that the submitted JSON matched its integrity proof and the published tool-release digest. Because the customer controls the machine, this does not independently prove completeness, production equivalence, runtime behaviour or absence of tampering before bundle generation. Stronger independent assurance requires source-control/cloud connectors, controlled test environments, runtime telemetry or human review.
Vulnerability disclosure
Security reports should be sent privately using the contact published in our security.txt. Do not include real customer secrets or exploit production data. We will acknowledge good-faith reports and coordinate remediation.
Operational commitments before enterprise claims
AgentRiskLayer will not claim enterprise certification or independent verification until external penetration testing, independent methodology review, release-signing procedures, documented backup restoration tests and formal incident-response processes are completed and documented.