Trust centre

What we inspect, what we store and what we do not claim.

AgentRiskLayer is designed to produce useful security evidence without pretending that a customer-operated static scan or controlled staging campaign is an independent audit or production penetration test.

Customer-controlled execution

The Inspector and Red Team Runner execute on the customer side only after explicit authorisation. Static inspection is read-only; adversarial testing is restricted to local, test or staging adapters, synthetic data and dry-run tools. Staging campaigns require a written Rules of Engagement record bound to the exact assessment, environment, testing window and approved endpoint origin.

Data minimisation

Uploaded evidence contains rule or case results, bounded metadata and fingerprints. The tools are designed to exclude source-file contents, matched credentials, environment-variable values, raw attack prompts and raw target responses.

Integrity and replay controls

Bundles contain SHA-256 and Ed25519 integrity metadata, use short-lived one-time upload tokens and are rejected when replayed, stale, altered or generated by an unpublished release.

Private by default

Assessments and inspection evidence are account-restricted. Public summary links remain disabled until the account owner explicitly enables sharing, and public tokens cannot access technical evidence or paid PDFs.

Transparent policy

The scanner and red-team runner source, release checksums, policy catalogues, adapter example and limitations are public so customers can review what will run before authorising it.

Enforced evidence lifecycle

Red-team evidence is retained for the approved period, then removed by an automated retention worker. A non-sensitive deletion receipt remains. Explicit legal holds are visible and suspend deletion until formally released.

Resilient paid delivery

Confirmed payments grant access transactionally. PDF and email work runs through durable retryable jobs, failed work creates operator alerts, and reconciliation can recover a partially completed purchase without charging the customer again.

Honest assurance label

Reports distinguish declared controls, locally observed static evidence, pipeline simulations and controlled staging evidence. They do not call the result a penetration test, certification, independent audit, breach probability or guarantee of security.

Current security controls

Inspection boundary

An accepted bundle demonstrates that the submitted JSON matched its integrity proof and the published tool-release digest. Because the customer controls the machine, this does not independently prove completeness, production equivalence, runtime behaviour or absence of tampering before bundle generation. Stronger independent assurance requires source-control/cloud connectors, controlled test environments, runtime telemetry or human review.

Vulnerability disclosure

Security reports should be sent privately using the contact published in our security.txt. Do not include real customer secrets or exploit production data. We will acknowledge good-faith reports and coordinate remediation.

Operational commitments before enterprise claims

AgentRiskLayer will not claim enterprise certification or independent verification until external penetration testing, independent methodology review, release-signing procedures, documented backup restoration tests and formal incident-response processes are completed and documented.

Review the InspectorReview Red TeamRelease manifestRead methodology