← Insights Security

What a security review of an agent should cover

Agents act. That makes them a different kind of software to review. Here is the checklist we bring to regulated clients.

A chatbot that says the wrong thing is embarrassing. An agent that does the wrong thing — issues a refund, changes a record, sends an email — is an incident. Security review for agents has to start from that difference.

We review four things: what the agent is allowed to see (data scoping per user and per task), what it is allowed to do (tool permissions, with the destructive ones gated behind confirmation or a human), how it can be manipulated (prompt-injection paths through every input, including documents and web content it reads) and what happens when it is wrong (audit trail, reversibility, escalation).

None of this is exotic. It is the same least-privilege, defense-in-depth thinking security teams already apply to services and people. The work is applying it deliberately to a new kind of actor, and then proving it with adversarial evals that run on every release.

Our teams build custom agentic systems that unlock meaningful business outcomes.

Work With Us

We use agentic engineering tools and practices to build them quickly and reliably.

We'll teach you how to do both.