Skip to main content
UNPWNED
UNPWNED Agent Proof
UNPWNED // AGENT PROOF

UNPWNED AGENT PROOF // B2B BOUNDARY ASSESSMENT

Do not ask an Agent whether it respects boundaries. Exercise them.

A boundary-assessment program in preparation for AI Agent builders that need to show enterprise customers what was tested, which build was exercised, which scenarios were contained and what remains untested.

01
Current

Local reference lab

5 methods, 24 definitions and 48 synthetic executions

02
Next gate

Authorized design-partner staging

Scope, SOW, DPA and stop authority before connection

03
Excluded

Production and real user data

Not tested or connected today

5 / 5Boundary methods in the reference lab
24Case definitions
48Profile executions
0Customer systems connected

The business problem

An Agent can look correct while operating outside its authority.

Response-quality checks do not prove tenant isolation, tool authorization or independent human approval. Once an Agent can reach data and actions, a small policy failure can become exposure or a state change performed for the wrong principal.

We test the enforcement point itself: who requested the action, against which resource, under which role, what was decided, which effect was observed and whether the system returned to baseline.

Five boundary methods

Test authority, not only content.

A method runs only when it applies to the Agent and appears explicitly in the approved scope.

01AP-TENANT-READ-001

Cross-tenant read isolation

Can a user or Agent read data that belongs to another tenant?

IMPACT

Data exposure, confidentiality loss and enterprise customer trust impact.

02AP-TENANT-WRITE-002

Cross-tenant write isolation

Can an action modify a record or state owned by another tenant?

IMPACT

Integrity loss, business process damage and unauthorized state change.

03AP-TOOL-SCOPE-003

Tool and permission boundaries

Can the Agent invoke a tool that is not assigned to the requester role?

IMPACT

Expanded blast radius across APIs, data stores and administrative actions.

04AP-APPROVAL-004

Human approval for sensitive actions

Does a sensitive action require a valid, independent and appropriate approver?

IMPACT

Financial or administrative action without documented human intent.

05AP-UNTRUSTED-CONTENT-005

Untrusted content versus authorization

Can hostile content become an approved tool proposal or action?

IMPACT

Prompt injection moves from untrusted text into real-world effect.

Engagement path

Assessment. Remediation. Retest. Proof.

The company controls the environment and stop authority. UNPWNED operates only inside a narrow approved scope.

  1. 01

    Map and scope

    Identify tenants, roles, tools, sensitive actions, the exact build and the emergency contact.

    NO ACCESS
  2. 02

    Prepare synthetic staging

    Create test accounts, synthetic canaries and short-lived credentials.

    STAGING ONLY
  3. 03

    Initial assessment

    Run one approved case at a time, observe effects and restore the baseline.

    FINDINGS
  4. 04

    Company-owned remediation

    The company fixes and deploys a new build. UNPWNED supplies evidence and a retest plan.

    COMPANY FIX
  5. 05

    Retest and Proof Pack

    Run the same cases again and separate fixed, vulnerable and not-tested states.

    PRIVATE EVIDENCE

Reference-lab result

A working engine with a bounded claim.

The same scenarios ran against two separate prebuilt profiles in UNPWNED’s owned local lab.

INTENTIONALLY VULNERABLE BUILD14 / 14

Defined attack scenarios were observed in the vulnerable profile.

SAME SCENARIOS // NOT AUTOMATIC REMEDIATION
PREBUILT FIXED REFERENCE14 / 14

The same scenarios were contained by the separate fixed profile.

Positive controls20 / 20 PASSED
CleanupVERIFIED
Customer systems0 CONNECTED

This result validates only the owned local synthetic reference lab. It is not a customer assessment, production test, certification, audit opinion or security guarantee.

Minimum-data principle

Enough evidence. Not a warehouse of customer content.

The planned pilot uses test accounts and synthetic data. The Proof Pack is designed around structured observations and digests.

Required for proof

  • Build and deployment identifier
  • Test method and status
  • Timestamp and run digest
  • Minimized effect observation
  • Cleanup and retest binding

Excluded from the Proof Pack

  • Credentials or session tokens
  • Secrets and API keys
  • Raw customer prompts
  • Full responses or tool output
  • Real end-user data

Before a real pilot, the DPA and scope define fields, purpose, retention, deletion and recipients. We do not claim the service can never process information.

First engagement step

Design Partner Discovery

We are validating fit for a narrow pilot shaped around the Agent and the company’s authorization model, without starting with system access.

AvailabilityDISCOVERY OPEN

Proposed pilot structure

  • Discovery call and boundary map
  • Written scope and authorized staging
  • Boundary methods applicable to the workflow
  • Findings review and remediation session
  • One retest against a new build
  • Private Proof Pack limited to tested scope

Not included

  • Production access
  • Real user data
  • Automatic code remediation
  • Certification or a security guarantee
Discuss fit

This page invites a non-binding discovery conversation only. No assessment is offered or authorized until separate terms, an SOW, a DPA and written scope are in force.

Short answers

What this service is and is not.

Does UNPWNED fix issues automatically?

No. The company remediates and deploys a new build. UNPWNED reruns the same scenarios and checks containment and positive controls.

Is this a penetration test or certification?

No. It is a scoped boundary-method assessment and private evidence service. It does not replace a human pentest, audit or certification.

Has a real AI company been assessed?

No. The verified result currently covers only UNPWNED’s owned local synthetic reference lab. Connecting a design partner is the next gate.

Can Agent Proof complement other red-team tools?

Yes. It focuses on build-bound authorization evidence and retest alongside content evaluation, model-safety testing and runtime guardrails.

The first question

What security proof do your customers ask for before approving an Agent?

The first conversation is discovery only. No credentials, no production access and no request to your systems.

Discuss design-partner fit
LOCAL SYNTHETIC REFERENCE // 2026-08-19CUSTOMER TESTING NOT YET AVAILABLE // NOT CERTIFICATION // NO SECURITY GUARANTEE