UNPWNED AGENT PROOF // B2B BOUNDARY ASSESSMENT
Do not ask an Agent whether it respects boundaries. Exercise them.
A boundary-assessment program in preparation for AI Agent builders that need to show enterprise customers what was tested, which build was exercised, which scenarios were contained and what remains untested.
Local reference lab
5 methods, 24 definitions and 48 synthetic executions
Authorized design-partner staging
Scope, SOW, DPA and stop authority before connection
Production and real user data
Not tested or connected today
The business problem
An Agent can look correct while operating outside its authority.
Response-quality checks do not prove tenant isolation, tool authorization or independent human approval. Once an Agent can reach data and actions, a small policy failure can become exposure or a state change performed for the wrong principal.
We test the enforcement point itself: who requested the action, against which resource, under which role, what was decided, which effect was observed and whether the system returned to baseline.
Five boundary methods
Test authority, not only content.
A method runs only when it applies to the Agent and appears explicitly in the approved scope.
AP-TENANT-READ-001Cross-tenant read isolation
Can a user or Agent read data that belongs to another tenant?
Data exposure, confidentiality loss and enterprise customer trust impact.
AP-TENANT-WRITE-002Cross-tenant write isolation
Can an action modify a record or state owned by another tenant?
Integrity loss, business process damage and unauthorized state change.
AP-TOOL-SCOPE-003Tool and permission boundaries
Can the Agent invoke a tool that is not assigned to the requester role?
Expanded blast radius across APIs, data stores and administrative actions.
AP-APPROVAL-004Human approval for sensitive actions
Does a sensitive action require a valid, independent and appropriate approver?
Financial or administrative action without documented human intent.
AP-UNTRUSTED-CONTENT-005Untrusted content versus authorization
Can hostile content become an approved tool proposal or action?
Prompt injection moves from untrusted text into real-world effect.
Engagement path
Assessment. Remediation. Retest. Proof.
The company controls the environment and stop authority. UNPWNED operates only inside a narrow approved scope.
- 01NO ACCESS
Map and scope
Identify tenants, roles, tools, sensitive actions, the exact build and the emergency contact.
- 02STAGING ONLY
Prepare synthetic staging
Create test accounts, synthetic canaries and short-lived credentials.
- 03FINDINGS
Initial assessment
Run one approved case at a time, observe effects and restore the baseline.
- 04COMPANY FIX
Company-owned remediation
The company fixes and deploys a new build. UNPWNED supplies evidence and a retest plan.
- 05PRIVATE EVIDENCE
Retest and Proof Pack
Run the same cases again and separate fixed, vulnerable and not-tested states.
Reference-lab result
A working engine with a bounded claim.
The same scenarios ran against two separate prebuilt profiles in UNPWNED’s owned local lab.
Defined attack scenarios were observed in the vulnerable profile.
The same scenarios were contained by the separate fixed profile.
This result validates only the owned local synthetic reference lab. It is not a customer assessment, production test, certification, audit opinion or security guarantee.
Minimum-data principle
Enough evidence. Not a warehouse of customer content.
The planned pilot uses test accounts and synthetic data. The Proof Pack is designed around structured observations and digests.
Required for proof
- Build and deployment identifier
- Test method and status
- Timestamp and run digest
- Minimized effect observation
- Cleanup and retest binding
Excluded from the Proof Pack
- Credentials or session tokens
- Secrets and API keys
- Raw customer prompts
- Full responses or tool output
- Real end-user data
Before a real pilot, the DPA and scope define fields, purpose, retention, deletion and recipients. We do not claim the service can never process information.
First engagement step
Design Partner Discovery
We are validating fit for a narrow pilot shaped around the Agent and the company’s authorization model, without starting with system access.
Proposed pilot structure
- Discovery call and boundary map
- Written scope and authorized staging
- Boundary methods applicable to the workflow
- Findings review and remediation session
- One retest against a new build
- Private Proof Pack limited to tested scope
Not included
- Production access
- Real user data
- Automatic code remediation
- Certification or a security guarantee
This page invites a non-binding discovery conversation only. No assessment is offered or authorized until separate terms, an SOW, a DPA and written scope are in force.
Short answers
What this service is and is not.
Does UNPWNED fix issues automatically?
No. The company remediates and deploys a new build. UNPWNED reruns the same scenarios and checks containment and positive controls.
Is this a penetration test or certification?
No. It is a scoped boundary-method assessment and private evidence service. It does not replace a human pentest, audit or certification.
Has a real AI company been assessed?
No. The verified result currently covers only UNPWNED’s owned local synthetic reference lab. Connecting a design partner is the next gate.
Can Agent Proof complement other red-team tools?
Yes. It focuses on build-bound authorization evidence and retest alongside content evaluation, model-safety testing and runtime guardrails.
The first question
What security proof do your customers ask for before approving an Agent?
The first conversation is discovery only. No credentials, no production access and no request to your systems.

