▼ HOW IT FAILS
Untrusted content becomes instruction.
▲ WHAT CLOSES IT
Trust boundaries on every input; tool descriptions reviewed as code.
IMS ASSESSES
Instruction-surface review + injection test battery.
HOVER A SURFACE →The network boundary dissolved years ago. In the agentic enterprise your perimeter is wherever an agent can read, decide, act, or leak. IMS maps it, tests it, and closes it.
Untrusted content becomes instruction.
Trust boundaries on every input; tool descriptions reviewed as code.
Instruction-surface review + injection test battery.
HOVER A SURFACE →Your AI perimeter is wherever an agent can read, decide, act, or leak.
Seven behavioral surfaces define where an agent can be attacked. We map, test, and close each one.
An operational diagnostic, not a marketing quiz. Toggle what your agents actually do.
Every engagement produces board-visible artifacts. Sample outputs from the assessment.
Findings 23Critical 4Roadmap items 11
FINDING RT-014 · surface S-04 TOOL› Indirect injection in a retrieved PDF chained the support agent's refund tool.› Text-to-action: untrusted content → live financial transaction. No human gate.+ CONTROL: scope tool to read-only; approval gate > $0; provenance tag on retrieval.
“We deployed 11 production agents in two quarters and inventoried none. Four can move money or write to customer systems without a human gate. This is unmanaged delegation — and it is the committee's risk to own.”— EXCERPT, IMS EXECUTIVE BRIEFING
Two-week perimeter map across all seven surfaces. The primary engagement.
Reference architecture for agents that can be deployed without unmanaged delegation.
Adversarial testing of injection, tool abuse, and text-to-action escalation.
Board-ready risk language, agent inventory, and fiduciary framing.
Inventory, scope review, and gating for every MCP server and tool action.
A private briefing environment for CISOs, boards, audit committees, and GCs.
Every enterprise needs an agent inventory before it needs another AI policy. Start with a two-week posture assessment.
Request AI Security Posture AssessmentExplore the framework