Counteragent Security — adversarial testing for AI agents

Your agent is talking to a bank.
The bank's questionnaire is asking about us.

Enterprise buyers now ask AI startups one question that stalls deals: “Has a credible third party adversarially tested your agent?” We are that third party. Human-led testing of your live agent — its prompts, tools, retrieval, and memory — delivered as the formal report your deal is waiting on.

Format — scoped assessment, 2 weeks, fixed price From — USD 8,000 Delivery — remote, in your environment
The problem

Agents fail in ways scanners can't see — and procurement knows it.

An AI agent reads untrusted content, decides, and acts. The dangerous failures are not code bugs; they are chains — a benign-looking document instructs your agent to export the customer table three steps later. Automated scanners find the easy cases. Your buyer's security team knows this, which is why a self-run scan output rarely closes the questionnaire.

“Have you conducted third-party red teaming or adversarial testing on your AI system? Attach the report.” — the question pattern now standard in enterprise AI-vendor security reviews
WHO PAYS
Seed–Series B AI-agent startups selling into banks, insurers, and healthcare — when an enterprise deal is sitting in security review.
WHY NOW
The deal is stalled this quarter, not next year. Every week in review is burn rate against a unsigned contract.
WHY US
Big-firm red teams start at $50K+ and book out for weeks. Platforms sell software, not the human test. We are the credible human test at startup price and startup speed.
Method

Five attack classes. One rule: we test like an attacker, not a checklist.

Every assessment runs against your actual agent — its system prompt, tools, retrieval sources, MCP integrations, and memory. Testing happens in your environment or a sandbox you provision, under written rules of engagement. Side-effect actions fire only at test endpoints you designate.

A1
Direct injection & goal hijack. Can a user turn your agent against its instructions — and against your customers?
A2
Indirect injection via retrieval. Poisoned documents, knowledge-base content, and web sources your agent trusts as instructions.
A3
Memory & persistence abuse. A payload planted in one session that detonates in another user's session days later.
A4
Tool misuse & excessive agency. Bulk exports, unauthorized sends, write actions — what your agent can do versus what it should.
A5
Chained exploitation. The centrepiece: multi-step chains across components — the class automated tools structurally cannot find.
Honest scopeThis is a scoped security assessment of defined attack classes — not a full red-team engagement, and we say so in the report. Procurement reviewers trust reports that state their own limits.
The report

Built to be forwarded to your buyer's security team.

The deliverable is written for the person reading your questionnaire, not for you alone. It is designed to be attached, unmodified, to an enterprise security review.

CHAIN
The demonstrated exploit chain — step-by-step, with sanitized transcripts. The artifact a scanner cannot produce.
MAPPED
Findings mapped to OWASP Agentic/LLM Top 10, MITRE ATLAS, and NIST AI RMF — the vocabularies your buyer's reviewers use.
ANSWERS
Questionnaire answer-pack appendix — pre-drafted responses your team can adapt for the security review in flight.
RETEST
Remediation retest included within 60 days, with an addendum letter showing findings closed.
Public sampleSample report ASA-2026-001 — a full assessment of our own deliberately-vulnerable reference agent, with measured attack rates across three configurations — is published: read the report. The reference agent, exact seeds, and hashed run logs are in the demo pack (hashes) so the results reproduce.
Pricing

Fixed price. Known before we start.

Scoping
$3,000 fixed
Attack-surface review and written test plan with early findings. Credited against the full assessment if you proceed within 30 days.
Assessment
$8–15K fixed
The full two-week assessment, report, answer-pack appendix, and retest. Price set by agent complexity — single agent from $8K; multi-agent, MCP, production integrations from $12K.
Continuous
$5K /month
Retesting on every model, prompt, or tool change. For teams shipping fast whose enterprise customers re-ask the question every quarter.
The arithmeticA $10,000 assessment against a stalled $300,000 enterprise contract is 3% of the deal it unblocks — and it is expensed once, against burn you are already paying every week the review sits open.
Data & insurance

Your data never leaves your building. Neither does our liability.

DATA
Testing runs in your environment. Only sanitized finding evidence is retained — encrypted, access-limited, deleted on a 12-month schedule with a certificate of deletion on request. Full data-handling statement attached to every SOW.
LEGAL
Written rules of engagement before any test: in-scope targets, permitted techniques, designated test endpoints, stop conditions, 24-hour critical-finding notice.
INSURANCE
Professional indemnity cover is bound at SOW signature, certificate of currency delivered before testing begins. USD 250,000 standard; USD 1,000,000 available where your upstream requirements call for it.
PEOPLE
All testing by the named principal. No subcontractors without your written consent.
Request scoping

Tell us what the questionnaire asked. We'll tell you what it takes to answer it.

One email is enough. Include the buyer's security-review question if you can paste it — we reply within two business days with a fixed-price scoping proposal or a straight “you don't need us.”

PrincipalDr Sharmadave Subramaniam, founder and principal tester. Security research published under the handle TheDocter. Direct: +60 11-1144 5083 (WhatsApp).