Offer — offensive assessment

Red teaming for AI agent chains

A published method, open datasets, and an execution log you can verify yourself.

Scope an assessment

€2,500 — one week, one report, one debrief.

The problem this offer addresses

Your AI agents do what they are asked. That is precisely the problem.

When several agents chain together — one reads, one decides, one executes — an instruction hidden in incoming content can travel the whole chain without a single model being jailbroken, without a guardrail firing, without an alert going out. Every agent behaves according to its instructions. The system does something other than what was intended.

This failure mode is not covered by classic security frameworks. ISO 27001 covers access, network and the development lifecycle. A fairness audit measures whether a model is fair. Neither says what happens when incoming content acquires an authority nobody ever granted it.

What gets tested

The exact perimeter is defined together at scoping. Depending on the case, a mission covers:

01

The boundary between instruction and data

What, in the context handed to your models, carries authority — and what should only ever be evaluated. This is the entry point of very nearly every compromise we have observed.

02
ATLAS

Propagation along the chain

What one agent passes to the next, and what that next one does with it. An instruction restated by a trusted link becomes undetectable downstream: that is the central mechanism in ATLAS.

03
RELAY

Authority laundering

The ability of incoming content to pass itself off as an already-approved decision. That is what RELAY measures, and it is what makes reviewers fold even when they can see the problem.

04

Acting on the output

What separates a model output from a database write, a tool call, a transaction. A chain that gets it wrong without being able to act is an incident; a chain that gets it wrong and acts is a loss.

05

Traceability

What your system keeps of what happened, and whether that record holds up in front of a third party.

How a mission runs

D0

Scoping

Joint definition of the perimeter, the systems in scope, the intervention window and what is out of bounds. Formalised by a signed written authorisation — without it, no operation begins.

D1

Reconnaissance

Mapping the chain: who talks to whom, who decides, who acts, and what content enters where.

D2 – D4

Attack

Running the relevant vectors across the agreed perimeter, prioritising whatever leads to an irreversible action.

D5

Debrief

A report of what was tested, what held and what gave way, with criticality and prioritised recommendations. Followed by a conversation to walk through it together.

The deliverable

Report

Vectors exercised, results, criticality, recommendations ordered by what to fix first. Usable internally and in front of a third party.

Loghash chain timestamped by a third party

And a verifiable trace of the mission itself. Operations are run through the Senthex infrastructure: every request sent is recorded in a hash chain timestamped by a third-party authority. You receive that log together with an offline verifier. So you can check for yourself what was sent at your systems, and when, without having to take our word for it.

That is unusual in this trade, and it is deliberate: a security test that demands blind trust is hard to defend in front of a regulator.

See the mechanism at work

The mission log relies on the audit-as-proof capability — SHA-256 chain, RFC 3161 anchor, offline verifier — which is a pilot capability (v1.1.7), not yet the published release. It is exercised on our own infrastructure during the mission; we will tell you exactly where it stands at scoping.

In plain terms: what this engagement does not do

An assessment covers a defined perimeter, at a point in time. It is neither a certification nor a guarantee that no vulnerability exists: finding nothing on a vector does not prove there is nothing there to find.

One week is enough to exercise, as a priority, the vectors that lead to an irreversible action — not to cover a complex chain exhaustively. The report states explicitly what was tested and what was not.

Every mission requires prior written authorisation defining the perimeter. Testing a system without that frame is illegal, and we do not do it.

Pricing

€2,500
one week

Assessment

One week, one report, one debrief. Launch price.

from €12,000
per year

Senthex Self-Host licence

The firewall deployed on your own infrastructure: model calls intercepted, blocking at the entry point, a verifiable audit log. Support and updates included. Your data does not leave your environment.

from €18,000
per year

Annual programme

The self-host licence, plus two half-yearly assessments. You hold, at any moment, a robustness report less than six months old, backed by a verifiable log — the artefact a regulated customer or a regulator will eventually ask you for in writing.

Broad perimeters and multiple environments are quoted at scoping.

Frequently asked questions

Is written authorisation required?

Yes, without exception. Scoping ends with a signed written authorisation defining the perimeter, the systems in scope, the intervention window and what is out of bounds. Without it, no operation begins: testing a system without that frame is illegal, and we do not do it.

Does this certify us, or make us compliant?

No. An assessment covers a defined perimeter, at a point in time — it is neither a certification nor a guarantee that no vulnerability exists. The report is a dated artefact you can produce in front of a customer or an auditor; it replaces neither a conformity assessment nor your technical documentation.

What happens if you find nothing?

The report states what was tested and what held, vector by vector — that is a usable result, not a failed mission. It also states explicitly what was not covered: finding nothing on a vector does not prove there is nothing there to find.

Do we need to be using Senthex already?

No. The assessment covers your chain as it runs today, whichever model providers you use. The Senthex infrastructure is there to record the mission itself, so you can check for yourself what was sent at your systems, and when.

What is the method grounded in?

Two studies Senthex ran and published: ATLAS, on prompt-injection cascades in a multi-agent company, and RELAY, on authority laundering in an agentic CI/CD chain, published on arXiv under cs.CR. The runs, the prompts and the analysis code are public — you can check the method before buying it.

A conversation to scope the perimeter, the window and the quote.

Tell us what you run: how many agents, which tools they can call, and what, on your side, can trigger an irreversible action. We come back with a proposed perimeter and a window.