Partners / AI agencies

Test before handover.

For agencies that build chatbots and AI agents for clients: an independent test of the agent and the app around it before handover, with findings in the agent you built reported to you first. Your client gets a report and a one-page letter they can check, and we never pitch your client.

Updated
FIG. 1 / A FINDING'S LIFE BEFORE HANDOVER
  1. 01 Tested

    On the build your client will get, before they see a date.

  2. 02 Found, reported to you

    Findings in your agent come to you first, with evidence and the fix principle.

  3. 03 Fixed, retested

    What your client reads: found and fixed before handover.

How a partner test runs.

  1. Scope with you. We agree the agent, the app around it and the test window with you, and your client authorizes testing of their systems in writing.
  2. Test before handover, in your staging or theirs, on the build your client will receive.
  3. Findings in your agent to you first, with their evidence and the principle of the fix. Findings in systems your client owns, and every critical one, go to your client’s named contact as well, as their authorization requires.
  4. Fix window. You fix; we answer questions while you do.
  5. Handover. Your client receives the report and a one-page attestation letter that says what was tested, when, and what was found and fixed.

The partner terms.

Findings first
Findings in the agent you built go to you first, with a fix window. Findings in systems your client owns, and every critical, go to your client’s named contact too, as their authorization requires. The final report lists every finding with its original severity and its retest result.
Who contracts
You or your client: either works. Whoever signs the order pays the invoice, and your client signs the authorization for their own systems either way.
Non-solicit
Written into the partner agreement. We test; we do not build agents, so there is nothing for us to sell your client.
No white-label
The report carries our name. An independent test is worth something only if it is visibly independent, and your client can check who did it.
Prices
Permission
Your client signs for their systems, you sign for yours, and the vendors of hosted parts sign for theirs. Nothing is tested without it.

Who it is for.

Agencies that build chatbots, RAG search or agents with real tools for their clients, especially when a client's procurement asks for an independent test, or when the agent will act on customer data.

Not a fit if:

  • you need the report under your own name;
  • you want a badge rather than a test;
  • the client will not authorize testing of their systems.

What we test before handover.

The agent you built, and the systems it can reach on your client's side.

01 / Model layer

AI Pentest

Prompt injection, direct and through retrieved content, data leakage, tool misuse and excessive agency, MCP servers. Mapped to OWASP and MITRE ATLAS, with reproduction rates.

02 / Stack layer

Stack Pentest

The web app, the APIs the agent calls and the cloud underneath: authorization, tenant isolation and the paths from one weak spot to the rest.

What agencies ask first.

Will you contact our client directly?

Only as far as the test needs it: the authorization and the test window are agreed with them, because it is their system. Everything else goes through you. We do not pitch them, and the partner agreement includes a non-solicit.

Can the report carry our brand instead of yours?

No. Your client is buying an independent opinion, and a white-labelled report hides who gave it. The report names us as the tester, and the attestation letter lets your client show the result to their own customers or auditors without the findings.

What does our client need to sign?

A written authorization for every system they own, and their vendors' permission for anything those vendors host, such as a model provider or a hosted vector store. We provide the authorization letter template and handle the paperwork with you, before the test window opens.

Read next