AI agent security · Switzerland

Your AI agent can read, decide and act.
Test what happens when it is manipulated.

Adversarial security workshops and assessments for enterprise agents with access to tools, sensitive data and business systems.

✓ Swiss-based✓ Builder-led✓ Controlled scope✓ Engineering-ready findings
Agent attack surfaceassessment view
INPUT
Untrusted document

Hidden instruction enters retrieved context

DECIDE
Enterprise agent

Interprets content and selects an action

ACT
Privileged tool call

CRM, email, code, ERP or internal API

CONTROL
Containment gate

Identity, approval, logging and rollback

We trace how untrusted input can become an unauthorized action—and whether your controls stop it.

For real agent systemsTools, memory, retrieval and business access
Before productionOr before a material release or permission change
For two audiencesTechnical depth for engineers, risk clarity for leaders
With a retestFixes are verified, not merely recommended
What we test

Security at the point where models become systems.

Traditional application testing still matters. Agent assessments add the failure modes created by untrusted context, autonomous decisions, connected tools and persistent memory.

01

Goal hijacking

Can email, documents, websites or retrieved content redirect the agent away from the user’s intent?

02

Tool & privilege misuse

Can the agent exceed its role, bypass approval or misuse a connected business system?

03

Data, secrets & memory

Can sensitive information leak across users, tools or sessions—or can persistent context be poisoned?

04

Blast radius

If the agent is compromised, are actions bounded, visible, attributable, reversible and containable?

Start where you are

A paid entry point. A deeper assessment when the risk justifies it.

You do not need to buy a broad security programme to answer the next important question about an agent approaching production.

Paid entry offer

Agent Security Readiness Workshop

Fixed-scope workshop · priced after fit confirmation

A focused half-day with engineering and security stakeholders to map the system, expose the highest-value attack paths and agree the launch gates.

  • Pre-work architecture questionnaire
  • Live agent and trust-boundary mapping
  • Prioritized threat scenarios
  • Top-five risk and control memo within two business days
  • Recommendation: test, fix, contain or proceed
Request the workshop

100% credited toward an assessment booked within 30 days.

Core engagement

AI Agent Security Assessment

Scoped assessment · proposal after the fit call

A controlled, ten-business-day adversarial assessment for one defined agent or tightly coupled workflow in an approved test environment.

  • Rules of engagement and architecture review
  • Threat model across inputs, memory, tools and identities
  • Controlled adversarial testing with reproducible evidence
  • Executive summary and developer-ready findings
  • Remediation workshop and one priority retest
Discuss assessment fit
How the assessment works

Bounded, evidence-led and built around your release decision.

The method is informed by the OWASP Agentic Security Initiative and NIST AI risk-management guidance. It is not a certification or compliance audit.

01 · SCOPE

Set the rules

Confirm the agent, environment, allowed techniques, stop conditions, data handling and owners.

02 · MAP

Model the system

Trace inputs, models, retrieval, memory, tools, identities, approvals and business consequences.

03 · TEST

Attack safely

Execute prioritized scenarios and capture enough evidence for engineers to reproduce the finding.

04 · FIX

Remediate & retest

Separate root causes from symptoms, agree practical controls and verify the priority fixes.

Good fit

For teams moving agents from impressive demos into consequential workflows.

Strong fit

  • The agent can call APIs, write data, send messages or change a workflow.
  • It consumes web pages, documents, email, tickets or other untrusted content.
  • It is approaching production, a major release or expanded permissions.
  • Engineering and security need a shared, evidence-based decision.

Not the right engagement

  • You need a compliance certificate or legal opinion.
  • You want destructive testing without a controlled environment.
  • The scope is an unrelated infrastructure or full source-code audit.
  • No system owner can authorize testing and stop conditions.
Built from agent engineeringNot a generic security wrapper around an unfamiliar system.
Why deflation

We build agents, so we know where their real boundaries fail.

deflation.ai builds and operates agents connected to email, telephony, calendars, business software and private data. That experience shapes a practical security view: the model is only one component. The larger risk lives in identity, permissions, memory, tools, approvals and operational containment.

The security practice is led by Harry Trippel, an agent engineer with a backend, security and technical-leadership background. Public methodology and technical case studies are being developed alongside the client work—without invented references or inflated claims.

Agent & harness engineeringBackend systemsSecurity backgroundSwiss delivery
Questions

What buyers usually need to know.

Can we start with the workshop only?

Yes. It is a complete paid engagement with its own deliverable. If the resulting risk surface does not justify an assessment, you still receive a prioritized threat and control memo.

Do you test production?

The standard engagement uses an approved test or staging environment with representative accounts and data. Production testing requires separate rules, safeguards and explicit written authorization.

Will our developers be involved?

Yes. The goal is not to throw a report over the wall. Engineers validate expected behavior, help confirm root causes and leave with practical remediation guidance.

Is this a traditional penetration test?

It is an adversarial assessment of an agent system. It includes relevant application-security paths, but the core scope focuses on agent behavior, untrusted context, tool use, identity, memory and blast radius. It is not a compliance certification.

How do you handle sensitive evidence?

Evidence is minimized, stored only as agreed, shared with named contacts and deleted according to the engagement’s data-handling terms. Exact requirements are confirmed before access is granted.

Next step

Bring one agent, one architecture and one upcoming production decision.

In a 20-minute fit call, we will determine whether the readiness workshop, the assessment or no engagement is the honest next step.

Controlled testing only. Written authorization is required before any adversarial work begins.