Goal hijacking
Can email, documents, websites or retrieved content redirect the agent away from the user’s intent?
Adversarial security workshops and assessments for enterprise agents with access to tools, sensitive data and business systems.
Hidden instruction enters retrieved context
Interprets content and selects an action
CRM, email, code, ERP or internal API
Identity, approval, logging and rollback
We trace how untrusted input can become an unauthorized action—and whether your controls stop it.
Traditional application testing still matters. Agent assessments add the failure modes created by untrusted context, autonomous decisions, connected tools and persistent memory.
Can email, documents, websites or retrieved content redirect the agent away from the user’s intent?
Can the agent exceed its role, bypass approval or misuse a connected business system?
Can sensitive information leak across users, tools or sessions—or can persistent context be poisoned?
If the agent is compromised, are actions bounded, visible, attributable, reversible and containable?
You do not need to buy a broad security programme to answer the next important question about an agent approaching production.
Fixed-scope workshop · priced after fit confirmation
A focused half-day with engineering and security stakeholders to map the system, expose the highest-value attack paths and agree the launch gates.
100% credited toward an assessment booked within 30 days.
Scoped assessment · proposal after the fit call
A controlled, ten-business-day adversarial assessment for one defined agent or tightly coupled workflow in an approved test environment.
The method is informed by the OWASP Agentic Security Initiative and NIST AI risk-management guidance. It is not a certification or compliance audit.
Confirm the agent, environment, allowed techniques, stop conditions, data handling and owners.
Trace inputs, models, retrieval, memory, tools, identities, approvals and business consequences.
Execute prioritized scenarios and capture enough evidence for engineers to reproduce the finding.
Separate root causes from symptoms, agree practical controls and verify the priority fixes.
deflation.ai builds and operates agents connected to email, telephony, calendars, business software and private data. That experience shapes a practical security view: the model is only one component. The larger risk lives in identity, permissions, memory, tools, approvals and operational containment.
The security practice is led by Harry Trippel, an agent engineer with a backend, security and technical-leadership background. Public methodology and technical case studies are being developed alongside the client work—without invented references or inflated claims.
Yes. It is a complete paid engagement with its own deliverable. If the resulting risk surface does not justify an assessment, you still receive a prioritized threat and control memo.
The standard engagement uses an approved test or staging environment with representative accounts and data. Production testing requires separate rules, safeguards and explicit written authorization.
Yes. The goal is not to throw a report over the wall. Engineers validate expected behavior, help confirm root causes and leave with practical remediation guidance.
It is an adversarial assessment of an agent system. It includes relevant application-security paths, but the core scope focuses on agent behavior, untrusted context, tool use, identity, memory and blast radius. It is not a compliance certification.
Evidence is minimized, stored only as agreed, shared with named contacts and deleted according to the engagement’s data-handling terms. Exact requirements are confirmed before access is granted.
In a 20-minute fit call, we will determine whether the readiness workshop, the assessment or no engagement is the honest next step.
Controlled testing only. Written authorization is required before any adversarial work begins.