TRUSTLI

Trustli

How we connect

Short version: we don't. Nothing installs, nothing integrates, and no software of mine ever runs inside your systems.

If I had to plug into your stack to check it, I'd be a security risk myself.

The whole value of an independent assessment is that the assessor stays outside. You hand me evidence; I never reach in and take it.

What you send me — three things

1

A staging copy of the agent

An endpoint I can talk to, with test credentials — the same instance you'd hand a QA tester. Not production. No real customer data.

My probe agents hold conversations with it and try to push it off-script: prompt injection in several styles, broken and failing tool calls, ambiguous "are you finished?" traps. The probes run on different underlying models from each other, because different models miss different things.

endpoint URL + test key · or a sandbox account · your rate limits respected
2

The agent's configuration

System prompt, tool and function definitions, the scopes and permissions it runs with, plus any spend or rate ceilings. A file, a repo link, or a redacted export — whatever is easiest.

tells me what it CAN do · the logs tell me what it DOES do
3

A week of logs

Whatever your agent already writes. An export is fine; if you'd rather, a read-only viewer key to your logging tool works too. Redact freely — I'm looking at behaviour patterns, not content.

JSON, CSV, plain text, OpenTelemetry — all fine

Then what happens

I run the fifteen checks. Where the evidence answers a check, it's graded. Where it doesn't, I come back with specific questions — never a generic questionnaire, always "your config shows the agent can do X, is there a ceiling on that, and where is it enforced?" That conversation takes about ten minutes and it's the only meeting required.

You get a signed verdict listing every check with its evidence, and a public badge page your customers' security teams can read in minutes. If something fails, you get the finding and what "fixed" looks like — free, and re-verification after you fix it is included, never billed.

Total effort on your side: about an hour of one engineer's time. Most of it is exporting things you already have. There is nothing to build, install, configure, or maintain.

What I will never ask for

Write access. To anything. Not to your systems, your data, or your agent's production credentials. If you offer them, I'll decline — read-only is a structural guarantee, not a policy I could quietly relax.
Production access. Live testing only ever runs against the staging instance you designate.
Anything running inside your infrastructure. No agent, proxy, or container of mine sits in your stack. Nothing to review, nothing to patch, nothing that can break at 3am.

Read the 15 checks →