Your agent sends messages, updates records, reads customer data — in your
name. When an enterprise buyer asks how you know it won't do something it shouldn't,
"trust us" is an expensive answer.
Fifteen published checks, run by an independent human against a staging copy of your
agent. Not a questionnaire, and not paperwork — the checks are exercised live, by probe
agents built on different models, because different models have different blind spots.
Blind — can it fail safely?
Failure recovery, environment awareness, in-flight checks, guardrails and spend
ceilings, and an append-only action log. Fail any of these five and no badge is issued
at all — that rule is why the badge means anything.
Unsupervised — does it know when it's done?
Stop rules, independent verification the agent can't rephrase, completion proof it
doesn't control, loop detection, persistent state, effort routing.
Unaccountable — can its claims be checked?
Whether what the agent says it did can be confirmed against a record it doesn't write,
plus ownership and error-routing for multi-agent systems.
How it runs
You point me at a staging copy of the agent, plus configs and a week of logs.
Read-only, always — there is no mechanism by which I can touch your production systems,
and I never ask for write credentials.
A short conversation confirms what the agent may and may not do, in your words:
the handful of "never" statements that define its lines.
The checks run, including live challenge testing against the staging instance.
You get a signed verdict — every check, pass or fail, with its evidence — and a
public badge page your customer's security team can audit in minutes.
$199 per agent, per month
Flat. No setup fee, no contract, cancel any time. Month one includes the full scan
and your badge; after that I re-run the checks on your cadence and the badge always
shows its true last-verified date. Verdicts expire at six months — a badge that stops
being re-earned stops claiming to be current.
If your enterprise customer's security team won't accept the report,
you get a full refund.
Four things Trustli will never do
Never sell you the fix.Findings and the fix path are free in your report. Re-verification after you fix
something is included and never billed. An assessor who also sells remediation has a
reason to find work — I don't have that reason.
Never take write access.Read-only by construction. Live testing only ever runs against a staging instance
you designate.
Never let an AI decide the verdict.AI reads evidence and runs challenges. Verdicts come from written, published rules
and are signed by a named human.
Never claim what I can't show.Continuous automated monitoring and a cryptographic public log are on the roadmap
and are not running today. When they are, this page will say so.
Who signs it
Paul Hopcraft. Twenty-plus years helping companies find problems before they cause harm
— workplace health and injury prevention — and I run write-access AI agents inside my own
businesses every day.
The first scan Trustli ever ran was on my own agents. They failed 6 of the 15 checks,
and the results are public. Independent means the verdict can hurt.