Agent security audit
2 critical0 critical
before production access
- Client
- Industry
- Software
- Region
- Germany
- Moves
- Secure
- Kick-off to hand-over
- 3 weeks
- Year
- 2025
01The void
An internal agent could read tickets, write to the CRM and send mail. Nobody had mapped what it would do if a ticket told it to.
02Results
Sample figures. Replace with the numbers the client signed off.
03How we worked
- 01 · 1 dayFind the void
Kick-off with security and the agent team. Threat model on one page.
- 02 · half a weekScope & evals
Scope: tools, identities, data paths. Attack plan agreed.
- 03 · —Build
No build: we tested what was there.
- 04 · 2 weeksSecure & comply
Prompt injection through tickets, tool abuse, data exfiltration. Every fix verified.
- 05 · half a weekHand over
Report, retest, and the tests left in their pipeline.
04What we built
- 01Ticketsuntrusted input
- 02Agentmodel + tools
- 03ToolsCRM, mail, files
- 04Identityservice account
- 05 · controlGuardrailsallow-lists, approvals
- 06Logsevery tool call
05Guardrails
- Least-privilege scopes per tool
- Human approval for outbound mail
- Injection tests in CI
06Stack
07In their words
A quote from the process owner goes here, once they have approved it. No invented testimonials.
More cases like this
of inbound claims, handled end to end
Insurance · Germany · 20257 weeks
Claims triage agent
6 days → 4 hourstime to first decision
critical issues before the investors looked
Software · Germany · 20262.5 weeks
Vibe coding audit before due diligence
It works. → It’s safe.what the data room says
of client data leave the bank’s tenant
Finance · Switzerland · 20258.5 weeks
Confidential knowledge assistant
SaaS. → In-house.where the model runs
Case #10
Your void could be
the next one.
A first call about your void. No deck. If it isn’t a fit, you’ll hear that too.
Find our void