AI assurance

Independent testing for the AI you've already deployed

Agents, copilots and AI-powered features change behaviour when the model, prompt or vendor changes. We test them the way an attacker would and give you evidence you can stand behind.

What we test for

Prompt injection

Can a document, email or web page hijack the agent's instructions?

Sensitive-data leakage

Does the system reveal customer records, credentials or internal content it shouldn't?

Excessive permissions

Can the agent read, write or act on more than its job requires?

Unsafe tool use

Can it be talked into sending, deleting, paying or executing something harmful?

Three ways to engage

Pick the one that matches where you are. Most organizations start with a review.

Point in time

Agent Security & Safety Review

For any organization running AI agents or copilots. A structured test of one system against the four categories above, plus a fix-first list.

  • Threat model of the agent, its tools and its data
  • Hands-on adversarial testing
  • Findings ranked by impact, with remediation steps
  • Executive summary for non-technical readers
Book a review

Multi-system

Enterprise Assurance Pilot

For larger or regulated organizations with several AI systems in play. We inventory everything, test the highest-risk systems, and set up the evidence trail.

  • Inventory and classification of all deployed AI
  • Reviews of the highest-risk systems
  • Assurance evidence mapped to your obligations
  • Roadmap for ongoing coverage
Discuss a pilot

Ongoing

Continuous AI Assurance

For existing customers. We re-test on a schedule and whenever your model, prompts or configuration change, so regressions are caught before your customers find them.

  • Scheduled and change-triggered re-testing
  • Behavioural regression alerts
  • Up-to-date evidence pack, always ready to share
  • Named contact who knows your systems
Ask about continuous assurance

Evidence, not reassurance

Every engagement ends with material written for the people who have to sign off: what was tested, what was found, what was fixed, and what remains. It's built to be handed to a board, a customer's security team, or a regulator without a translator.

We're independent of the model vendors and the platforms you build on, so the findings are ours, not theirs. Where Onxtra built the system being reviewed, the report says so on the first page, and we'll support a third-party review of the highest-risk findings if you want one.

Each engagement also strengthens the reusable assurance platform we're building and validating with Canadian customers, so the checks get sharper over time. More about the platform and our research.

Who the evidence is for

  • Management deciding whether to expand AI use
  • Customers asking what you've done to protect their data
  • Regulated environments that need a defensible record
  • Your own engineers who need to know what to fix first

Running AI agents already?

A security and safety review shows you what an attacker would find. Tell us what you've deployed and we'll scope it.

Book an agent security review