Advisory · AI Agent Security · Built in Norway & the UK
Do you know what your AI agents can actually do?
Agents act as well as answer. They read your data, take in content you don't control, and send things on your behalf. We find every agent you run, audit each one against the same six checks, and show you which are one prompt injection away from leaking data.
Simon Willison's lethal trifecta names the combination that turns a helpful agent into a way to steal data. Any one of these is fine. All three in the same agent means an attacker only has to get some text in front of it.
Private data
The agent can read files, mailboxes, customer records or source code.
SharePoint sites, Microsoft Graph, CRM, knowledge sources
Untrusted content
The agent takes in text that someone outside your organisation can write.
Inbound email, shared documents, web pages, external chats
A way out
The agent can send information beyond your boundary.
Webhooks, custom connectors, outbound mail, HTTP tools
The fix is rarely to switch the agent off. It is to cut one leg: narrow what it reads, stop it ingesting outside content, or remove the route out. The audit tells you which leg is cheapest to cut for each agent.
Inventory & ownership
Every agent found and listed, from Copilot Studio and Power Platform to custom builds and MCP tools, each with a named owner and a stated purpose.
Identity & permissions
What each agent runs as, whether it borrows a person's credentials, and whether its scopes are wider than the job needs.
Lethal-trifecta exposure
Which agents combine private data, untrusted content and a way out, and which single leg to cut to make each one safe.
Human oversight
Which actions an agent can take on its own, which need approval, and whether that approval is a real check or a rubber stamp.
Logging & evidence
Whether you can reconstruct what an agent read, decided and did, and how long that record is kept.
Lifecycle & kill switch
How agents are approved, changed and retired, who can stop one quickly, and what happens to orphaned agents when their maker leaves.
Discover
We find every agent, connector and tool in use, including the ones nobody registered.
Map
Each agent is mapped to the data it reads, the content it ingests and the routes out.
Audit
Every agent is scored against the six checks, with evidence for each finding.
Report
You receive the inventory, trifecta map and fix list, walked through with your team.
Working towards the AI agent standard? See AIUC-1 readiness
Find out which agents hold all three.
Book a 30-minute call. We'll walk through the six checks and what an audit of your agents would cover. How many agents are you actually running?
OWASP LLM Top 10 · AIUC-1 · EU AI Act · NIST AI RMF · ISO 42001