DELXSECURITY

AI agent security assurance method / v1.0

Security work with a boundary, a burden of proof and an ending.

The six-phase method joins organizational risk, agent-specific attack paths and application security verification in one decision-grade record.

Direct answer

Frame → Map → Challenge → Evidence → Remediate → Verify

Start with the decision and the owner, map authority and trust boundaries, use the smallest authorized technique that can test the risk, and close only the finding whose changed behavior was actually verified. The output is a bounded record with explicit scope and residual risk — not a generic scanner score.

Six phases

01

Frame

Document mission, system boundaries, business impact, authorized techniques and explicit exclusions.

02

Map

Model assets, identities, data, tools, trust boundaries, dependencies and plausible adversaries.

03

Challenge

Exercise the highest-risk paths with safe, proportionate and pre-authorized techniques.

04

Evidence

Record reproducible proof, affected assets, preconditions, impact and confidence for each finding.

05

Remediate

Prioritize structural fixes, compensating controls and ownership against real risk.

06

Verify

Retest the changed behavior and issue a clear record of fixed, accepted and residual risk.

Evidence map for an agent security decision

Each control question ends in an observable proof and an accountable decision. This keeps a polished score or framework label from standing in for runtime evidence.

Identity and authority

Who can act, for which owner and under what limit?

Evidence to inspect: Identity sources, delegated scopes, approval records and revocation evidence.

Tools and side effects

What can the agent change, send or spend at execution time?

Evidence to inspect: Tool schemas, API permissions, resource access, egress paths and action logs.

Context and memory

Which inputs can become durable instructions or authority?

Evidence to inspect: Retrieval provenance, prompt and tool-output boundaries, memory writes and retention rules.

Failure and recovery

What happens when the agent is wrong, compromised or unavailable?

Evidence to inspect: Detection, stop paths, human escalation, rollback, continuity records and recovery tests.

Agentic control plane

Identity

Named actors, no ambient trust

Human, service and agent identities are attributable, authenticated and separately authorized.

Authority

Least privilege at action time

Tools, resources, spend and side effects are bounded before execution and revocable during it.

Context

Memory is an integrity boundary

Sources, retention, retrieval and writes are governed so hostile context cannot become durable authority.

Recovery

Safe interruption is a feature

Monitoring, human escalation, kill paths and continuity records support containment and recovery.

What the report says

  • Scope, authorization and limitations stated before findings.
  • Executive decisions separated from technical evidence.
  • Severity based on exploitability, business impact and existing controls.
  • Reproduction and remediation guidance proportionate to the risk.
  • Verification status for every finding: open, mitigated, fixed or accepted.
  • No certification language unless a qualified certification body issued it.

When to use the method

Before launch

Frame new authority

Use it before an agent gains tools, memory, sensitive data, spend or a material third-party dependency.

During change

Revisit the control plane

Re-run the relevant phases after an architecture, model, workflow, identity or supply-chain change.

After remediation

Verify the actual behavior

Repeat the original proof, check adjacent regressions and record what remains fixed, mitigated, accepted or open.

Direct answers

Q&A

What is the Delx Security assurance method?

It is a bounded six-phase method for turning a security question into a decision-grade record: Frame, Map, Challenge, Evidence, Remediate and Verify.

Q&A

Is the Delx method the same as a penetration test?

No. The method can include proportionate authorized testing, but it begins with scope, authority and a threat model and uses the smallest technique that can prove or refute a hypothesis. A penetration test is only one possible activity inside an explicitly authorized scope.

Q&A

What evidence does an AI agent security assessment produce?

It connects identity and authority, tools and side effects, context and memory, and failure and recovery to observable proof: a signed scope and Rules of Engagement, inventories, timestamped logs, reproductions, remediation ownership and a repeatable verification step.

Q&A

When can active security testing begin?

Only after the system owner accepts an auditable scope that names assets, techniques, timing, contacts and stop conditions. Documentation and benign evidence come first, and unexpected sensitive access or instability triggers a stop and incident path.

Q&A

Does this method certify that a system is secure?

No. It reports the tested scope, evidence, limitations, findings and residual risk. Framework alignment is a vocabulary for coverage, not a certification or a guarantee about future releases.