Agentic system threat review
Before launch or before expanding an agent's tools, memory, spend or data access.
Evidence delivered: Trust-boundary model, authority inventory, ranked abuse cases and a sequenced control plan.
Bounded services / evidence-led delivery
Every engagement begins with an owner, an explicit question and a bounded scope. Active testing requires written Rules of Engagement.
Before launch or before expanding an agent's tools, memory, spend or data access.
Evidence delivered: Trust-boundary model, authority inventory, ranked abuse cases and a sequenced control plan.
For a release candidate or production system with an owner who can authorize bounded testing.
Evidence delivered: Evidence-backed findings, attack paths, remediation guidance, decision brief and one verification round.
For teams that already have findings and need an independent, fixed-scope closure record.
Evidence delivered: Evidence comparison and a finding-by-finding state: fixed, mitigated, accepted or still open.
For teams that need security to become part of delivery rather than a periodic audit event.
Evidence delivered: Risk ownership, minimum controls, release gates, vulnerability intake, incident paths and evidence cadence.
Map human, service and agent identities, delegated permissions and revocation paths before authority becomes an incident.
Review MCP tools, APIs, data, memory, egress and side effects at action time — not only in prompts or static configuration.
Leave reproducible evidence, an owner for each finding, a remediation path and one agreed verification step.
When an MCP server is in scope, the review can inspect its discovery metadata, tool contracts, authorization, validation, side effects, egress and recovery boundary. Written Rules of Engagement are required before active testing.
Before choosing a service, use the field guides to frame the system, authority, MCP surface and evidence that will change your decision.
Delx Security does not perform unbounded testing, certify whole organizations, guarantee security or treat a framework mapping as legal compliance.
Denial of service, destructive testing, persistence, social engineering and third-party targets are excluded unless the exact technique and owner authorization are separately written.