TKOResearch
Menu

AgentBoundary Certified

The procurement-grade robustness certification for AI agents.

Independent adversarial testing against 51 real prompt-injection scenarios, objective active-execution scoring, and a verification package grounded in the open AgentBoundary benchmark.

Who it is for

AI SaaS vendors selling into the enterprise, security teams deploying internal copilots and agents, and LLM/MLOps platforms that need a neutral trust signal.

When to certify

Use this before enterprise security review, before granting production access to an agent, or when a model upgrade has invalidated prior testing.

The problem

Procurement asks for proof. Vendors have only claims.

  • AI agents are shipping before their boundary controls are validated under adversarial execution — speed-to-market is beating security review.
  • Enterprise security questionnaires demand artifacts; vendors supply claims. There is no neutral, reproducible attack-test standard to point to.
  • Every model swap or prompt change silently shifts safety behavior between annual audits — robustness is not a one-time property.

Certification tiers

Three tiers, from a single-flow baseline to a board-ready engagement with bespoke adversarial scenarios.

Baseline

$6,500

5 business days

One agent flow, full 51-scenario suite, single-model run, judge-triangulated score.

Production

$18,000

10 business days

Up to three agent flows, all four scenario types (RAG, filesystem, browser, code), cross-judge triangulation, one rerun after fixes, procurement memo.

Board-Ready+

$38,000

15 business days

Up to six flows, full suite plus bespoke attack extensions, executive readout, remediation workshop, quarterly recert option.

Pricing is anchored to tier-2 penetration-test budgets and the cost of unblocking a single enterprise deal. Annual recertification runs 55–60% of the initial tier; delta-recerts after a major model change are scoped to the affected flows.

What you receive

A certification package built for security and procurement review.

Boundary Robustness Scorecard

Overall compliance %, per-attack-family rates, Wilson confidence intervals on every rate, and a 0–100 AgentBoundary Robustness Score.

Technical Report

The failing prompts, execution traces, root-cause patterns, and a severity-ranked remediation backlog written for engineering action.

Procurement Appendix

Methodology, judge-triangulation summary, scope boundaries, explicit limitations, and a signed attestation letter.

Public Verification Badge

12-month verification listing with tier, certification date, verification URL, and revocation terms. Confidential by default; the vendor controls publication.

Recertification Plan

Annual recert plus triggered recert after a major model or agent-architecture change, so the badge always reflects current behavior.

Methodology

Academically rigorous, operationally sharp.

The certification runs on the same published methodology as the open AgentBoundary benchmark, so every score is reproducible and defensible under scrutiny.

  • Active-execution scoring standard — mere restatement or echoing of injected text is explicitly not counted as compliance.
  • Cross-judge triangulation across three architecturally distinct judges to remove single-model bias.
  • Wilson score confidence intervals on every binomial compliance rate, reported transparently.
  • Attack families covered: markdown injection, cognitive overload, RAG poisoning, context drift, and HTML injection.
  • Agent scenario types covered: RAG, filesystem, browser, and code agents.

Hard questions, answered

We already run the open-source benchmark, or our internal red team tests this.

Self-attestation rarely satisfies external security review. Certification converts your internal security work into neutral, third-party artifacts with a defensible audit trail grounded in the open methodology.

LLM-as-judge scoring is subjective, or could be wrong.

We use active-execution scoring with structured JSON rubrics, three architecturally distinct judges, and Wilson score confidence intervals on every claim. That is the research gold standard, not a single-model opinion.

A bad score could be used against us.

All results are confidential. You have sole discretion over whether and when to display the public badge. A private pre-certification window is included; publish only after a remediation pass clears your chosen threshold.

Why it holds

The benchmark is open by design. The certification adds a published methodology, a repeatable adversarial dataset, active-execution scoring, signed validation materials, and a clear audit trail that security and procurement teams can review.

Certification scope

Certify your agent before your next enterprise security review.

Apply to start with a short scoping call. Turnaround, remediation windows, and any public verification options are confirmed in scope.

Apply for certification