Baseline
$6,500
5 business days
One agent flow, full 51-scenario suite, single-model run, judge-triangulated score.
AgentBoundary Certified
Independent adversarial testing against 51 real prompt-injection scenarios, objective active-execution scoring, and a verification package grounded in the open AgentBoundary benchmark.
Certification paths
AI SaaS vendors selling into the enterprise, security teams deploying internal copilots and agents, and LLM/MLOps platforms that need a neutral trust signal.
Use this before enterprise security review, before granting production access to an agent, or when a model upgrade has invalidated prior testing.
The problem
Certification tiers
Three tiers, from a single-flow baseline to a board-ready engagement with bespoke adversarial scenarios.
$6,500
5 business days
One agent flow, full 51-scenario suite, single-model run, judge-triangulated score.
$18,000
10 business days
Up to three agent flows, all four scenario types (RAG, filesystem, browser, code), cross-judge triangulation, one rerun after fixes, procurement memo.
$38,000
15 business days
Up to six flows, full suite plus bespoke attack extensions, executive readout, remediation workshop, quarterly recert option.
Pricing is anchored to tier-2 penetration-test budgets and the cost of unblocking a single enterprise deal. Annual recertification runs 55–60% of the initial tier; delta-recerts after a major model change are scoped to the affected flows.
What you receive
Overall compliance %, per-attack-family rates, Wilson confidence intervals on every rate, and a 0–100 AgentBoundary Robustness Score.
The failing prompts, execution traces, root-cause patterns, and a severity-ranked remediation backlog written for engineering action.
Methodology, judge-triangulation summary, scope boundaries, explicit limitations, and a signed attestation letter.
12-month verification listing with tier, certification date, verification URL, and revocation terms. Confidential by default; the vendor controls publication.
Annual recert plus triggered recert after a major model or agent-architecture change, so the badge always reflects current behavior.
Methodology
The certification runs on the same published methodology as the open AgentBoundary benchmark, so every score is reproducible and defensible under scrutiny.
Hard questions, answered
“We already run the open-source benchmark, or our internal red team tests this.”
Self-attestation rarely satisfies external security review. Certification converts your internal security work into neutral, third-party artifacts with a defensible audit trail grounded in the open methodology.
“LLM-as-judge scoring is subjective, or could be wrong.”
We use active-execution scoring with structured JSON rubrics, three architecturally distinct judges, and Wilson score confidence intervals on every claim. That is the research gold standard, not a single-model opinion.
“A bad score could be used against us.”
All results are confidential. You have sole discretion over whether and when to display the public badge. A private pre-certification window is included; publish only after a remediation pass clears your chosen threshold.
Why it holds
The benchmark is open by design. The certification adds a published methodology, a repeatable adversarial dataset, active-execution scoring, signed validation materials, and a clear audit trail that security and procurement teams can review.
Certification scope
Apply to start with a short scoping call. Turnaround, remediation windows, and any public verification options are confirmed in scope.