Skip to main content

Research Guidelines

Effective date: August 31, 2026  ·  Last updated: August 31, 2026

Agentomy conducts adversarial security research against AI agent systems, including our own. These are the rules we hold ourselves to. They are written to be checked, not to reassure: where a claim can be verified against our public repositories, it is meant to be.

1. What we research

We research our own platform, the benchmarks we publish, and the agent frameworks we integrate with. That is the whole scope.

  • Our own platform and infrastructure, without limit.
  • Our published benchmarks and their scenario libraries.
  • Agent frameworks and protocols we integrate with, tested against instances we control.

We do not research customer deployments, third-party systems we have not been invited into, or anyone else’s production environment.

2. Consent

We test our own systems freely. We test a system belonging to anyone else only with written authorisation that names the scope and the window.

There is no exception for tests that appear harmless. A read-only probe against someone else’s infrastructure is still a probe against someone else’s infrastructure, and the judgement of whether it was harmless is not ours to make after the fact.

3. What we never do

  • No testing against production systems holding real personal data.
  • No denial-of-service or load testing as a research technique.
  • No social engineering of employees, contractors, or support staff.
  • No persistence, lateral movement, or data access beyond the minimum required to demonstrate that a finding is real.

4. Adversarial material we publish

We publish adversarial test material. We do not publish weaponised exploits. That distinction is concrete, and you can verify it rather than take our word for it.

Every fixture in our public benchmarks is stored encoded at rest and decoded only inside a test run, and every scenario is paired with an assertion that the governance layer refuses the input. The material exists to prove a refusal, not to perform an attack.

The practical consequence: you can take a scenario, run it against a system you control, and see whether it holds. You cannot lift a payload out of it and point it at someone else, because what is published is the test and its expected refusal, not a working tool.

5. Disclosure

If we find a vulnerability in a system that is not ours, we report it privately to the party responsible before telling anyone else. We propose a remediation window when we report, ninety days by default, and we will agree a longer one where the fix genuinely requires it.

We publish only after the window closes or the fix ships, whichever comes first, and we coordinate the timing with the affected party. We do not publish a working exploit at any point, before or after remediation.

If a party is unreachable or declines to engage, we will still not publish material that makes exploitation easier. The finding may be described; the method of exploiting it will not be.

6. What we publish and what we hold

Our benchmarks, methodology, and scoring records are public and reproducible. Anyone can run them against a live endpoint and check our numbers.

Findings that concern a specific customer are never published, in any form, including anonymised or aggregated. A customer’s governance posture is theirs to disclose.

7. Research into agent behaviour, not only infrastructure

Security research usually means probing networks and applications. A meaningful part of ours does not. Governance failures in agent systems often appear in behaviour rather than infrastructure: an agent that accepts an instruction it should refuse, that drifts from its declared purpose, or that inherits authority it was never granted.

Testing for those means exercising a model’s responses under adversarial conditions rather than scanning a host. We hold that work to the same rules above. Consent, scope, and disclosure do not change because the target is a behaviour rather than a port.

8. Reporting something to us

If you believe you have found a vulnerability in Agentomy, tell us before telling anyone else and we will do the same for you. Use the security contact route on our contact page. We will acknowledge receipt, tell you what we found when we have assessed it, and agree publication timing with you rather than announce it unilaterally.