BlackNesherAgentic AI Security Assessment
Consent-based only
Trust & Compliance

Authorization first. Every time.

We perform real adversarial actions against submitted AI systems. That only happens with explicit authorization — never against a live third party you haven't told us you own or are cleared to test.

Authorization

Consent-based testing only

Every submission requires explicit attestation that you own the system or hold clear authorization to have it tested. We log the timestamp, IP address, and submitted content of every request as part of that authorization record. See our Terms of Service for the full policy.

Standards

MITRE ATLAS-mapped findings

Every technique maps to an official MITRE ATLAS or ATT&CK technique ID, cross-checked live against the published framework — not a subjective in-house severity label.

Grounding

Live NVD/CVE cross-reference

Where a finding relates to a known vulnerability class, we cross-reference live against the National Vulnerability Database rather than relying on a static, potentially stale internal list.

Confidentiality

Methodology stays protected

Customer-facing reports show what was found and how severe it is — not the exact payload or reproduction steps. That protects both your system (no exploit recipe left lying around) and our methodology.

Data handling

Minimal retention, no resale

We don't sell submitted data. Submission content and results are retained only as long as needed to deliver the service and maintain the authorization record. Full detail in our Privacy Policy.

Infrastructure

Access-controlled by design

Every table backing this platform runs with row-level security enabled and no public policies — all access goes through server-side, service-role-gated routes. There is no direct client-side path to raw data.

What happens if a submission looks unauthorized

We rely on the submitter's attestation, but that attestation isn't a blank check — if we receive a good-faith claim from a system owner that their system was submitted without authorization, or a valid legal request, we will provide the logged submission record (timestamp, IP, content) and take the claim seriously. False attestation carries real liability for the person who submitted it — see Section 3 of our Terms of Service.

Questions about authorization, data handling, or compliance for your specific use case? Talk to us.