How easily can it be moved?
Search for conditions that change the agent’s behaviour instead of replaying only a public list of attacks.
TRUSCOR adversarially tests live third-party AI agents, records what they can actually reach and do, and produces reproducible evidence for people who need more than the operator’s own assurance.
Current status is stated on this page. Planned products are labelled; projections are not presented as measurements.
A system inventory says what an agent should be able to do. TRUSCOR is built to establish what happens when somebody actively tries to move it outside that intention.
Search for conditions that change the agent’s behaviour instead of replaying only a public list of attacks.
Map the tools, identities, data, systems, and transitive access available to the live deployment.
Connect observed reach to a transparent model of deployment-specific loss. This modelling layer is designed, not validated.
The working MVP runs this five-phase pipeline end to end against live systems. Production controls and the wider product layers remain in development.
Empirically identify tools, data sources, identities, permissions, approval gates, and transitive access.
OUTPUT · CAPABILITY-REACH GRAPHConstruct adversarial conditions around the deployment’s actual tools, language surface, and permission structure.
OUTPUT · CONDITION SETExecute only under written authorization and within an agreed scope. Hardened blast-radius controls remain in development.
OUTPUT · CONTROLLED RUNRecord inputs, retrievals, tool calls, state changes, and boundary crossings so a finding can be reproduced.
OUTPUT · EVIDENCE TRACEGrade observed behaviour and state assumptions around exposure. TAFAAR is designed, not validated.
OUTPUT · GRADED FINDINGThe maturity label is part of each claim. A roadmap item does not become a product merely because it has a name.
The proprietary core maps live systems, composes adversarial conditions, executes controlled runs, captures traces, and grades findings.
Runs end to end todayA framework intended to translate observed agent behaviour into transparent, deployment-specific loss ranges.
No production implementation or back-testing yetA planned local-first toolkit and open evidence format for engineers examining their own systems.
Not launchedA decomposable risk record and third-party artifact for a defined system, scope, and point in time.
Not currently issuedTechnical facts about AI components and deployment shape for an underwriter making its own decision.
No live API todayReconstruction of memory, retrieval, tool calls, and fault boundaries after an incident.
Commercial layer not yet liveTRUSCOR is early. The useful way to earn trust at this stage is to separate working capability from intended capability and leave both visible.
TRUSCOR’s evidence is meant for people who care whether the examiner has a stake in the conclusion.
Describe what failed and how to reproduce it; do not implement the repair.
Take no referral fee, revenue, or other consideration from remediation vendors.
TRUSCOR evaluates third-party systems, not products built by XAGI Labs.
Provide evidence, not an underwriting decision or a stake in its outcome.
Appear as a neutral examiner or do not take the engagement.
Consume existing SOC 2, ISO 27001, and VAPT evidence as inputs instead.
Visit the product website for the current TRUSCOR programme and contact path.
Go to truscor.org →