How we engage
AI agent security assessment
MCP security review
Every engagement starts from your architecture and your threat model, not a generic checklist. Most clients begin with the two-week review and move to one of the build engagements once they know where the gaps are.
01 · 2 weeks · Fixed fee [CONFIRM: publish “from $18,000” or omit price]
Agent Security Architecture Review
We map every place your agents take input, hold state, and take action, then trace how untrusted data can reach a privileged action. You get a threat model written for your system, a ranked list of findings with the mechanism behind each one, and a design for the controls that close them. Covers agent identity and credential lifetime, authorization at the tool-call boundary, memory and config write paths, MCP server and tool trust, sandboxing and egress, and the monitoring you would need to notice an agent going wrong.
You receive
- a threat model document
- ranked findings with reproduction traces
- a control design your team can implement
- a customer-facing attestation letter on request
We need from you
- architecture diagrams
- tool and MCP definitions
- a staging environment or read access
- one engineer for questions
- an authorization signer
Get your top three exposure paths, freeAfter the review
agentic identity and authorization
02 · Agentic Identity and Authorization Design
4 to 8 weeks
Ephemeral, task-scoped credentials in place of long-lived tokens; authorization that evaluates each agent request against the task it was given; rate limiting on token consumption and behavioral baselines. Done inside a mature multi-tenant platform without rearchitecting its core.
03 · MCP and Tool-Use Hardening
2 to 4 weeks
We review each MCP server and tool your agents can reach, classify what each channel can inject, design taint tracking so model-derived data cannot flow into shell commands, file writes, or outbound requests unchecked, and gate memory and config writes as privileged actions.
04 · Agent Security Evaluation and Red Teaming
3 to 6 weeks, or ongoing
Full trajectories, not single prompts: injection through every input channel, tool misuse, exfiltration, privilege escalation, memory poisoning, multi-step attacks. Findings mapped to the OWASP agentic categories. Reproducible failing traces you can turn into regression tests, scored on false positives as well as catch rate, plus an evidence package for enterprise questionnaires.
05 · AI-Assisted AppSec Program Build-Out
8 to 12 weeks
The review process, standards, and evidence trail enterprise procurement asks for, then threat modeling automated with coding agents so every engineering team runs its own first-pass assessment. The program we built to unblock upmarket sales, adapted to your stack.
06 · Fractional Security Architect
retainer
A senior security architect embedded with your leadership and engineering teams a set number of days per month: design reviews for new agent features, incident support, vendor and model evaluation. For Series A to C companies that need the judgment before the headcount. [CONFIRM: publish "from $6,000/month" or omit]
Not sure which fits? The architecture review is where most engagements start, and its output is yours whether or not we do the build.
What an engagement looks like
- Named engineers before kickoff, so you know who shows up on day one
- A shared Slack channel for the engagement and a weekly written status
- Critical findings reported the same day, not in the final report
- A draft report with a review window, then a live walkthrough with your engineers
- One retest of fixed findings included
- NDA and written authorization before any testing; credentials rotated after; raw evidence deleted on a stated schedule
Architects who still ship
We read your code and your infrastructure before we write a recommendation. Findings come with the mechanism, not just the CVSS score, so your engineers understand why a control matters and can extend it without us. We write designs your team can implement, and when you want us to implement them, we do that too. Every engagement ends with something you own: a threat model, a design document, a test suite, or working code.
We have secured the systems you are trying to build
Launch security at Amazon scale.
Our principals served as security architects on Amazon Marketplace, Payments, and Prime Air, where the review standards they wrote became the baseline for new products.
Programs that cleared enterprise procurement.
They built application security and anti-abuse programs at SaaS companies like Smartsheet, including detection systems that held up under the industry-wide password-spray campaigns of 2024 and 2025, and designed the agentic identity and authorization model for a mature multi-tenant platform. [CONFIRM: employment-agreement check on naming Smartsheet]
Pre-launch testing delivered on deadline.
In 2019 Foretheta ran the penetration test of Stacks' public web properties, working directly with its Head of Engineering, reporting twice a week, and closing with a final report and wrap-up review inside a three-week window. We have provided security code review to teams building on the Stacks Clarity platform since. [CONFIRM: naming rights and, if available, a one-line quote from the Stacks engineering lead]
We run agents and the infrastructure behind them in production ourselves, so every control we recommend is one we have had to live with.
20+
years of security engineering across Amazon, Microsoft, Smartsheet, and telecom
1,000+
engineers trained and mentored on secure-by-design practice
Procurement
security programs that cleared enterprise procurement and opened upmarket sales
Pre-launch
penetration tests delivered on deadline for public technology companies
Carnegie Mellon MS in Information Security Policy and Management · Co-inventor, U.S. Patent 10,728,272, risk scoring in a connected graph
[CONFIRM: name, title, headshot, LinkedIn URL for one principal]
From our research
Technical analyses of how agents fail, and what would have stopped it
All researchOne article a week. Each one takes a real incident or experiment, explains the mechanism, and names the control we would build.
18 September 2026
Guardrail models judge from the transcript, and the agent authors most of it. Why self-report is a soft gate, and how to give the monitor a view the agent cannot write to.
Read the analysis →17 September 2026
A payload split across an MCP tool description, a tool result, and a sampling message defeats every single-channel check. What privilege separation between channels looks like.
Read the analysis →15 September 2026
An injection an agent judges worth remembering becomes a standing instruction in every later session. Why it persists, and the memory-write control that stops it.
Read the analysis →Get one article a week, plus the 20 questions we ask in the first week of every review. [CONFIRM: the 20-question checklist PDF to attach to the welcome email]
Questions we get on the first call
Our pen-test vendor already tests the product.
Pen tests probe the application. Agents add a layer where the attacker's input arrives as a document, a tool description, a schema, or an image, and where the harmful action is one the agent was authorized to take. That is what we test and design for; most pen-test scopes do not include it yet.
Our model provider is responsible for prompt injection.
The provider defends the model. Your agent's tools, credentials, memory, and permissions are yours, and every failure described on this page happened in that layer.
We cannot share source code.
Most reviews start from architecture diagrams, tool definitions, and a walkthrough with your engineers. We work under NDA and can review inside your environment.
We are too early for this.
The two-week review is sized for a team of five. Getting agent identity and tool permissions right before the first enterprise customer is cheaper than retrofitting after.
How is this different from a general AppSec firm?
Our principals designed agentic identity and authorization for a production multi-tenant platform and publish on agent failures every week. General AppSec firms are learning this on your engagement.
What does it cost?
The review is fixed-fee [CONFIRM: "from $18,000"]. Build engagements are quoted after the review. The fractional architect is a monthly retainer with no minimum term beyond the first month.
Start with a 30-minute architecture conversation
Tell us what your agents do, what they can reach, and what worries you. We will tell you where we would look first and whether a review makes sense. No deck, no discovery questionnaire.
or email security@foretheta.com
We respond within one business day. Engagements are fixed-fee or retainer, quoted after the first call.