Security & compliance review

Find out what your AI agent can get you into, before a caller does.

We test your AI voice agent the way callers will and check it against the rules it has to follow: what it promises, what it reveals, what it tells callers, who it calls, and what abuse would cost. You get a written report and a fix list.

What we check.

What it can be talked into

Refunds, discounts, exceptions to your policies, and instructions to ignore its instructions. We call it the way a determined caller would.

What it gives away

Other callers' details, its own instructions, and anything in its knowledge base that isn't meant for customers.

What it tells callers

That it's an AI, that the call is recorded, and how to reach a person, where and when the rules require it.

Who it calls and texts

Consent for outbound calls, do-not-call handling, calling hours, and whether it can be steered into dialing premium-rate numbers.

What data it touches

Every tool and lookup it can use, how it checks who's calling, and, in healthcare, the vendor agreements the law expects.

What abuse would cost

Floods, long calls, concurrency and spend limits, and whether you'd find out tonight or at the end of the month.

How it's put together

Whether policy lives in a prompt or somewhere you can change safely, what sits between the model and its tools, and whether a fix for one problem can be made without moving everything else.

How it works.

  1. 1

    Tell us about the agent

    The form below: where it runs, what it does, and what worries you. We reply within one business day.

  2. 2

    We call it, and read its setup

    Dozens of test calls: ordinary, messy and hostile. Then its instructions, tools and settings, read-only.

  3. 3

    You get the report

    Every finding, ranked by risk, with the call that shows it and the change that fixes it.

  4. 4

    We check the fixes

    Once you've made the changes, we run the calls that failed again and confirm they hold.

Who it's for.

  • Businesses about to put an AI agent on their phone line
  • Teams whose agent is live and who want to know what it's been saying
  • Agencies shipping agents for clients, who want proof before hand-off
  • Anyone in healthcare, legal or finance, where a wrong answer costs more than a refund

Request a review.

Tell us about the agent. A person reads every request and replies within one business day with next steps and a price.

A person reads every request. We don't share what you send.

Questions people ask first.

Do you need access to our systems?
A phone number to call, and a read-only look at the agent's instructions, tools and settings. We don't need to change anything.
Which platforms?
Vapi, Retell, ElevenLabs, Synthflow, Bland, and agents built from scratch.
Is this legal advice?
No. We check your agent against common legal requirements and against how it behaves on real calls, and we flag what a lawyer should look at. We're not a law firm.
What does it cost?
It depends on what the agent does and how much it touches. We'll give you a fixed price after reading your request, before any work starts.
How long does it take?
We'll give you a date when we reply. Most of the time goes into the test calls.
Can you fix what you find?
Yes, if you'd like us to. Or hand the report to whoever built it: every finding comes with the change that fixes it.