Security & Compliance

Your data, our posture

AgentRedTeam processes the inputs you submit for analysis. This page states, plainly, what we handle and what we do not claim.

What we handle

AI agent descriptions, capability lists, and threat-focus selections you submit for adversarial simulation.

Data handling commitments

  • Submissions run the product pipeline and are retained only as long as needed for your audit log (paid tiers) or until you delete the run.
  • We apply access controls consistent with GDPR Art. 32 (security of processing) where personal data is processed.
  • BYOK keys (Enterprise), when offered, are stored server-side only and never exposed to the browser.
Honesty rule: Red-team results are decision-support. We do not guarantee you will find every vulnerability, achieve 100% coverage, or never miss an attack path. We do not claim guarantee / 100% / never miss.

Our compliance posture

  • AgentRedTeam is decision-support, not a law firm, clinic, or certified auditor.
  • For binding advice, consult a qualified professional in the relevant domain.

Subprocessors & payments

  • Payments are processed by Waffo Pancake (merchant of record).
  • See Privacy and Terms for full terms.

refs: OWASP LLM Top 10 (LLM01 Prompt Injection) · OWASP Top 10 for AI Agents · NIST AI RMF

AgentRedTeam

Break your AI agents before attackers do.

Features

  • Identify likely attack vectors against your agent
  • Simulate prompt-injection and tool-abuse risks
  • Score your agent's exploitability
  • Get a prioritized hardening checklist

Legal

© 2026 AgentRedTeam. All rights reserved.