ApexClaw
Home › Contact
Contact

Three questions get you to the right starting point — they shape the first call rather than gate it.

Most conversations start with the Agent Trust Gap Brief because it is fast and tells you whether more is warranted. If an agent has already done something unexpected, start with incident response instead.

Get an Agent Trust Gap Brief

Three questions, then a conversation

Rather than a long discovery form, three questions get you to the right starting point. Send them in any format — the answers shape the first call, they do not gate it.

  1. What can your agents currently access? Tools, data, systems, money — roughly is fine.
  2. What consequence worries you most? An unauthorized send, a spend event, a compliance question you could not answer, an incident you could not reconstruct.
  3. What do you need next? A fast read, a full audit, help after something already happened, or a governed pilot.

Where to start

Agent Trust Gap Brief

The fast, low-friction read. Most engagements start here because it tells you whether the rest is warranted.

Details →

Agent Trust Audit

The full assessment: inventory, permissions, MCP exposure, evidence, revocation testing, remediation roadmap.

Details →

Something already happened

If an agent has acted outside what you intended, start here instead — containment before assessment.

Incident response →

Reach us

Email: julian [at] thruliquid [dot] com

Security reports: see security.txt (RFC 9116). Findings about agent-facing surfaces — MCP endpoints, published schemas, the signing key directory — are especially welcome.

Honest note  A server-side intake form and calendar booking are on the roadmap and not yet live. Until they are, this page says so rather than implying an automated pipeline that does not exist. Enquiries are read and answered by a person.

Regions we cover

Regulatory coverage spans seven regions, each with its own real detail page rather than a single generic claim:

What happens after you reach out

  • A person reads the message — there is no automated intake pipeline, and the page says so rather than implying one.
  • The three questions above determine the starting point: a Gap Brief, a full audit, or incident response.
  • NDAs are signed by default for client engagements; results are treated as confidential unless the client chooses otherwise.

Common questions

What is the fastest way to start?

Request an Agent Trust Gap Brief. It requires no system access and produces a specific list of gaps.

Do you work outside your home market?

Yes. Regulatory coverage spans the EU, US, UK, Canada, Middle East, APAC and Latin America.

What if we have an incident right now?

Say so. Incident response is prioritised over assessment work.

Do you sign NDAs?

Yes. Client engagements and results are treated as confidential by default.

Is there a security contact?

Yes — see /.well-known/security.txt for the disclosure address and policy.

Sources

The regulatory backdrop behind that regional coverage: the EU AI Act's three penalty tiers run up to 7%, 3% and 1% of global turnover depending on the obligation breached, and Gartner projects more than 40% of agentic AI projects will be cancelled by the end of 2027 — the reason most first calls start with the Agent Trust Gap Brief rather than a sales pitch. Standards referenced: OWASP Top 10 for Agentic Applications, NIST AI RMF, ISO/IEC 42001.