ApexClaw
Home › Solutions
Solutions

Every ApexClaw engagement answers one question: can you prove what your agents did, and stop what they should not.

Eight engagements, from a fast observable read through to a fully governed pilot. Each produces evidence you can hand to an auditor, a customer or a board — with its own limitations stated in writing.

Get an Agent Trust Gap Brief

Where to start

Most engagements begin with the Gap Brief, because it is cheap to run and it tells you whether the rest is warranted. If an agent has already done something you cannot explain, start with incident response instead.

Entry point

Agent Trust Gap Brief

A short, evidence-based read of your observable agent risk surface: inventory snapshot, ranked trust gaps, evidence gaps, standards mapping, one recommended next control, and stated limitations.

Details →
Full assessment

Agent Trust Audit

Agent and tool inventory, permission mapping, MCP tool-exposure assessment, evidence and replay assessment, revocation and kill-switch testing, and a remediation roadmap ordered by blast radius.

Details →
Urgent

Agent Incident Response

An agent acted outside what you intended. Contain, preserve, bound the blast radius, establish whether it was authorized or merely unstopped, and reconstruct from whatever evidence exists.

Details →
Discovery

Inventory & Permission Map

Every agent, every tool it can reach, every credential it holds, and the named human accountable for each. Usually the first time an organisation sees the true count.

Details →
Technical

MCP & Tool-Exposure Assessment

Per MCP server and per tool: what it can read, change and spend; whether authorization is scoped at the tool; and readiness for the 2026-07-28 specification before the twelve-month deprecation window closes.

Details →
Audit readiness

Evidence & Replay Assessment

Could you reconstruct a consequential action end to end today? This tests it against real actions rather than against the documentation.

Details →
Verification

Revocation & Kill-Switch Test

Measured time-to-effect on a live path. Not whether the code exists — whether it works, and how fast.

Details →
Implementation

Governed Agent Pilot

One workload, fully governed end to end: identity, gate, approval, receipt, revocation, replay. Proof before scale.

Details →

What every engagement produces

Findings with evidence

Each finding names what was observed, how, and on what date. Findings we could not verify are marked UNKNOWN rather than inferred.

Standards mapping

Gaps mapped to OWASP ASI01–10, NIST AI RMF, ISO/IEC 42001 and the obligations that apply in your jurisdiction — as interpretation, not as a compliance determination.

Stated limitations

What the engagement could not see, in writing. An assessment claiming completeness is not a trust artifact.

Claims boundary  These are assessments, not certifications. No SOC 2, ISO 27001 or EU AI Act conformity is claimed or implied by any of them. Pricing is scoped after discovery and stays labelled as a target until formally fixed. How we handle claims →

Why this exists

Machine identities already outnumber human ones by more than 80x in most enterprises, and Gartner projects that more than 40% of agentic AI projects will be cancelled by the end of 2027, driven by escalating cost, unclear value, and inadequate risk controls — the gap these engagements exist to close. The EU AI Act's three penalty tiers run up to 7%, 3% and 1% of global turnover depending on the obligation breached, which is why "we'll get to governance later" is a more expensive plan than it looks.

What every engagement produces, restated

  • Findings with evidence — what was observed, how, and on what date; unverifiable findings are marked UNKNOWN rather than inferred.
  • Standards mapping — gaps mapped to OWASP ASI01–10, NIST AI RMF, and ISO/IEC 42001.
  • Stated limitations — what the engagement could not see, written down rather than implied away.

The structured data behind this page follows JSON-LD 1.1, the W3C Recommendation, so any agent or crawler reading it machine-side gets the same facts stated here in prose.

Standards this page cites

Every engagement listed here starts from the same premise: a claim that cannot be checked against evidence is not worth much more than the paper it is written on, so each one produces something a skeptical reader can verify independently rather than take on faith.

Common questions

What is an Agent Trust Gap Brief?

A short assessment of the distance between what your agents can currently do and what you could prove afterwards. It is the low-friction entry point.

What is an Agent Trust Audit?

A full review of agent inventory, action surface, controls and evidence, producing a prioritised remediation plan.

What if we already had an incident?

Start with incident response — containment and evidence preservation come before assessment.

Do you need access to our systems?

The Gap Brief does not. Deeper work is scoped with you and read-only wherever possible.

How long does the Gap Brief take?

It is deliberately short. The output is a specific list of gaps with evidence, not a general maturity score.