Every ApexClaw engagement answers one question: can you prove what your agents did, and stop what they should not.
Eight engagements, from a fast observable read through to a fully governed pilot. Each produces evidence you can hand to an auditor, a customer or a board — with its own limitations stated in writing.
Get an Agent Trust Gap BriefWhere to start
Most engagements begin with the Gap Brief, because it is cheap to run and it tells you whether the rest is warranted. If an agent has already done something you cannot explain, start with incident response instead.
Agent Trust Gap Brief
A short, evidence-based read of your observable agent risk surface: inventory snapshot, ranked trust gaps, evidence gaps, standards mapping, one recommended next control, and stated limitations.
Details →Agent Trust Audit
Agent and tool inventory, permission mapping, MCP tool-exposure assessment, evidence and replay assessment, revocation and kill-switch testing, and a remediation roadmap ordered by blast radius.
Details →Agent Incident Response
An agent acted outside what you intended. Contain, preserve, bound the blast radius, establish whether it was authorized or merely unstopped, and reconstruct from whatever evidence exists.
Details →Inventory & Permission Map
Every agent, every tool it can reach, every credential it holds, and the named human accountable for each. Usually the first time an organisation sees the true count.
Details →MCP & Tool-Exposure Assessment
Per MCP server and per tool: what it can read, change and spend; whether authorization is scoped at the tool; and readiness for the 2026-07-28 specification before the twelve-month deprecation window closes.
Details →Evidence & Replay Assessment
Could you reconstruct a consequential action end to end today? This tests it against real actions rather than against the documentation.
Details →Revocation & Kill-Switch Test
Measured time-to-effect on a live path. Not whether the code exists — whether it works, and how fast.
Details →Governed Agent Pilot
One workload, fully governed end to end: identity, gate, approval, receipt, revocation, replay. Proof before scale.
Details →What every engagement produces
Findings with evidence
Each finding names what was observed, how, and on what date. Findings we could not verify are marked UNKNOWN rather than inferred.
Standards mapping
Gaps mapped to OWASP ASI01–10, NIST AI RMF, ISO/IEC 42001 and the obligations that apply in your jurisdiction — as interpretation, not as a compliance determination.
Stated limitations
What the engagement could not see, in writing. An assessment claiming completeness is not a trust artifact.
Claims boundary These are assessments, not certifications. No SOC 2, ISO 27001 or EU AI Act conformity is claimed or implied by any of them. Pricing is scoped after discovery and stays labelled as a target until formally fixed. How we handle claims →
Why this exists
Machine identities already outnumber human ones by more than 80x in most enterprises, and Gartner projects that more than 40% of agentic AI projects will be cancelled by the end of 2027, driven by escalating cost, unclear value, and inadequate risk controls — the gap these engagements exist to close. The EU AI Act's three penalty tiers run up to 7%, 3% and 1% of global turnover depending on the obligation breached, which is why "we'll get to governance later" is a more expensive plan than it looks.
- Agent Trust Gap Brief — the fast, low-friction entry point.
- Agent Trust Audit — the full assessment.
- Agent Incident Response — containment when something has already happened.
What every engagement produces, restated
- Findings with evidence — what was observed, how, and on what date; unverifiable findings are marked UNKNOWN rather than inferred.
- Standards mapping — gaps mapped to OWASP ASI01–10, NIST AI RMF, and ISO/IEC 42001.
- Stated limitations — what the engagement could not see, written down rather than implied away.
The structured data behind this page follows JSON-LD 1.1, the W3C Recommendation, so any agent or crawler reading it machine-side gets the same facts stated here in prose.
Standards this page cites
- OWASP Top 10 for Agentic Applications.
- NIST AI Risk Management Framework.
- EU AI Act, Regulation 2024/1689.
Every engagement listed here starts from the same premise: a claim that cannot be checked against evidence is not worth much more than the paper it is written on, so each one produces something a skeptical reader can verify independently rather than take on faith.
Common questions
What is an Agent Trust Gap Brief?
A short assessment of the distance between what your agents can currently do and what you could prove afterwards. It is the low-friction entry point.
What is an Agent Trust Audit?
A full review of agent inventory, action surface, controls and evidence, producing a prioritised remediation plan.
What if we already had an incident?
Start with incident response — containment and evidence preservation come before assessment.
Do you need access to our systems?
The Gap Brief does not. Deeper work is scoped with you and read-only wherever possible.
How long does the Gap Brief take?
It is deliberately short. The output is a specific list of gaps with evidence, not a general maturity score.