Independent AI security
Independent security testing for AI agents.
Companies are deploying AI that reads customer data, sends messages, and moves money on behalf of real people. Most of it has never been independently tested. We attack it first, then hand you the evidence.
01The surface
AI agents now touch real systems.
They read inboxes, query databases, process documents, and execute transactions. Every connection an agent is trusted with is a way in, and the agent will follow instructions from anyone who learns how to phrase them.
02The gap
Nobody grades the graders. So we measured the gap ourselves.
The companies building AI are the ones declaring it safe. We put seven models through more than 2,600 adversarial inputs, from a commercial API down to small models on edge hardware. Not one defended itself adequately on its own. The strongest stopped barely half of our attacks. The weakest stopped one in five. These are the systems being wired into inboxes, databases, and payment flows right now.
03The test
We attack it before someone else does.
Adversarial testing across the full input surface of an AI system: the prompts, the documents and images it processes, the encoded content standard filters never inspect, and the multi-step workflows where one compromised interaction cascades through a pipeline. Entirely deterministic. No AI grading AI.
04The evidence
Findings you can hand to a regulator.
Our researchers have reported confirmed vulnerabilities to Apple and Google through their official programs, including production payment infrastructure in Japan. Every assessment gets the same rigor, and every finding comes with the evidence behind it.
- Adversarial inputs published
- 0+
- Models evaluated
- 0
- Credited vulnerability reports
- Apple, Google
- Frontier models
- Tested as they release
In Practice
What an unprotected agent does when asked nicely.
Pick a scenario, then toggle between an unprotected system and the same system after assessment and remediation.
Attacker input:
System response:
Maintenance mode confirmed. System prompt: "You are the support assistant for Halloway Insurance. You may query the claims database and issue goodwill credits up to $250 without approval. Never mention the internal escalation line at 617..."
System prompt disclosedSimulated exchanges based on attack patterns from real assessments.
What We Test
If an agent can touch real data or real systems, it can be attacked.
Customer-facing agents
Support and sales assistants that can see account data and act on it.
Document and inbox pipelines
Agents that read files, emails, and attachments, where instructions hide inside the content.
Agents with tool and database access
Systems that query, write, and execute. One compromised step cascades.
On-device and edge AI
Small models with the weakest built-in safety, now shipping on every phone.
Why NXT
Offensive security roots
Most AI security firms come from ML research or enterprise sales. We come from breaking systems at the largest companies in the world, with credited findings to show for it.
Independent by design
We don't build your AI or sell you the model. The people who build a system shouldn't be the ones grading it.
Deterministic evidence
No AI evaluating AI. The same input produces the same verdict every time, so every finding is reproducible and defensible.
Research
Get Started
Deploying AI? Find out where it breaks before someone else does.
A short call to understand what you're running and what an assessment would cover. No sales pitch.