We audit the joins.
The vault can be correct and the agent still transfers. A model inside the prover can change what the circuit means. We review those hops in one engagement.
Artifact
- join
- agent.tool(sign) ∩ wallet.owner(agent)
- assumption
- the principal that picks the call is not the principal that signs
- fails
- when one model is both author and key-holder
Each tab is the same finding on a different surface.
Who this is for
You ship both surfaces in one product.
- Protocol security lead. If you are adding an agent that can sign, or a model that sits next to a vault, the join is in scope.
- AI product owner. You hold keys in an agent loop. Artifact review, not a responsible-AI workshop.
- Counsel. The method page states scope, artifacts, and what an audit does not prove. Brief the board from that, not from a logo.
Who this is not for
We do not rubber-stamp simple token contracts or issue governance PDFs for chatbots.
When two vendors each leave the join out of scope, one firm still has to own it. We will say so on the call if there is no join and no serious single surface.
Method in four steps
- Step 1. Scope the surfaces and write the brief (threat model + invariants).
- Step 2. Review each surface, then the joins between them.
- Step 3. Show exploit paths and the assumption that produced them.
- Step 4. Retest fixes. Publish what the client clears.
After a first engagement, Continuous review is the retainer that keeps the same brief current.
Read the methodOne firm for the wallet and the model that operates it. Capability list on a page counsel can forward.
Public work
Public reports and a sample of the format. No logo wall.
Format example. Vault, agent, and the glue between them. Not a client engagement.
No public case studies yet. Until a client clears one, the method and the sample report are what we can show.
All reportsRequest a scoping call
Request a scoping call when the join is in the product. We will decline a token and a white paper.