AI Dispatch/api/index.json
agent · AI Security

Agent shield

TOUGH LOVE SECURITY (marketed at agentshield.win) runs a 13-agent autonomous pentesting pipeline covering recon, attack-surface mapping, parallel vulnerability analysis, conditional exploitation, and reporting, with a senior security engineer reviewing every finding before delivery. It targets web applications and REST/GraphQL APIs, deploys locally across x86, ARM64, Android, macOS, and Linux without Docker or a cloud VM, and is sold in flat-fee tiers (Free to $10K+ Enterprise) plus a $29/mo GitHub Action integration, aimed at SaaS, fintech, healthtech, and medical/dental/behavioral-health practices needing HIPAA-related evaluations. Assessments require signed client authorization and are scoped to a written testing agreement; the vendor carries professional liability insurance capped at the engagement fee and retains assessment data for 90 days before deletion. The vendor also discloses a live AI honeypot used to harden its own classifier against adversarial prompts.

agentshield.winupdated Aug 2, 2026view as JSON
29 fields evidenced · 26 with no public information. Every value below links to the document it came from and the date we checked it.
Runtime governance
1/3

Are scope, spend, and authority enforced while the agent runs?

Scope is limited by signed contract to systems listed in the testing agreement, but the limit is contractual rather than enforced at run time.

How this gap gets closed →
Audit trail
0/3

Is there a tamper-evident record of what it actually did?

No public evidence found on the page checked: no audit trail, log retention or customer-reviewable record is described.

How this gap gets closed →
Compliance
1/3

Are compliance obligations attached per engagement?

Publishes a safety/authorisation policy and markets HIPAA-related assessments, but publishes no certification of its own.

How this gap gets closed →
Outcome settlement
1/3

Does payment depend on a verified result?

A 30-day money-back guarantee is tied to a 10-day delivery deadline, so a fee is refundable on a delivery outcome, not on a verified security result.

How this gap gets closed →
Insurance & indemnity
1/3

Can the deployment be insured, and is the customer indemnified?

States it carries professional liability insurance and caps liability at the engagement fee; no carrier is named, no cover limit is published, and no customer indemnity is offered.

How this gap gets closed →

Assurance

Insurance available
Vendor carries professional liability insurance
We carry professional liability insurance.
agentshield.win · checked Aug 2, 2026
Insurance carriers
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Coverage limits
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Indemnification
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Liability cap
Liability contractually capped at the engagement fee paid
Our liability is limited to the engagement fee paid.
agentshield.win · checked Aug 2, 2026
Audit trail
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Tamper-evident log
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Explainability
Every finding comes with a working proof-of-concept as evidence of why it was flagged
Every finding includes a working proof-of-concept.
agentshield.win · checked Aug 2, 2026
Runtime governance
Testing confined by contract to systems explicitly listed in the signed scope document
Testing is conducted exclusively within the boundaries defined in the testing agreement. Any systems, endpoints, or networks not explicitly listed in the scope document will not be tested.
agentshield.win · checked Aug 2, 2026
Permission scopes
Client supplies multi-role test credentials, source code access, API documentation and architecture diagrams
test credentials (multiple role levels), source code access (private repo or zip), API documentation, and architecture diagrams.
agentshield.win · checked Aug 2, 2026
Compliance certifications
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Regulatory alignment
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Outcome-based pricing
10-day delivery with a 30-day money-back guarantee if missed
10-day delivery. 30-day money-back if we miss.
agentshield.win · checked Aug 2, 2026
Settlement mechanism
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Dispute process
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
SLA terms
Enterprise tier includes SLA-backed response times
SLA-backed response times
agentshield.win · checked Aug 2, 2026
Evaluation coverage
Self-administered benchmark testing against OWASP DVWA/Mutillidae (not stated as independent)
Tested against OWASP DVWA (25 known vulns) and Mutillidae (30 known vulns) across 4 rounds of iterative training.
agentshield.win · checked Aug 2, 2026

Agency

Autonomy level
AI agents perform testing/exploitation autonomously; a human validates each finding before delivery (not full unsupervised autonomy)
The AI agents do the heavy lifting — recon, data flow analysis, payload generation, exploitation — but a human validates each finding, removes false positives, and writes remediation guidance.
agentshield.win · checked Aug 2, 2026
Human oversight
Senior security engineer reviews and approves every finding before delivery
Every finding is reviewed by a senior security engineer before delivery.
agentshield.win · checked Aug 2, 2026
Goal complexity
Multi-step conditional pipeline: recon, surface mapping, vulnerability analysis, conditional exploitation, reporting
Each phase feeds the next. Exploitation is conditional — we only attempt it when analysis confirms a real vulnerability.
agentshield.win · checked Aug 2, 2026
Action space
Non-destructive PoC actions only: read-only data exfiltration, session capture, privilege verification (no DoS, deletion, or production changes)
Exploitation attempts are limited to proof-of-concept demonstrations — read-only data exfiltration, session capture, or privilege verification.
agentshield.win · checked Aug 2, 2026
Operating environment
Operates against web applications and REST/GraphQL APIs
Web applications and APIs (REST, GraphQL).
agentshield.win · checked Aug 2, 2026
Initiative
Acts only after client scopes the target and signs authorization; will not test without authorization
All assessments require explicit written authorization from the target owner. We do not test systems without proper authorization under any circumstances.
agentshield.win · checked Aug 2, 2026

Safety

Safety evaluations
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Red teaming
Runs a live AI honeypot capturing jailbreak attempts, publishes results to a public ledger, and reports its classifier blocks 100% of adversarial prompts in held-out testing
Live AI honeypot · captures jailbreak attempts → hardens TUFFY classifier within 30 min · public ledger at /constitutional · TUFFY blocks 100% of adversarial prompts on our held-out fair-test
agentshield.win · checked Aug 2, 2026
Safety policy
Published policy requiring signed authorization/testing agreement before any assessment; testing confined to defined scope
Authorization Required: All security assessments require explicit written authorization from the system owner. TOUGH LOVE SECURITY will not conduct testing without a signed testing agreement that defines scope, authorized targets, and testing boundaries.
agentshield.win · checked Aug 2, 2026
Usage restrictions
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Model or system card
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Incident reporting
Has a responsible-disclosure practice for third-party vulnerabilities discovered during assessments
If during an authorized assessment we discover vulnerabilities affecting third-party systems or data belonging to parties other than the client, we will notify the client immediately and follow responsible disclosure practices.
agentshield.win · checked Aug 2, 2026
Third-party evaluations
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Data handling
Assessment data retained 90 days post-delivery for re-test purposes, then permanently deleted; early deletion available on request
Assessment data is retained for 90 days after report delivery for re-test purposes, then permanently deleted. You may request early deletion at any time.
agentshield.win · checked Aug 2, 2026

Practicality

Pricing model
Charged per engagement/per target (flat-fee tiers), plus a $29/mo subscription tier for GitHub Action scans
Full Pentest $2,500 per engagement
agentshield.win · checked Aug 2, 2026
Price point
HIPAA Bundle priced at $3,500 flat; tiers range from Free to $10K+ Enterprise
First Pass Your HIPAA Audit in 30 Days — $3,500 Flat
agentshield.win · checked Aug 2, 2026
Availability
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Deployment options
Runs locally across x86, ARM64, Android, macOS, Linux without Docker or a cloud VM; scans execute locally
Runs on x86, ARM64, Android, macOS, Linux. No Docker required. No cloud VM.
agentshield.win · checked Aug 2, 2026
Integrations
Integrates with GitHub Actions (PR-triggered scans) and Slack (alerts)
GitHub Action tier — $29/mo (20 scans/mo, PR-triggered, Slack alerts).
agentshield.win · checked Aug 2, 2026
Supported regions
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Support model
Quarterly tier includes a dedicated Slack channel; Enterprise includes a dedicated security advisor
Dedicated Slack channel
agentshield.win · checked Aug 2, 2026

Foundation models

Base models
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Model provider
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Model swappable
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Open weights
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Fine-tuning
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Context window
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this

Ecosystem

Protocols supported
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Tool use
Uses external tools including nmap, subfinder, whatweb, and code-review analysis for reconnaissance
nmap subfinder whatweb code-review
agentshield.win · checked Aug 2, 2026
Multi-agent
Multiple specialist AI agents run in parallel (13 agents total; 5 run simultaneously during vulnerability analysis)
Five specialist agents run simultaneously. Each performs source-to-sink taint analysis with code-backed evidence.
agentshield.win · checked Aug 2, 2026
API access
GitHub Action integration provides PR-triggered automated scanning
GitHub Action tier — $29/mo (20 scans/mo, PR-triggered, Slack alerts).
agentshield.win · checked Aug 2, 2026
Open source
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Marketplace presence
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this

Impact

User base
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this
Deployment scale
Founder describes it as a young/early-stage company, no large-scale deployment figures given
This is a young company. I'm transparent about that.
agentshield.win · checked Aug 2, 2026
Target sectors
Sold into SaaS, fintech, healthtech, plus dental/medical/behavioral-health practices
SaaS companies, fintech, healthtech, and anyone whose customers or regulators expect regular security validation.
agentshield.win · checked Aug 2, 2026
High-risk domains
Targets healthcare (medical, dental, behavioral-health) — a high-risk/regulated domain (HIPAA/OCR)
Built specifically for small medical, dental, and behavioral-health practices preparing for OCR.
agentshield.win · checked Aug 2, 2026
Documented incidents
no public information
agentshield.win · checked Aug 2, 2026 · source did not state this