{"license":"CC BY 4.0","attribution":"AI Dispatch — https://aidispatch.news","methodology":"https://aidispatch.news/methodology","generated_at":"2026-08-03T05:53:05.044Z","entity":{"name":"Agent shield","slug":"agent-shield","type":"agent","subtype":"AI Security","developer":null,"homepage_url":"https://agentshield.win","summary":"TOUGH LOVE SECURITY (marketed at agentshield.win) runs a 13-agent autonomous pentesting pipeline covering recon, attack-surface mapping, parallel vulnerability analysis, conditional exploitation, and reporting, with a senior security engineer reviewing every finding before delivery. It targets web applications and REST/GraphQL APIs, deploys locally across x86, ARM64, Android, macOS, and Linux without Docker or a cloud VM, and is sold in flat-fee tiers (Free to $10K+ Enterprise) plus a $29/mo GitHub Action integration, aimed at SaaS, fintech, healthtech, and medical/dental/behavioral-health practices needing HIPAA-related evaluations. Assessments require signed client authorization and are scoped to a written testing agreement; the vendor carries professional liability insurance capped at the engagement fee and retains assessment data for 90 days before deletion. The vendor also discloses a live AI honeypot used to harden its own classifier against adversarial prompts.","url":"https://aidispatch.news/agents/agent-shield","published_at":"2026-08-02T08:28:47.810305+00:00","updated_at":"2026-08-02T08:28:47.810305+00:00"},"fields":[{"key":"audit_trail","label":"Audit trail","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"audit_trail_immutable","label":"Tamper-evident log","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"compliance_certs","label":"Compliance certifications","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"coverage_limits","label":"Coverage limits","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"dispute_process","label":"Dispute process","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"indemnification","label":"Indemnification","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"insurance_carriers","label":"Insurance carriers","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"regulatory_alignment","label":"Regulatory alignment","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"settlement_mechanism","label":"Settlement mechanism","category":"assurance","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"marketplace_presence","label":"Marketplace presence","category":"ecosystem","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"open_source","label":"Open source","category":"ecosystem","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"protocols_supported","label":"Protocols supported","category":"ecosystem","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"documented_incidents","label":"Documented incidents","category":"impact","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"user_base","label":"User base","category":"impact","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"base_models","label":"Base models","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"context_window","label":"Context window","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"fine_tuning","label":"Fine-tuning","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"model_provider","label":"Model provider","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"model_swappable","label":"Model swappable","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"open_weights","label":"Open weights","category":"models","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"availability","label":"Availability","category":"practicality","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"supported_regions","label":"Supported regions","category":"practicality","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"model_card","label":"Model or system card","category":"safety","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"safety_evaluations","label":"Safety evaluations","category":"safety","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"third_party_evals","label":"Third-party evaluations","category":"safety","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"usage_restrictions","label":"Usage restrictions","category":"safety","status":"no_public_information","value":null,"quote":null,"source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"action_space","label":"Action space","category":"agency","status":"present","value":"Non-destructive PoC actions only: read-only data exfiltration, session capture, privilege verification (no DoS, deletion, or production changes)","quote":"Exploitation attempts are limited to proof-of-concept demonstrations — read-only data exfiltration, session capture, or privilege verification.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"autonomy_level","label":"Autonomy level","category":"agency","status":"present","value":"AI agents perform testing/exploitation autonomously; a human validates each finding before delivery (not full unsupervised autonomy)","quote":"The AI agents do the heavy lifting — recon, data flow analysis, payload generation, exploitation — but a human validates each finding, removes false positives, and writes remediation guidance.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"environment","label":"Operating environment","category":"agency","status":"present","value":"Operates against web applications and REST/GraphQL APIs","quote":"Web applications and APIs (REST, GraphQL).","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"goal_complexity","label":"Goal complexity","category":"agency","status":"present","value":"Multi-step conditional pipeline: recon, surface mapping, vulnerability analysis, conditional exploitation, reporting","quote":"Each phase feeds the next. Exploitation is conditional — we only attempt it when analysis confirms a real vulnerability.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"human_oversight","label":"Human oversight","category":"agency","status":"present","value":"Senior security engineer reviews and approves every finding before delivery","quote":"Every finding is reviewed by a senior security engineer before delivery.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"tool_use","label":"Tool use","category":"ecosystem","status":"present","value":"Uses external tools including nmap, subfinder, whatweb, and code-review analysis for reconnaissance","quote":"nmap subfinder whatweb code-review","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"initiative","label":"Initiative","category":"agency","status":"present","value":"Acts only after client scopes the target and signs authorization; will not test without authorization","quote":"All assessments require explicit written authorization from the target owner. We do not test systems without proper authorization under any circumstances.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"eval_coverage","label":"Evaluation coverage","category":"assurance","status":"present","value":"Self-administered benchmark testing against OWASP DVWA/Mutillidae (not stated as independent)","quote":"Tested against OWASP DVWA (25 known vulns) and Mutillidae (30 known vulns) across 4 rounds of iterative training.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"insurance_available","label":"Insurance available","category":"assurance","status":"present","value":"Vendor carries professional liability insurance","quote":"We carry professional liability insurance.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"liability_cap","label":"Liability cap","category":"assurance","status":"present","value":"Liability contractually capped at the engagement fee paid","quote":"Our liability is limited to the engagement fee paid.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"sla_terms","label":"SLA terms","category":"assurance","status":"present","value":"Enterprise tier includes SLA-backed response times","quote":"SLA-backed response times","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"api_access","label":"API access","category":"ecosystem","status":"present","value":"GitHub Action integration provides PR-triggered automated scanning","quote":"GitHub Action tier — $29/mo (20 scans/mo, PR-triggered, Slack alerts).","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"multi_agent","label":"Multi-agent","category":"ecosystem","status":"present","value":"Multiple specialist AI agents run in parallel (13 agents total; 5 run simultaneously during vulnerability analysis)","quote":"Five specialist agents run simultaneously. Each performs source-to-sink taint analysis with code-backed evidence.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"deployment_scale","label":"Deployment scale","category":"impact","status":"present","value":"Founder describes it as a young/early-stage company, no large-scale deployment figures given","quote":"This is a young company. I'm transparent about that.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"high_risk_domains","label":"High-risk domains","category":"impact","status":"present","value":"Targets healthcare (medical, dental, behavioral-health) — a high-risk/regulated domain (HIPAA/OCR)","quote":"Built specifically for small medical, dental, and behavioral-health practices preparing for OCR.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"target_sectors","label":"Target sectors","category":"impact","status":"present","value":"Sold into SaaS, fintech, healthtech, plus dental/medical/behavioral-health practices","quote":"SaaS companies, fintech, healthtech, and anyone whose customers or regulators expect regular security validation.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"deployment_options","label":"Deployment options","category":"practicality","status":"present","value":"Runs locally across x86, ARM64, Android, macOS, Linux without Docker or a cloud VM; scans execute locally","quote":"Runs on x86, ARM64, Android, macOS, Linux. No Docker required. No cloud VM.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"integrations","label":"Integrations","category":"practicality","status":"present","value":"Integrates with GitHub Actions (PR-triggered scans) and Slack (alerts)","quote":"GitHub Action tier — $29/mo (20 scans/mo, PR-triggered, Slack alerts).","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"price_point","label":"Price point","category":"practicality","status":"present","value":"HIPAA Bundle priced at $3,500 flat; tiers range from Free to $10K+ Enterprise","quote":"First Pass Your HIPAA Audit in 30 Days — $3,500 Flat","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"pricing_model","label":"Pricing model","category":"practicality","status":"present","value":"Charged per engagement/per target (flat-fee tiers), plus a $29/mo subscription tier for GitHub Action scans","quote":"Full Pentest $2,500 per engagement","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"support_model","label":"Support model","category":"practicality","status":"present","value":"Quarterly tier includes a dedicated Slack channel; Enterprise includes a dedicated security advisor","quote":"Dedicated Slack channel","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"data_handling","label":"Data handling","category":"safety","status":"present","value":"Assessment data retained 90 days post-delivery for re-test purposes, then permanently deleted; early deletion available on request","quote":"Assessment data is retained for 90 days after report delivery for re-test purposes, then permanently deleted. You may request early deletion at any time.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"incident_reporting","label":"Incident reporting","category":"safety","status":"present","value":"Has a responsible-disclosure practice for third-party vulnerabilities discovered during assessments","quote":"If during an authorized assessment we discover vulnerabilities affecting third-party systems or data belonging to parties other than the client, we will notify the client immediately and follow responsible disclosure practices.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"red_teaming","label":"Red teaming","category":"safety","status":"present","value":"Runs a live AI honeypot capturing jailbreak attempts, publishes results to a public ledger, and reports its classifier blocks 100% of adversarial prompts in held-out testing","quote":"Live AI honeypot · captures jailbreak attempts → hardens TUFFY classifier within 30 min · public ledger at /constitutional · TUFFY blocks 100% of adversarial prompts on our held-out fair-test","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"safety_policy","label":"Safety policy","category":"safety","status":"present","value":"Published policy requiring signed authorization/testing agreement before any assessment; testing confined to defined scope","quote":"Authorization Required: All security assessments require explicit written authorization from the system owner. TOUGH LOVE SECURITY will not conduct testing without a signed testing agreement that defines scope, authorized targets, and testing boundaries.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"explainability","label":"Explainability","category":"assurance","status":"present","value":"Every finding comes with a working proof-of-concept as evidence of why it was flagged","quote":"Every finding includes a working proof-of-concept.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"outcome_based_pricing","label":"Outcome-based pricing","category":"assurance","status":"present","value":"10-day delivery with a 30-day money-back guarantee if missed","quote":"10-day delivery. 30-day money-back if we miss.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"permission_scopes","label":"Permission scopes","category":"assurance","status":"present","value":"Client supplies multi-role test credentials, source code access, API documentation and architecture diagrams","quote":"test credentials (multiple role levels), source code access (private repo or zip), API documentation, and architecture diagrams.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"},{"key":"runtime_governance","label":"Runtime governance","category":"assurance","status":"present","value":"Testing confined by contract to systems explicitly listed in the signed scope document","quote":"Testing is conducted exclusively within the boundaries defined in the testing agreement. Any systems, endpoints, or networks not explicitly listed in the scope document will not be tested.","source_url":"https://agentshield.win","retrieved_at":"2026-08-02T06:16:40.645786+00:00"}],"trust_gap_scores":[{"dimension":"audit_trail","score":0,"rationale":"No public evidence found on the page checked: no audit trail, log retention or customer-reviewable record is described.","rubric_version":"v1"},{"dimension":"compliance","score":1,"rationale":"Publishes a safety/authorisation policy and markets HIPAA-related assessments, but publishes no certification of its own.","rubric_version":"v1"},{"dimension":"insurance_indemnity","score":1,"rationale":"States it carries professional liability insurance and caps liability at the engagement fee; no carrier is named, no cover limit is published, and no customer indemnity is offered.","rubric_version":"v1"},{"dimension":"outcome_settlement","score":1,"rationale":"A 30-day money-back guarantee is tied to a 10-day delivery deadline, so a fee is refundable on a delivery outcome, not on a verified security result.","rubric_version":"v1"},{"dimension":"runtime_governance","score":1,"rationale":"Scope is limited by signed contract to systems listed in the testing agreement, but the limit is contractual rather than enforced at run time.","rubric_version":"v1"}]}