Multi-agent security testing
Security agents.
A harness with intent.
Multi-model security agents, coordinated through a carefully curated harness, test web applications, APIs and AI/LLM systems in white-box and black-box modes.
The core of the product
Agent freedom.
Harness discipline.
The product brings a group of security agents powered by different models into one orchestrated system. Our custom-built harness gives those agents a carefully chosen mixture of freedom and constraint.
The purpose is to support investigation while keeping the work directed by the assessment’s scope. The harness is the organizing layer around the agents—not just a single model receiving a prompt.
How the pieces fit togetherASHWA / CONCEPTUAL ARCHITECTUREHARNESS + AGENTS
Web applicationsAPIsAI / LLMs
WHITE-BOX + WEBSITE / BLACK-BOX
Curated harness
Freedom to investigate.
Constraints to stay focused.
Security agent
Model ASecurity agent
Model BSecurity agent
Model C
Findings + proof of concept + remediationUnderstand the issue. Reproduce it. Plan the fix.
CONCEPTUAL VIEW / MODEL LABELS ARE ILLUSTRATIVE
Two testing modes.
One security focus.
Choose the perspective that fits the access available and the question you need to answer.
01 / WHITE-BOX + WEBSITEInside context.
Application behavior.
Bring internal context, such as source code, together with a website in scope. Give the assessment visibility into implementation as well as the application’s exposed behavior.
Discuss during scoping: available code, application access and the boundaries of the assessment.
02 / BLACK-BOXTest from
the outside.
Assess web applications, APIs or AI/LLM systems without relying on source-code access. Start from the interfaces and access agreed for the engagement.
Discuss during scoping: targets, credentials where relevant and permitted testing activities.
Web. APIs. AI.
Three supported application surfaces. The testing scope is agreed for your environment.
WEB APPLICATIONSWhere users
meet your system.
Assess websites and web applications using the agreed white-box or black-box perspective.
APIsWhere systems
connect.
Bring API interfaces into scope, with the endpoints and available access discussed before testing.
AI / LLM SYSTEMSWhere AI
meets the application.
Include AI and LLM applications in the assessment, with the system context and testing boundaries agreed together.
From a finding
to a fix.
The output connects an issue to a proof of concept and remediation guidance.
FINDING STRUCTURE / ILLUSTRATIVE
Evidence your team can work with.
- Finding
- What the issue is and where it was observed in the assessed application.
- Proof of concept
- A demonstration or reproduction path that explains how the issue can be observed.
- Remediation
- Guidance for addressing the issue so engineering has a concrete next step.
This illustrates the types of output, not a customer report or a promise of a specific finding. Report format and any additional deliverables are discussed on the call.
Scope the trial together.
01 / TARGETSWhat are we testing?
Discuss the web, API and AI/LLM systems you want to include.
02 / ACCESSWhat context is available?
Agree whether white-box context, a black-box approach or both fit your needs.
03 / OUTPUTWhat does your team need?
Discuss findings, proof of concept, remediation and any additional requirements.
Technical questions.
Do you need access to source code?
Source-code access is relevant to white-box assessment. The product also supports black-box testing without source-code access.
What makes the harness important?
It provides the curated structure around the multi-model security agents, balancing freedom to investigate with constraints on the work.
Which models power the agents?
The system uses multiple models. Model-selection details can be discussed during the technical conversation.
What do we receive?
Findings with proof of concept and remediation guidance. The report format and any additional deliverables are agreed during scoping.