Agent Defense: a paid Discovery engagement

See what your AI agents actually do, before you have to govern them.

Five to fifteen business days. Nothing in your fleet changes and nothing gets blocked. At the end you hold a signed, tamper-evident report: every agent we found, what each one did, and exactly what would have been contained, by agent and by reason.

Fixed price. Fixed length. Credited in full toward implementation if you proceed.

Why a Discovery first

The question isn’t whether your agents are safe. It’s whether anyone can say what they did.

Most organizations running AI agents can name the agents they deployed. Far fewer can name the ones that were spawned, the credentials each one holds, or what a compromised one would be able to reach. The failures now on the public record aren’t single bad outputs. They are agents acting outside the authority anyone meant to give them, sometimes together, sometimes with credentials that were never theirs.

Inventory gap

You govern what you can see

Discovery finds the agents that exist in your runtime, then compares that list to the one you believe you have. The difference is the first finding.

Authority gap

Identity is separate from behavior

Two questions, two planes: is this agent who it claims, acting within what it was granted? and is what it’s doing dangerous? A forged or reused credential is a finding even when the action looks harmless.

Evidence gap

A log you can’t verify isn’t evidence

Every observation in the Discovery report sits in a hash-chained, tamper-evident record. Your auditor, your regulator or your board can check it wasn’t edited after the fact.

The deliverable

What the report contains

The report is generated from the same evidence ledger the platform writes in production, over exactly the observation window. It is not assembled by hand.

Scope, for you to confirm

Agents and actions under governance

The total fleet and action volume the engagement saw, stated as the numbers you would be governing under contract, for you to confirm against your own inventory.

Behavioral plane

What would have been contained

Actions that would have been quarantined or held for a human, ranked by agent, broken down by reason, with a per-hour distribution that shows bursts an average hides.

Authority plane

Identity, credential and privilege findings

Forged or reused credentials, actions outside granted authority, high-impact actions that would have required approval. Each one is stated as what Candor would have done and why.

Integrity

Chain verified, coverage stated

The evidence chain is verified before a single number is printed. Anything the engagement could not evaluate is reported as a coverage gap, never folded into the results.

Three sizes, one engagement

Sized to your fleet. Priced to be a down payment.

Every size delivers the same five steps and the same report. What scales is the fleet covered, the observation window, and the depth of the review that follows.

DiscoveryBest fitWindow and feeWhat’s included
LaunchFirst production agent or a single workflow. Small company.5 business days
$5,000
Fleet inventory, passporting, observation window, signed report, one review session.
GrowthMultiple agents or several business systems. Growing SMB.10 business days
$12,500
Everything in Launch, across the whole fleet; policy baseline drafted from what was observed; review with your engineering and security leads.
AssuranceRegulated or high-consequence environments. Mid-market.15 business days
$30,000
Everything in Growth; evidence review structured for your audit or compliance function; enforcement rollout plan; executive read-out.
EnterpriseComplex estates, multiple regions, dedicated or on-premises deployment.Scoped
From $60,000
Scoped jointly. Dedicated infrastructure available.
Credited in full. The Discovery fee is the implementation fee for the matching tier. Proceed to enforcement within 30 days of the final report and it is credited entirely. Standard cloud delivery included; taxes and dedicated infrastructure excluded.
Verified behaviors on our own fleet and our own range

We ran the engagement on ourselves first.

Candor operates its own fleet of AI agents under the same controls it sells. Before this engagement was offered, every step of it was exercised on that fleet, with the results written to the same evidence chain a customer receives. Dates and counts below are from those records.

18 Sep 2026. Observation window opened on both planes. A forged credential and an unauthorized high-impact action were sent through the live system inside the window. Neither was blocked, nothing changed in the fleet, and both appeared in the generated report as findings, by agent and by reason. Window closed; the same forged credential was then presented again and was quarantined.
18 Sep 2026. Compromised-supervisor drill: the root of a ten-agent delegation tree was declared compromised. All ten agents lost their authority in both planes, matching the predicted blast radius exactly; a replacement generation with fresh identities was registered, deployed and passing health checks in under three minutes.
15 Sep 2026. Endurance: 600 consecutive governed evaluations with no degradation; 90th-percentile decision latency 2.4 seconds on the sovereign local model.
17–18 Sep 2026. Discovery run against fleets it was never told about: agents identified from the runtime, reconciled against the declared roster, confirmed by an operator and brought under governance, with every discrepancy between the two lists recorded as a finding.
Every figure above is reproducible from a hash-chained record. We would rather show you a smaller true number than a larger claimed one.
Questions we get asked

Before you say yes

Will anything in our systems change during the Discovery?

No. Discovery observes. Your agents keep running exactly as they did; nothing is blocked, held or altered. Passporting adds identity records on Candor’s side; it does not rewrite your agents.

Can an agent be blocked by mistake during the window?

No. In an observation window Candor computes every decision it would have made and records it, but returns “allow” to everything. Enforcement is a separate, explicit step you choose after reading the report.

What do you need from us?

Read-only visibility into where your agents run (a container platform, process inventory or your fleet manifest) and a way for governed actions to be evaluated. Most engagements start without changing a line of agent code.

Where is our data evaluated?

Decisions are made by Candor’s own sovereign model on Candor-operated infrastructure; no third-party AI provider sits in the loop reading your agents’ actions. The evidence ledger stores decisions and matched fragments, not full payloads. Dedicated or on-premises deployment is available at the Enterprise tier.

What if the report finds nothing?

Then you hold a signed, chain-verified statement that over the window your fleet behaved within its authority, with the fleet inventory and action volume confirmed. That is a result, and it is yours whether or not you proceed.

Is Discovery only for AI characters in games?

No. The Agent Defense engine was first shown to game studios, and that work continues. Discovery is for any organization running AI agents that hold credentials, call tools or act on business systems.

Start with the size that fits.

Tell us roughly how many agents you run and what they touch. We’ll confirm the tier, the window and the start date in one conversation.

Start a Discovery →