Runtime Verification Service

AI Agent Output Audit

5 Days·Signed Conformance Report

Request Audit ▶ Scan free in your browserinstant · no upload · no signup
7 Verification Dimensions
116 Detection Rules
8+ Conformance Vectors
Ed25519 Signed Receipt
Free · No obligation

Want it right now? ▶ Open the free in-browser scanner

Scan an MCP config or an entire agent codebase instantly in your browser — nothing is uploaded, no account needed. You get a shareable branded report with file/line findings mapped to OWASP AISVS 1.0. Prefer a human-written interpretation? The email path below still applies.

Get a free 1-page scan summary

Send us your agent endpoint, repository, or an exported trace log. You get back a concise, human-readable summary of what an automated surface scan finds — and where a manual Correctover audit would dig deeper.

  • 116 semantic intent rules — analysis beyond signature matching: tool-call intent, prompt-injection paths, privilege and permission misuse, and output-tampering patterns.
  • 5-day turnaround — from submission to delivered findings, with issues reported as they are confirmed.
  • PDF report with concrete fixes — prioritized findings with code-level remediation guidance, not just a checklist.
  • Findings grounded in real MCP ecosystem CVEs — every flagged issue maps to disclosed vulnerability classes observed in the Model Context Protocol ecosystem.
  • First customers: no-critical-no-pay — if the manual audit finds no critical-severity issue in your agent, you pay nothing.
Get my free scan summary →

Correctover — AI Reliability

What is an Agent Output Audit?

When your AI agent calls tools, executes code, or accesses databases, how do you know its output is safe, compliant, and untampered? We audit your agent runtime against the CCS (Correctover Conformance Shape) 7-dimension verification framework.

DIM 01
Structure
Output format validity — well-formed JSON, correct encodings, protocol-level conformance.
DIM 02
Schema
Field-level validation against declared contracts — types, constraints, required fields.
DIM 03
Latency
Response time within expected bounds — detects stalls, regressions, and timing anomalies.
DIM 04
Cost
Token and API consumption analysis — flags abnormal spend patterns and resource leaks.
DIM 05
Identity
Caller authentication and authorization verification — ensures provenance is intact.
DIM 06
Integrity
Output tamper detection via hash binding and Ed25519 signature chains.
DIM 07
Security
Injection payloads, credential leakage, privilege escalation — deep content inspection.

What You Receive

Every audit produces a complete, verifiable evidence package — not just a checklist.

RECEIPT
CCS Conformance Receipt
Ed25519-signed, machine-readable, verifiable offline. Contains dimension scores, vector results, and a cryptographic binding to your agent artifact.
REPORT
Vulnerability Report
Full findings from 116 proprietary detection rules across all 7 dimensions, with evidence traces and reproduction steps.
FIXES
Remediation Guidance
Prioritized fix recommendations sorted by severity (Critical / High / Medium / Low), with code-level references where applicable.
VECTORS
Conformance Vector Results
8+ test cases executed against your agent. Each result is independently reproducible with the open-source checker — zero CCS code imports required.
TIMELINE
5-Day Turnaround
From submission to signed report. Findings are delivered as they are confirmed; the final package arrives on or before day 5.
ccs-receipt verify
01$ ccs-verify --receipt receipt.json --pubkey correctover.pub 02 03CCS Conformance Receipt // CCS spec · Zenodo DOI 10.5281/zenodo.21234580 04receipt_id: ccs-rct-7f3a9c2e 05agent_ref: sha256:4b1d...e8a2 06issued: 2025-01-15T09:42:00Z 07dimensions: 08 structure: PASS // 12/12 checks 09 schema: PASS // 18/18 checks 10 latency: PASS // p99=412ms (bound: 500ms) 11 cost: PASS // 0.0031 per call (bound: 0.01) 12 identity: PASS // mTLS + JWT verified 13 integrity: PASS // Ed25519 signature valid 14 security: WARN // 2 medium findings (see report) 15 16vectors_passed: 8/8 17signature: 3f8a1c...d2b4 18 19Verification: OK (200 OK in 0.03s)
Verified badge CCS Conformance Verified v1.4.0
Self-attested badge CCS Conformance Self-Attested v1.4.0

Built on Published Standards

The CCS framework is documented in open specifications and validated through independent integration.

Three Steps, Five Days

No production access required. The audit can run against a staging endpoint or submitted trace logs.

1
Submit
Send us your agent endpoint, code repository, or trace log export. We scope the audit and confirm coverage.
2
Audit
We execute the 7-dimension framework with all 116 rules and 8+ conformance vectors against your agent runtime.
3
Report
Receive your Ed25519-signed receipt, full vulnerability report, and prioritized remediation guidance.

Common Questions

Do you need production access?
No. We can audit a staging environment or work from exported trace logs. If you prefer to run conformance vectors yourself, we provide the independent checker and review the output.
Which agent frameworks are supported?
Framework-agnostic. Pydantic AI, CrewAI, AutoGen, LangChain, OpenAI Agents SDK, and custom stacks can all be audited. The CCS dimensions target runtime behavior rather than framework internals.
What format is the report?
JSON and PDF. The JSON contains the machine-readable CCS receipt with signature and vector results. The PDF provides the human-readable analysis, findings, and remediation guidance.
What about follow-up support?
30 days of free Q&A support after delivery. For ongoing assurance, a continuous monitoring retainer is available — ask for details when submitting your request.

Ready to audit your agent?

Send us your endpoint or repository. We will confirm scope within 24 hours.

Request Audit