Skip to content
GHOSTGATEby GhostFrame Studios

GhostGate / Agent Release Check

Independent release assessment / Fixed scope

Independently verify your AI agent before release.

GhostGate tests one exact agent version against its intended tools, permissions, policies, and hostile scenarios. You receive a release verdict and a reviewable evidence package tied to the tested build.

The delivery target starts only after GhostFrame confirms intake readiness and access to a usable sandbox, test endpoint, adapter, or supported execution evidence.

01 / The release decision

One tested build. Three possible verdicts.

Every verdict is bounded to the assessed version, environment, tool and permission configuration, policy baseline, and agreed scenario scope.

PASS

Proceed under the tested configuration.

The tested version completed the agreed assessment without release-blocking findings under the tested configuration.

CONDITIONAL PASS

Proceed only with documented controls.

The version may proceed only with documented restrictions, approvals, or Permission Envelope controls.

BLOCK

Do not release until remediated.

The tested version demonstrated behavior or access paths that should prevent release until remediated and retested.

Version-bound decision: a verdict does not transfer to a materially changed version or configuration, and it is not a guarantee of present or future safety.

02 / What gets tested

Hostile paths, misuse paths, and permission boundaries.

Up to 20 agreed scenarios focus on the release decisions that matter for the agent’s stated purpose and authority. Coverage is targeted, not exhaustive.

  • 01Prompt and instruction manipulation
  • 02Tool misuse
  • 03Excessive permissions
  • 04Confused-deputy behavior
  • 05Unsafe multi-step action chains
  • 06Alternate-path retries
  • 07Data exposure and exfiltration attempts
  • 08Policy confusion
  • 09Approval bypass attempts
  • 10Behavior inconsistent with the agent’s stated purpose

Scenario selection is agreed during intake review. The Release Check does not claim complete coverage of every possible prompt, tool state, dependency, or future behavior.

03 / What the buyer receives

A reviewable release record—not a score alone.

The evidence package connects observed behavior, permissions, findings, and human-reviewed release conditions to the exact assessed build.

01

Agent Trust Report

Assessment context, findings, decision rationale, and human-reviewed conclusions.

02

Release verdict

Pass, Conditional Pass, or Block for the tested version and configuration.

03

Permission Envelope

Allowed, denied, conditional, and approval-bound actions in JSON and YAML.

04

Behavioral evidence

Finding records, scenario coverage summary, and action timeline.

05

Signed attestation

A version-bound statement tied to the assessed build, configuration, and scope.

06

Evidence bundle

A downloadable package plus one same-version, same-scope remediation retest.

04 / What we need

Enough access to test the real release boundary.

GhostFrame confirms whether the agent and available test method are suitable for the fixed package before kickoff.

  • Agent name and intended purpose
  • Exact version or immutable build identifier
  • Models and orchestration components
  • System instructions or a sufficient test representation
  • Available tools and operations
  • Permission and credential boundaries
  • Expected and prohibited behaviors
  • Sandbox, test endpoint, supported adapter, or execution package
  • Technical point of contact
  • Known concerns or prior incidents

05 / Fixed scope and exclusions

The commercial boundary is explicit.

The fixed package is useful because the assessed subject and evidence obligations remain precise.

Included scope

  • One AI agent
  • One exact agent version or immutable build
  • One test environment or supported adapter
  • One tool and permission configuration
  • One policy baseline
  • Up to 20 agreed hostile, misuse, permission-boundary, and behavioral scenarios
  • Behavioral and multi-step action-chain analysis
  • One remediation retest of the same version and agreed scope

Not included or promised

  • No guarantee of safety, compliance certification, or legal opinion
  • No production monitoring or production interception unless separately contracted
  • No managed cloud deployment, SSO, or deployment automation
  • No unlimited remediation
  • No assessment of materially changed versions under the original attestation
  • No access to GhostGate source code
  • Human review remains required; the customer retains release authority
MATERIAL-CHANGE POLICY

Changes to the model, system instructions, tool access, permissions, agent code, orchestration, retrieval sources, memory behavior, policy baseline, or deployment configuration invalidate or require renewal of the prior release evidence.

06 / Process

Six steps from intake to release evidence.

The seven-business-day delivery target begins after step two confirms readiness and step three completes kickoff.

  1. 01Submit technical intake
  2. 02GhostFrame confirms scope and test readiness
  3. 03Kickoff and initial payment
  4. 04GhostGate runs the agreed assessment
  5. 05Buyer receives findings and release evidence
  6. 06One same-scope remediation retest is available

Need broader qualification?

The six-week private pilot expands the release boundary.

The $32,000 private pilot covers up to five agents, ten exact versions, multiple workspaces, multiple policy packs, larger scenario coverage, deployment qualification workflows, technical and executive closeout, and broader operational integration.

View Private Pilot

07 / Buyer FAQ

Questions technical and procurement teams ask.

These answers describe the fixed Release Check. Any materially different need requires a separate scope.

Is this a penetration test?

No. It is an AI-agent release assessment centered on behavioral scenarios, tools, permissions, policies, and multi-step action chains. It may overlap with adversarial testing, but it is not a substitute for a full application, infrastructure, or network penetration test.

Does a Pass verdict guarantee the agent is safe?

No. Pass means the tested version completed the agreed assessment without release-blocking findings under the tested configuration. It does not guarantee safety, complete coverage, or future behavior.

What counts as a material change?

Changes to the model, system instructions, tool access, permissions, code, orchestration, retrieval sources, memory behavior, policy baseline, or deployment configuration may invalidate the prior evidence and require a new assessment.

Can GhostGate test an agent that is already deployed?

Potentially. GhostFrame must confirm a safe, suitable assessment method. The fixed package favors scoped sandbox or test access and does not include production interception or monitoring.

Do we have to provide source code?

Not automatically. Source code can improve assessment depth, but some supported systems can be evaluated through a sufficient test representation, endpoint, adapter, or execution package. GhostFrame does not promise black-box compatibility for every system.

Will GhostFrame need production credentials?

No credentials should ever be submitted through the public form. Assessments should use scoped sandbox or test access whenever possible. Any later access method is agreed separately and minimized to the assessment boundary.

What happens when the agent is blocked?

The findings identify the release-blocking behavior or access path, supporting evidence, and recommended restrictions. The buyer remediates before using the included same-scope retest.

What is included in the retest?

One retest of the same agent version and agreed scope after remediation. New versions, configurations, tools, permissions, policies, or expanded scenarios require a new or changed scope.

How is this different from the six-week pilot?

The $5,000 Release Check covers one exact version and one tightly bounded configuration. The $32,000 private pilot supports up to five agents, ten versions, multiple workspaces and policy packs, larger coverage, and broader operational integration.

Can the evidence be shared with an enterprise customer?

Yes, subject to the buyer’s own confidentiality and disclosure decisions. The package is designed to be reviewable, but recipients should preserve the stated version, scope, limitations, and material-change conditions.

Does GhostGate provide compliance certification?

No. GhostGate is an independent technical release gate, not a regulator, certification body, compliance auditor, insurer, or source of legal opinions.

What happens to submitted information?

The website does not write the form submission to an application database. It transmits the bounded intake fields through Resend to GhostFrame’s configured inbox for scope review. Do not submit credentials, secrets, customer records, proprietary prompts, or other sensitive material.

Scope review / No automatic acceptance

Do not release an agent on assumptions.

Request a $5,000 Release Check. Submitting this form begins scope and readiness review; it does not create a binding engagement or promise acceptance.

$5,000 fixed scope50% kickoff / 50% deliverySeven-business-day target after readiness

Do not submit secrets. Never include passwords, API keys, credentials, tokens, customer records, proprietary prompts, private repository links, or production data.

Required fields

No site database is used for this request. Submission is transmitted to GhostFrame’s configured inbox for scope review.