AI agent due diligence

You vet every employee. The AI agent you handed your email, CRM and files, nobody checked.

An AI agent is a digital identity that can act. It receives employee-level permissions with no prior vetting. ProfCheck is the independent third party you hire to check it before it goes live, reviewed by an analyst, the same way we check people.

ProfCheck AI agent screening: an AI agent passing a verification gate beside an AI Agent Dossier listing origin, permissions, external connections and security risk.
The gap

Three reasons no one has actually checked your agent.

Every tool is internal

The market is full of software you run on your own agents. None of it is an independent check of an agent someone else built.

A self-issued passport is not verification

An agent credential the operator issues for itself is self-attestation. It is the opposite of an outside party verifying what the agent can actually do.

Effective permissions exceed the declaration

"Never sends email" is an instruction, not a permission. If the scope allows sending, one injected line of text defeats the promise.

Who it's for

For the team that grants the agent its access.

Security, GRC and procurement

The people onboarding a third-party AI agent and answerable for what it can reach.

Agents wired into real systems

Agents connected to email, CRM, finance or file systems, acting on live data.

A vendor onboarding gate

A step before an agent is connected, and cyber-insurance renewals that want a risk assessment on file.

Audit and board oversight

A DORA or third-party-risk audit, or a board asking whether due diligence was done before deployment.

What we check

The whole operational entity, not just the model.

Permission Intelligence

Effective capability against the declared purpose. Every tool and scope classified on an eight-rung autonomy ladder, from read to authorize.

Permission Attack Graph

Chains from untrusted input, an inbound email or a fetched web page, to an action that sends, writes or transfers, with the mitigations that actually hold.

Vendor and supply chain

Who stands behind the agent: the maker, the model provider, the MCP servers and third-party tools, and who can change them after the check.

Seven risk domains

Identity, permissions, autonomy, supply chain, data exposure, behaviour and monitoring, scored into one risk profile.

Cited against standards

Mapped to OWASP Agentic Top 10, NIST AI RMF and CSA Agentic IAM, the agent-world equivalent of sanctions and watchlists.

How it works

From manifest to decision, in days.

1. You hand us a Manifest

OAuth scopes, tools, MCP servers, the System Prompt and a short description of the use case.

2. We map effective versus declared

And build a Permission Attack Graph of the chains that cross a trust boundary.

3. An analyst reviews and scores

Seven risk domains against OWASP, NIST and CSA, with every finding tied to its basis.

4. You receive a decision-support report

A risk profile, permission-reduction recommendations and a one-page Agent Passport.

  • Delivered within a few business days
  • Encrypted PDF, one password per report
  • Static analysis only. We never run your agent or its credentials
  • No report leaves without analyst review
What you receive

A report you can decide with.

  • Agent Risk Profile across seven domains, scored 0 to 100 with a risk band
  • Permission Attack Graph with the chains that matter
  • Critical Findings, called out on their own
  • Concrete permission-reduction recommendations
  • A one-page Agent Passport that travels with the agent

ProfCheck provides evidence and recommendations. The decision to connect the agent, and with what permissions, stays with you.

Before you grant the next agent access, check it.

Describe your agent and its access, and we will scope the check.