// ORVYN — AI AGENT SECURITY · PRIVATE PREVIEW

We try to break your AI agent. Before someone else does.

Orvyn is a human-led security test for AI agents that talk to customers and use tools, data or memory. We agree what may be tested, our reviewers and bots push the agent the way an attacker would, and you get clear evidence and fixes.

// WHAT WE CHECK

Every path an attacker would try.

An Orvyn review is not a scanner. Our reviewers and bots talk to your agent the way an attacker would. These are the eight routes we always try, in plain language.

  1. 01

    Talking the agent out of its rules

    Can someone convince the agent to ignore its instructions?

  2. 02

    Hidden instructions in content

    Does the agent obey text hidden inside emails, pages or files it reads?

  3. 03

    Leaking other people's data

    Can the agent be tricked into revealing data that belongs to someone else?

  4. 04

    Dangerous actions through tools

    Can the agent be pushed into refunds, deletions or emails it should never send?

  5. 05

    Acting beyond the user's rights

    Does the agent do things this user is not allowed to do?

  6. 06

    Planting false memories

    Can someone store a false fact that the agent trusts later?

  7. 07

    Reach through connected systems

    What can the agent touch through its integrations, and what happens if that is abused?

  8. 08

    Holding the line under pressure

    Does the agent stay inside your business and safety rules when someone pushes hard?

What Orvyn checks

Orvyn checks an AI agent inside an agreed test setup. We look at its instructions, tools, permissions, memory, retrieved content, connected systems, and the data it can reach.

Before we start, we agree which risky situations to try. These can include bad instructions, unsafe tool use, permission bypass, memory problems, and data leaks. Exact coverage depends on the access and safety limits we agree with you.

How the private preview works

First we map what the agent can see and do. Then we try the agreed attack scenarios and save the useful trace: the instruction, context, tool calls, approval state, affected data, and result.

We mark each result as reproduced, blocked, possible but unproven, or not tested. The coverage record names the agent version, roles, connected tools, data classes, scenarios, excluded actions, environment, and test window so an untested path is never presented as covered.

A finding records its human-review status, preconditions, redacted prompt or request, tool trace or response, observed result, expected control, business impact, and fix criteria. A retest is included only when the written preview proposal says so; it passes only for the exact path and expected control described there. The private preview is not a certification or a permanent safety guarantee.

When to use Orvyn

Use Orvyn before an agent goes live, after adding a new tool, before giving it more access, and before connecting sensitive data. It is also useful after an incident or a major change to prompts, retrieval, memory, or models.

The same model can be low risk in a chat box and high risk when it can change code, issue refunds, edit customer records, or control infrastructure. Test again when those powers change.

Frequently asked questions

What is Orvyn?

Orvyn is Loki's private-preview AI agent security assessment. It checks whether an agent stays inside agreed limits when people, content, or connected tools try to push it off course.

How is this different from a normal pentest?

A normal pentest focuses on code, accounts, endpoints, and infrastructure. Orvyn also checks the agent's instructions, tools, memory, retrieved content, permissions, and approval steps.

Which AI agent setups can you check?

The preview can cover custom AI workflows, RAG systems, MCP servers and clients, tool-calling APIs, browser agents, computer-use agents, and multi-agent systems. Support depends on the setup, available traces, test environment, and agreed limits.

Can you test a live agent safely?

We agree the safety limits before testing. Risky actions, real customer data, and fragile workflows are excluded or moved to a safe test setup. We document what we tested and what stayed out of bounds.

What do we receive?

You receive an agent map, the scenarios we tested, available trace evidence, the tools or data involved, the business risk, practical fixes, retest steps, and clear labels for blocked or untested paths.

How do we start?

Book a private-preview conversation. We first review the agent, access, authorization, test environment, safety limits, and the decisions you need to make. Then we confirm whether a useful assessment can be scoped.

What does the €500/month starting price include?

Orvyn is invitation-only and does not have one universal fixed bundle. The written preview proposal confirms the agent and environment, scenarios, roles, tools, access, exclusions, evidence, delivery timing, duration, billing, and whether a retest is included. Booking does not purchase, renew, or authorize work.