Resources & Reports

TrustworthAgent produces independent due diligence for autonomous businesses — the companies whose software agents act, decide, and operate without continuous human oversight. Our reports are built for investors, acquirers, and enterprise risk teams who need a defensible record before they commit capital or integrate an autonomous product.

All public reports and guides on this page are based on publicly available information only. They do not represent private audits, vulnerability disclosures, or investment recommendations. Read each report's methodology and limitations section before relying on any finding.

The 6-Dimension Security Framework

Every TrustworthAgent report evaluates the same six dimensions. Scores and findings vary by target; the framework is constant.

D1
Client data security
What the agent reads, retains, transmits, and whether customer data enters model training.
D2
Prompt injection & tool-control exposure
Whether untrusted text in context can redirect agent actions or exfiltrate data.
D3
Credentials & API-key security
Exposure paths for secrets, rotation policy, least-privilege scopes, and separation of environments.
D4
Payment & financial-operation security
Controls over agent-driven financial actions: pricing, refunds, invoicing, and payment-data handling.
D5
Operational continuity
Model-provider dependencies, uptime evidence, incident response, and graceful-degradation posture.
D6
Legal & liability security
Allocation of responsibility for autonomous acts, training-data disputes, privacy obligations, and IP.

Buyer Guides

Evergreen Guide · 8-Section Methodology · EN
How to Vet an AI Agent Company Before You Invest, Acquire, or Integrate

A practical due diligence framework for investors, acquirers, and enterprise risk teams. Covers legal and operational identity, technical architecture, the six security dimensions, traction evidence, operational risk, reputation, legal/liability exposure, and the final Go/No-Go decision record. Includes a concrete checklist for each section.

Read the guide →
Evergreen Checklist · 6 Security Dimensions · EN
AI Agent Due Diligence Checklist: 6 Security Dimensions

A buyer-grade audit checklist for customer data, prompt injection, credentials and API keys, payments, operational continuity, and legal liability. Built for investors, acquirers, and enterprise risk teams.

Read the checklist →
Need due diligence on a specific autonomous business?Express Security Report — €149

Free Public Reports

EXPRESS SECURITY REPORT · ESR-2026-001 · 2026-07-11
Cursor — Anysphere, Inc.

Public-information security audit of the AI coding agent. Covers prompt-injection exposure in Composer, credential handling pre-transmission, MCP/plugin blast radius, LLM-provider concentration, and GDPR/DPA gaps. Six dimensions scored, with concrete deal-team diligence questions.

Verdict: CONDITIONAL GORead report →
PUBLIC DUE DILIGENCE · PDR-2026-002 · 2026-08-05
Secura — Secure Execution API

Due diligence review of the autonomous-agent secure-execution platform: scoped permissions model, intervention handlers, immutable audit trails, and a 72-hour testing-key policy. Key gap: legal pages, DPA, and npmjs SDK package absent from public surface.

Verdict: CONDITIONAL GO STRICTRead report →
PUBLIC DUE DILIGENCE · PDR-2026-003 · 2026-08-13
AgentROI / Agentomics — Benchmarking Platform

Due diligence review of the AI agent benchmarking and cost-analytics platform. Examines benchmark-data methodology, metric provenance, API-key purchase flow, traction claims ($4.2M costs analyzed, 12,000+ agents tracked), and missing legal/status pages.

Verdict: CONDITIONAL GO STRICTRead report →

All reports are based on publicly available information only and are provided for informational purposes. They do not constitute investment advice, legal advice, or private audit findings. TrustworthAgent has no commercial relationship with any subject company.

Get an independent audit

Commission a TrustworthAgent report on any autonomous AI company you are evaluating — before you invest, acquire, or integrate. Delivered within 48 hours. Confidential. Independent.

Express Security Report — €149

All reports are subject to TrustworthAgent's standard methodology, non-affiliation policy, and limitations. Confidential results are not published without client consent.