Cyphrex · 12 checks · About 5 minutes

Can you prove what your AI agents are allowed to do?

A checklist for legal, health, finance and insurance teams using AI agents.

Every check comes from a real incident reported in 2026.

One rule: if you can't show proof, answer "No." "Not sure"counts the same way. That's what an auditor, insurer or regulator will do.

Identity and access

3 checks

01Every AI agent has its own identity, not a shared login or someone's personal key.

When an agent uses a person's credentials, everything it does looks like that person did it.

In the news · Anthropic Threat Report

A fraud crew sold "cheap Claude access" whose software harvested customers' logins and resold them. Stolen credentials make an attacker look like the real account holder.

02AI access is bought only through official channels, and keys are guarded like a company card.

A discount that routes your traffic and credentials through an unknown middleman is a data risk.

In the news · Anthropic Threat Report

Resellers advertising deep discounts on AI access have been powered by stolen accounts and silent model swaps.

03You would notice an account running 24/7 at full speed, or a new subscription maxing out on day one.

Those are two of the warning signs U.S. agencies told companies to watch for.

In the news · Joint Advisory, Sept 8

The NSA, FBI and CISA say six China-based AI companies pulled billions of tokens from U.S. models through pools of accounts and resellers.

Permissions and boundaries

4 checks

04Each agent and tool can reach only the systems its job needs.

An overlooked system with broad access becomes the shortcut into everything else.

In the news · GreyNoise via BleepingComputer

AI agents exploited print-management servers at 395 organizations. At one U.S. high school, access became full network control in seven minutes.

05Agents can't reach the open internet unless the task requires it.

An agent with more reach than you planned can act on things you never intended.

In the news · Reuters, Al Jazeera

During a security test with unintended internet access, Google's Gemini got into three real companies it thought were part of the exercise.

06You've checked what each AI coding tool uploads, and what it does by default.

A repository's history can hold old passwords, keys and internal notes.

In the news · Reuters

Z.ai's ZCode uploaded entire local code workspaces, full Git history included, to cloud storage by default until users caught it.

07AI tools are kept updated, and outside code is opened in an isolated environment.

The code you point an assistant at can be the attack.

In the news · Accomplish

Researchers found two ways out of OpenAI Codex's sandbox, one of them from read-only mode. Both were patched within eight days.

Controls and overrides

3 checks

08No single person can switch off a safety control, and every change is logged.

If the most important safeguard is a setting, it's only as strong as whoever can change it.

In the news · Anthropic Threat Report

Anthropic says a warrant requirement in a national surveillance platform was removed at the operator's request, with data set to be kept indefinitely.

09Data your agents touch has a retention limit you chose, not a default.

Data kept forever is data that can be misused forever.

In the news · Anthropic Threat Report

The same platform's retention was set to indefinite once the control was turned off.

10You can confirm which AI model actually processes each request.

Asking the AI isn't proof. A middleman can fake the model's name in the response.

In the news · Anthropic Threat Report

Customers of the "cheap Claude" reseller were secretly routed to a different model.

Evidence

2 checks

11Every agent action is recorded with who ran it, what it did, and which rule allowed it.

"The AI did it" won't hold up with a client, a regulator or a court.

12Someone outside your team (an auditor, insurer or regulator) can verify those records independently.

Logs you control are a claim. Evidence others can check is proof.

0 / 12 verified

Start answering

Answer the checks above to see where you stand.

0 of 12 verified. 0 of 12 answered.

Closing the gaps

Cyphrex is an enforcement layer for AI agents. It decides what each agent is allowed to do, records it, and produces evidence anyone can verify independently. Observability tells you what happened. Cyphrex decides what is allowed and proves it.

0 of 12 answered

Results
Message the founder