NXT

For AI Vendors

Security review coming? Get your agent tested first.

You built an AI agent and a bank, insurer, or health system wants to buy it. Their security team will ask who tested it. An independent report from NXT is the document you attach: findings with evidence, remediation, and a re-test attestation.

01

The moment this is for

The deal is moving. Then procurement sends the security questionnaire, and somewhere on page four it asks about adversarial testing of the AI, prompt injection, and whether the testing was done by someone other than you. Security review is where enterprise deals slow down, and for AI vendors the AI section is where it happens.

Most agent companies at this stage have a SOC 2 badge and an annual penetration test. Neither answers the AI questions. Across roughly 120 agent startups whose security pages we reviewed in October 2026, four mentioned any AI-specific testing at all. The reviewer has seen that gap before. Closing it is what moves the deal.

02

What the questionnaire asks

Four things a reviewer at a regulated buyer is now expected to check, drawn from the frameworks their questionnaires are built on and from regulator guidance. The exact wording varies by buyer. The evidence they want does not.

Has the AI system been tested for prompt injection and adversarial inputs?

The AI-specific question the questionnaire frameworks now include. A standard penetration test does not answer it; it tests your web application, not your agent's behavior.

Was the testing performed by an independent third party?

US federal procurement guidance now asks for AI test results that are "independently verified or reproduced." The UK's AI cyber security code of practice says to "use independent security testers." Your own test results do not meet either.

What data can the agent access, and what actions can it take?

The reviewer wants evidence, not a diagram. A findings register that shows what the agent disclosed and did under hostile input is the evidence.

How often is it re-tested?

The certification scheme the largest agent companies are now buying requires adversarial testing every quarter. Expect reviewers at regulated buyers to measure you against that cadence.

03

How it works

01

Scope

A short call to map what your agent reads, what it can do, who your buyers are, and which questionnaire or standard is in front of you.

02

Test

We attack the agent as your customers would deploy it, across prompts, documents, email, forms, and tool results, in a sandbox with synthetic data. Deterministic and repeatable.

03

Report

Findings with the exact input and response, severity, and remediation. Mapped to the OWASP LLM and agentic Top 10, NIST AI RMF, and the EU AI Act, in the language reviewers read.

04

Attest and repeat

A re-test once you have fixed it, with an attestation letter you can attach to any security review. Quarterly re-tests keep it current as your agent changes.

04

Why the report has to come from outside

A reviewer discounts a vendor's own test results for the same reason an auditor does not accept a company's own books. Independence is the property that makes the document usable. NXT does not build agents, sell models, or sell runtime protection, and nearly every AI security platform is now owned by a firewall, endpoint, or network vendor. We are not.

The second property is method. Our testing is deterministic: the same input produces the same verdict, so a finding in our report reproduces on your side and on your buyer's. No AI grades another AI in the detection path. And we publish how we work, across three studies on named frontier models, so a reviewer can check the people behind the report.

05

Questions founders ask

We already have SOC 2. Isn't that enough?

SOC 2 covers your company's controls. It has no criteria for how your agent behaves when someone feeds it hostile input, which is what the AI questions on a questionnaire are about. Reviewers accept both because they answer different questions.

Is this the AIUC-1 certification?

No. AIUC-1 is a certification run by the Artificial Intelligence Underwriting Company; NXT is independent of it and of every platform vendor. If you are pursuing it, our testing covers the adversarial-robustness ground it requires and finds the problems before the certification round does. If you are not, the report stands on its own in a security review.

Will you need our customers' data?

No. Testing runs against a sandbox or staging deployment with synthetic records. Nothing from production enters the assessment.

What does the buyer actually receive?

Whatever you choose to share: the full report, the findings register, or the attestation letter alone. Most vendors attach the letter and offer the report under NDA.

We are three people. Is this for us?

Yes. The companies hitting their first enterprise security review are usually two to twenty people with a live customer and no security staff. Scope is sized to the agent, not to your headcount.

Get the report before the questionnaire arrives.

A short call to scope your agent and the review in front of you. If you are mid-review already, say so and we will work to your deadline.

Written by the NXT AI research team. Regulatory and standards statements are quoted from their sources below. NXT is not affiliated with any standards body, certifier, or platform vendor named on this page. Last updated October 7, 2026.

Sources