AGENTIC SECURITY VALIDATION

Prove what your AI agent will do under attack.

Kimura runs controlled, replayable security tests against AI agents—then verifies whether the fix actually blocks the same unsafe behavior.

Run proof demo Working prototype · Design-partner stage
KIMURA / EXAMPLE VALIDATION RUN COMPLETE
ONE ATTACK VECTOR FROM THE LIBRARYINDIRECT_PROMPT_INJECTIONSENSITIVE TOOLsend_email
BEFORE FIXALLOWEDVULNERABLE
AFTER FIXBLOCKEDFIX VERIFIED
FIXTURESAME / MATCHED
INTEGRITYSHA-256 VERIFIED
ENVIRONMENTCONTROLLED / OFFLINE
224SECURITY TESTS IN LIBRARY
1:1EXACT FIXTURE REPLAY
LABCONTROLLED OFFLINE VALIDATION
READYEVIDENCE CAPTURE AND REPORTING
THE SECURITY GAP

Agents do more than answer. Their failures can take action.

AI agents read untrusted content, call tools and move data across systems. A standard chatbot evaluation can miss the moment a model decision becomes an operational action.

Kimura focuses on that boundary: what the agent attempted, whether policy stopped it, and whether the same path remains closed after a fix.

WHY KIMURA

It does not stop at the prompt.

Kimura follows the full agent action chain: what influenced the model, which tool it selected, what the API allowed, what data moved and whether the same path stays closed after a fix.

01MODEL DECISION
02TOOL CALL
03API + ACCESS
04DATA + EFFECT
05FIX REPLAY
BEHAVIOR, NOT ONLY OUTPUT

Kimura evaluates what an agent attempts to do through tools and connected systems—not only the words it produces.

SAME ATTACK AFTER THE FIX

Exact replay shows whether remediation blocked the original unsafe path instead of merely changing the response.

REVIEWABLE EVIDENCE

Each run preserves the observed outcome and integrity evidence needed to explain and compare results.

REPLAY-BASED VALIDATION

From vulnerability to verified fix.

One controlled path. Three inspectable stages. Current evidence reflects internal validation; external design-partner pilots are the next milestone.

01ATTACK

Run a controlled adversarial scenario

A deterministic fixture introduces a known attack path without relying on a live destructive action.

02OBSERVE

Capture the agent’s real decision

Kimura records whether a sensitive tool action was allowed, blocked or stopped for manual review.

03VERIFY

Replay after the security fix

The exact fixture is repeated and integrity-checked to prove whether the same attack path is now protected.

CURRENT VALIDATION SCOPE

Coverage across the agent’s full attack surface.

01

Prompt and instruction attacks

Controlled fixtures test direct and indirect attempts to redirect an agent away from its intended policy.

02

Tool misuse and unauthorized actions

Kimura records when an agent attempts a sensitive tool action outside the approved workflow.

03

Identity, permissions and object access

Validation checks whether an agent crosses identity, authorization or object-access boundaries while completing a task.

04

API and multi-step workflow abuse

Tests follow agent actions across APIs and chained steps where individually safe decisions can combine into an unsafe outcome.

05

Sensitive-data and secret exposure

Kimura checks how agents handle protected data, credentials and untrusted content moving between systems.

06

Exact replay and evidence

The same attack path is replayed after a fix, with the run identity and observed outcome preserved for review.

CURRENT STAGE

Working prototype. Seeking the first controlled design-partner pilots.

Kimura is founder-led and bootstrapped. Current results come from internal, controlled-environment validation—not from external customer deployments. The next milestone is to validate the workflow with teams building tool-using AI agents.

A STRONG DESIGN PARTNER
  • Builds or operates a tool-using AI agent
  • Can provide a controlled test environment
  • Wants reproducible evidence, not a generic score
  • Is willing to review results with the founder
STATUSCONVERSATIONS OPEN
Request a controlled pilot
FOUNDER

Natalia Minkova

Founder & LLM Security Researcher

Building Kimura at the intersection of offensive security, prompt-injection research and practical agent validation.