An AI you can let off the leash — because it's on rails.
Security leaders won't trust an AI to touch production until the guardrails are built into the system, not bolted on. We started there. Here are the controls they ask for — and exactly how TensorShield enforces each one.
What leaders require before trusting AI pentesting — and how we enforce it
Ability to terminate all activity
39% ask for itA global kill-switch freezes every autonomous action for your whole org instantly. It fails closed — the switch beats any pending approval; queued actions wait until a human disengages it.
Data residency guarantees
38% ask for itSelf-host on your own cloud (AWS/Supabase in your account) so data never leaves your boundary. World-state intel is shared and global; your findings, exposure, and incidents stay strictly tenant-isolated.
Human oversight / review checkpoint
37% ask for itConsequential changes pause at a human-gated desk before anything is applied — tier-gated, with irreversible/legal actions requiring a named human's signature that can never be auto-approved.
Full logging of all actions
36% ask for itEvery decision — automated or human — is recorded into a signed, replayable ledger (ed25519 over canonical contents). The same scheme covers your compliance evidence, so one verifier checks both.
Controls against prompt injection
35% ask for itThe model only ever proposes; a deterministic predicate disposes. A prompt-injected agent literally cannot record a finding or take an action a tool didn't prove — so injection widens nothing it shouldn't.
Hard technical scope enforcement
32% ask for itA rules-of-engagement guard gates every agent action against the engagement's scope and budget, with an absolute destructive-action ban and explicit-consent gating for active exploitation.
Isolation between agent and tools
30% ask for itThe orchestrating agent never holds the tools or the host. Scanners run in per-scan sandbox containers on an isolated network, reached through a de-privileged Docker proxy — not a raw socket.
Proof of asset ownership
36% ask for itConnected systems prove ownership through their own OAuth consent. For a standalone target you type, you prove control by publishing a per-asset token via a DNS TXT record or a well-known file — verified against the live target before it's trusted.
8 of 8 enforced by the architecture today — not a roadmap. These are guardrails the system holds itself to from the first scan, so you can trust the agent before you have to trust the results.
Build the boundaries into the system.
The same research found leaders want hard, technical limits — a kill-switch, isolation, scope enforcement — ranked above a human babysitting every step. AI is most useful when it takes work away from people, not when it adds a new thing to watch. So our controls are mechanical and always-on, and the human is reserved for the calls only a human should make.
See the controls in your own workspace.
The kill-switch, the signed ledger, the human gate — they're in the product from the first scan, not a add-on. Start free and they're already on.
Start free