Safe by construction

An AI you can let off the leash — because it's on rails.

Security leaders won't trust an AI to touch production until the guardrails are built into the system, not bolted on. We started there. Here are the controls they ask for — and exactly how TensorShield enforces each one.

What leaders require before trusting AI pentesting — and how we enforce it

Ability to terminate all activity

39% ask for it

A global kill-switch freezes every autonomous action for your whole org instantly. It fails closed — the switch beats any pending approval; queued actions wait until a human disengages it.

Kill-switch · per-connection quarantine

Data residency guarantees

38% ask for it

Self-host on your own cloud (AWS/Supabase in your account) so data never leaves your boundary. World-state intel is shared and global; your findings, exposure, and incidents stay strictly tenant-isolated.

Tenant isolation · self-hosted deploy

Human oversight / review checkpoint

37% ask for it

Consequential changes pause at a human-gated desk before anything is applied — tier-gated, with irreversible/legal actions requiring a named human's signature that can never be auto-approved.

HITL desk · tier gates · named sign-off

Full logging of all actions

36% ask for it

Every decision — automated or human — is recorded into a signed, replayable ledger (ed25519 over canonical contents). The same scheme covers your compliance evidence, so one verifier checks both.

Signed decision ledger

Controls against prompt injection

35% ask for it

The model only ever proposes; a deterministic predicate disposes. A prompt-injected agent literally cannot record a finding or take an action a tool didn't prove — so injection widens nothing it shouldn't.

Propose-vs-dispose · instruction-source boundary

Hard technical scope enforcement

32% ask for it

A rules-of-engagement guard gates every agent action against the engagement's scope and budget, with an absolute destructive-action ban and explicit-consent gating for active exploitation.

Rules-of-Engagement guard · SSRF screen

Isolation between agent and tools

30% ask for it

The orchestrating agent never holds the tools or the host. Scanners run in per-scan sandbox containers on an isolated network, reached through a de-privileged Docker proxy — not a raw socket.

Host/sandbox boundary · socket proxy

Proof of asset ownership

36% ask for it

Connected systems prove ownership through their own OAuth consent. For a standalone target you type, you prove control by publishing a per-asset token via a DNS TXT record or a well-known file — verified against the live target before it's trusted.

DNS / file challenge · OAuth consent

8 of 8 enforced by the architecture today — not a roadmap. These are guardrails the system holds itself to from the first scan, so you can trust the agent before you have to trust the results.

The instinct leaders have

Build the boundaries into the system.

The same research found leaders want hard, technical limits — a kill-switch, isolation, scope enforcement — ranked above a human babysitting every step. AI is most useful when it takes work away from people, not when it adds a new thing to watch. So our controls are mechanical and always-on, and the human is reserved for the calls only a human should make.

See the controls in your own workspace.

The kill-switch, the signed ledger, the human gate — they're in the product from the first scan, not a add-on. Start free and they're already on.

Start free