the adversarial audit
Anyone can run a security pass once and screenshot the green. The harder thing is to keep re-attacking your own system as it grows — and get the same answer every time. The latest round: a 50-agent audit, its fixes shipped, then a separate 14-lens adversarial re-audit where every finding had to survive a skeptic before it counted. What holds, holds.
the cadence
✓ crown jewels held every round — isolation · money · governance · SSRF · token domains
Chat memory was keyed by the sender, not the tenant — so a guest who messaged two businesses through the platform could have one's conversation surface inside the other's prompt. Fixed: memory is tenant-keyed at the storage layer, so a shared sender physically can't cross the boundary.
In the cross-tenant tool economy, a provider could raise the price of a granted tool after a caller began using it and drain their balance. Fixed: the caller consents to a price per call, fail-closed — no consent, no charge — enforced before a single credit moves.
The billing check ran before the crisis check, so a distressed customer messaging an out-of-credits business got "unavailable" instead of a crisis line. Fixed: crisis is served free, ahead of every ceiling and charge, on every customer surface.
The lenses span isolation · auth · injection · money · governance · booking · channels · the autonomous resident · data-rights (GDPR/PECR) · the site generator · frontend · ops. Verdict, every round: zero critical standing; tenant isolation and the XSS surface came back clean; no live auth bypass — every confirmed edge fixed and redeployed.
the honest numbers
Most builders pad. I'd rather you trust the parts that are real than be impressed by parts that aren't.
The system is honest because the person who designed it is. I made sure of that from the start — built in, not bolted on.
the invitation
If you want a builder who attacks his own work this hard before anyone asks — and keeps doing it as the system grows — let's talk.