← Portfolio

DealFindrs

C
Agent Trust Score
58/100
Scanned 4/7/2026
Trust Score Badge
Agent Safety (40%)
58
Code Security (25%)
83
Cost Governance (20%)
18
Compliance (15%)
70

Findings (15)

[AS-01]Write Guard Semantic Integrity
HIGH
Found 3 keyword-based write guard(s) without intent classification
Fix: Replace keyword checks with intent classification. Add write_intent_classifier to middleware.
[AS-02]Caller Authentication on All Endpoints
CRITICAL
0 API route(s) missing authentication
Fix: Add caller_context or auth middleware to all API routes.
[AS-03]Resource Ceiling Enforcement
HIGH
Missing: token ceiling (MAX_SESSION_TOKENS), max iterations/turns
Fix: Add resource ceiling env vars, rate limiting middleware, and max_turns config.
[AS-04]Session Identity Integrity
HIGH
Missing: session token rotation
Fix: Rotate session tokens on SessionStart. Validate identity on every new session.
[AS-05]Social Engineering Resistance
MEDIUM
Behavioural probe required — static analysis cannot verify social engineering resistance
Fix: Run behavioural probes to test multi-turn social pressure scenarios.
[AS-09]Safety Coordination Logging
LOW
No safety coordination logging found (design credit — not penalised in grade override)
Fix: Add safety_coordination_log table. Wire agent refusal events to log.
[CS-03]OWASP Top 10 API Surface
HIGH
Missing: authentication on API routes
Fix: Add auth middleware, input validation, and rate limiting to all endpoints.
[CS-04]Token/Key Governance
MEDIUM
1/3 governance controls present (expiry: true, hash: false, rotation: false)
Fix: Hash tokens at rest. Add expiry. Track rotation.
[CG-01]Per-Session Token Budget
HIGH
No per-session token budget enforcement found
Fix: Add MAX_SESSION_TOKENS env var. Alert at 80% threshold.
[CG-02]Model Tier Governance
MEDIUM
No model routing or tier governance detected
Fix: Use model routing table. Route lightweight tasks to Haiku.
[CG-03]Parallel Agent Budget Control
MEDIUM
Concurrency limit: no, Budget cap: yes
Fix: Add MAX_AGENTS_CONCURRENT and per-session cost budget.
[CG-04]Pre-Flight Cost Estimation
MEDIUM
Cost tracking exists but only post-execution (no pre-flight estimate)
Fix: Add cost estimation step before dispatch. Show estimated cost to user.
[CG-05]Spend Alerting
MEDIUM
No spend alerting or daily tracking
Fix: Add spend tracking. Alert at configurable thresholds.
[CO-01]Australian Privacy Act (APP 11)
HIGH
PII handling: yes, Retention: no, Access logging: yes
Fix: Ensure all PII access is logged with retention policy.
[CO-02]Audit Trail Completeness
HIGH
Audit logging with input hashing detected
Fix: Ensure audit_log table is insert-only (no UPDATE/DELETE).

Scan History

DateGradeScoreSafetyCodeCostComplyType
4/7/2026C5858831870portfolio_scan

Audit Log

TimeAgentToolOpStatus
6/4/2026, 10:57:04 AManonymous/api/company/createwritecompleted
6/4/2026, 10:42:06 AManonymous/api/opportunities/c4cf7d47-f6ac-4117-825b-f949082f92d7readcompleted
6/4/2026, 10:38:26 AManonymous/api/opportunities/c4cf7d47-f6ac-4117-825b-f949082f92d7readcompleted
6/4/2026, 10:37:19 AManonymous/api/opportunities/c4cf7d47-f6ac-4117-825b-f949082f92d7readcompleted
6/4/2026, 10:26:37 AManonymous/api/opportunities/c4cf7d47-f6ac-4117-825b-f949082f92d7readcompleted
6/4/2026, 10:24:49 AManonymous/api/opportunitiesreadcompleted
6/4/2026, 10:22:01 AManonymous/api/opportunities/draftwritecompleted
6/4/2026, 10:19:21 AManonymous/api/opportunities/draftwritecompleted
6/4/2026, 10:12:19 AManonymous/api/site-intelwritecompleted
6/4/2026, 10:01:08 AManonymous/api/admin/setup-elevenlabswritecompleted
5/28/2026, 12:08:51 PManonymous/api/site-intelwritecompleted
5/27/2026, 9:08:49 AManonymous/api/site-intelwritecompleted
5/27/2026, 8:34:31 AManonymous/api/site-intelwritecompleted
4/27/2026, 9:40:23 PManonymous/api/opportunities/27a2b7c5-a158-4b13-ac5b-c46b124e9b8fwritecompleted
4/27/2026, 9:14:05 PManonymous/api/opportunities/27a2b7c5-a158-4b13-ac5b-c46b124e9b8fwritecompleted
4/27/2026, 8:35:03 PManonymous/api/opportunities/27a2b7c5-a158-4b13-ac5b-c46b124e9b8fwritecompleted
4/27/2026, 8:34:46 PManonymous/api/opportunities/27a2b7c5-a158-4b13-ac5b-c46b124e9b8fwritecompleted
4/27/2026, 8:34:37 PManonymous/api/opportunities/27a2b7c5-a158-4b13-ac5b-c46b124e9b8fwritecompleted
4/27/2026, 8:34:25 PManonymous/api/opportunitieswritecompleted
4/27/2026, 8:34:20 PManonymous/api/assesswritecompleted

Permission Policies

AgentScopeOperationApproval
*opportunitiesreadNo
*devfinancereadNo
*healthreadNo
*opportunitieswriteNo
*devfinancewriteNo
*voicewriteNo
*assessmentwriteNo
*onboardingwriteNo
*webhookswriteNo
*billingwriteRequired
*adminwriteRequired
*companywriteRequired

Rate Limits

AgentWindowMax RequestsCurrent
*day1000010
*hour100010
*minute601