SEGMENT 01 · AGENT FLIGHT CHECK · BOOKING NOW
Know what your agents are doing. In two weeks.
Every company now has agents acting on production systems — coding agents, MCP servers, internal automations — and almost nobody has the list. Agent Flight Check gives you the list, the permissions behind it, and ten days of tamper-evident records of what those agents actually did.
THE OFFER
Two weeks. One price. Evidence you keep.
A fixed-scope diagnostic with a named deliverable and a date on it. No platform licence, no per-seat fee, no data hosted by us. How we handle your data →
FIXED PRICE · CREDITED AGAINST A BUILD$7,500 for the full Flight Check.
Credited in full against a remediation build signed within 60 days. If the report says nothing needs fixing, you paid for a clean bill of health with the evidence to prove it.
- SCOPE / One organisation, up to twelve agent or MCP endpoints in the first pass
- ACCESS / Read-only proxy inside your boundary; no credentials leave your network
- OUTPUT / Inventory, permission map, evidence export (JSON), findings report, remediation plan, readout
- TIME / Fourteen calendar days from install to readout
See a sample readout — findings, plan, and the export you can verify → WHAT YOU GET
Six things, all of them yours.
Delivered as files you own, in formats engineering already reads. Nothing is locked behind a login on our side.
01
Agent & MCP inventory
Every agent, model, MCP server, connector, and tool inside the agreed scope — up to twelve endpoints in the first pass — including the ones nobody remembers installing. Anything found beyond scope is listed, not audited.
02
Permission map
What each one can read, write, publish, purchase, or never touch — and who approved it, and when.
03
Ten days of records
Agent actions recorded inside your boundary as a hash-chained, tamper-evident timeline. Read-only. Nothing leaves your network.
04
Findings report
Risks, coverage gaps, and reliability failures — ranked, with the evidence that supports each finding.
05
Remediation plan
What to fix, in what order, with a build estimate engineering can act on the same week.
06
Leadership readout
Sixty minutes with your engineering and security leads. Questions answered from the record, not from slides.
HOW IT RUNS
Install. Record. Read out.
Two weeks is long enough to catch the weekly cadence of your agents and short enough that the answer arrives while the question is still live.
WEEK 1Install and interview
Witness is installed as a transparent proxy in front of your MCP servers and agent runtimes. We interview the owners of each agent and reconstruct the approval history.
READ-ONLY UNTIL YOU SAY OTHERWISEWEEK 2Record and analyse
Ten days of live traffic accumulate. We correlate actions against permissions, reconcile the inventory, and draft the findings.
READ-ONLY UNTIL YOU SAY OTHERWISEDAY 14Readout
Report, remediation plan, and evidence export delivered. Readout call with leadership. You keep the recorder running or switch it off.
READ-ONLY UNTIL YOU SAY OTHERWISE WHAT YOU HAND US · WHAT WE NEVER HOLD
The security packet, in one screen.
Written for the person who has to approve the install. If any line here is not true for your environment, the Flight Check does not proceed.
INSTALL
You install. We don't hold credentials.
Witness is a zero-dependency Node script you run from your own machines, wrapped around your MCP config with `witness wrap`. No agent of ours runs inside your network; no token, key, or password is ever given to us.
DATA
Hashed, not stored. Nothing leaves.
Arguments and results are SHA-256 digests; only keys you allow-list are summarised in plaintext, and any key that looks like a secret is excluded by construction. Records stay in a directory you own. The export you send us is one you have read.
RELAY
Transparent and fail-open.
Every frame passes through untouched. If the recorder cannot write, it says so on stderr and keeps relaying — recording can be lost, uptime cannot. Switch it off by restoring the backed-up config.
IDENTITY
Declared, not verified — and it says so.
Principals are labels from your harness config. Every record carries verified: false. We will not tell you a record proves who approved an action, because in this version it does not.
VENDOR
A name on the contract, and an instrument you can read.
Dark Vector Cognition LLC, Texas. Founded and run by Al Sharma, who is accountable for every engagement and is who you deal with directly — no account manager between you and the work. The recorder is Apache-2.0 on GitHub, so what runs in your environment can be read line by line before it runs.
SCOPE
Twelve endpoints. Two weeks. Fixed price.
What is found beyond scope is listed, not audited. The readout is delivered as files you own — no login on our side, no licence, nothing that stops working when the engagement ends.
Read what the recorder does, and what it refuses to claim, before you book: Witness, before you run it →
WHO IT'S FOR
Agent sprawl with a name on it.
The Flight Check is built for the person who will be asked, in a board meeting or an incident review, what the agents did — and has to answer from evidence.
YOU RUN
Claude Code, Codex, Cursor, or internal agents against production systems, and more than one team owns them.
YOU ARE
A 150–2,000-person software company — VP Engineering, Head of Platform, or CISO — being asked what the agents are doing.
YOU NEED
A defensible inventory, an evidence trail for the next incident, and a plan — not another vendor dashboard.
THE INSTRUMENT · WITNESS
Open-source, local-first, cross-vendor.
The Flight Check runs on Witness — DVC's agent flight recorder. A transparent MCP proxy that writes tamper-evident, hash-chained records of every agent action, with explicit coverage manifests so it never overclaims what it saw. Apache-2.0. Complete for one engineer for free; the Flight Check is where an organisation buys the reading of it.
- RECORDS / Operator, target, action, policy result, expiry, nonce — every entry chained to the last
- COVERAGE / Observed, absent, unreachable, unsupported, and unconfigured scope are all declared
- CONTROL / Read-only by default; suspend and terminate contracts fail closed and require explicit approval
- VENDORS / Not locked to one model provider, one IDE, or one cloud
What Witness does and does not claim →AFTER THE READOUT
The report is the beginning, not the invoice.
A diagnostic that ends in a PDF is expensive homework. Every Flight Check ends with a costed path to fixing what it found — and you can take that path with us or without us.
BUILD · $50–200K · 4–12 WEEKS
Fix what the record found.
Permission boundaries, approval gates, agent contracts, and the evidence pipeline — built in your environment, owned by you. The $7,500 comes off the top.
OPERATE · FROM $5K / MONTH
Keep the recorder running.
Continuous recording, monthly findings, and a human who reads the chain before your auditor does. For estates that change weekly.
RE-CHECK · $500 / MONTH
Come back every year.
An annual return for estates that change slowly. We re-record for ten days and diff the result against your previous record, so the report is what changed rather than what exists — new servers, widened permissions, agents that went quiet. Between re-checks you get four hours of advisory time a quarter, answered next business day.
Re-check begins after your first Flight Check and is billed monthly, cancellable at any renewal. Incident response is scoped separately — the four hours are advisory time, not a retainer for an emergency.
TWO WEEKS · $7,500 · NOTHING LEAVES YOUR NETWORK
Book the readout call.
Thirty minutes to confirm scope and dates. If the Flight Check isn't the right instrument for your estate, we'll say so on the call.
Book the readout call →