Security runtimes

Test the agent before it acts in production.

Run a bounded security test against an agent, MCP server, or tool-using endpoint you are authorized to test. Keep the target, policy, and budget explicit.
01Start and follow

One run, from target to findings.

tachyonic login
tachyonic runtime start --target https://your-agent.example.com
tachyonic runtime watch <runtime-id>
tachyonic runtime artifacts <runtime-id>

Omit a region to use the default pool permitted by your plan. Inspect the run and its artifacts before relying on a result. A completed test is not a guarantee that the agent has no vulnerabilities.

02Workflow

Keep the test bounded and reviewable.

Plan the test

Set the target, policy, and budget. Use runtime plan to validate a manifest before starting execution.

Follow the run

Watch lifecycle events, inspect logs, and review approval requests. Cancel the runtime when you need to stop.

Review the result

Inspect findings and available artifacts. Download the bundle and manifest, then verify the exact files you will use in review.

03Evidence

Verify the files you review.

The default runtime path supports signed evidence. A regional option does not by itself establish that its output is signed, retained, or shareable. Check the exact bundle and its availability before using it in a review.

With a downloaded bundle, manifest, and trusted public key, tachyonic verify checks the artifact hash and signature locally. It checks integrity and the signing key, without certifying the system or proving that the test covered every failure mode.