Why LeftOut Security

Do you know
your agent?

The thing everyone can see is not always the whole system. That is why there is an eye, a dog, and something impossible waiting beneath the mask.

Tom and his black dog Ruby discover a tentacled creature with one large central eye and several smaller eyes beneath a yellow smiling mask in a server room
The threat beneath the maskWhat looks familiar can still hold authority nobody mapped.
The reveal

We kept finding the same kind of mystery.

A team would show us the model. The model would look reasonable. The demo would work. The policy would sound responsible. Then we would follow the system one step farther.

Behind the friendly interface were identities, retrieval systems, plugins, tools, data stores, approval paths, persistent memory, and permissions to act. The visible thing was real. It just was not the whole thing.

That is the Shoggoth in the picture: not a claim that AI is a monster, but a reminder that a simple face can conceal a complicated system.

The mask

The mask is useful. It is also incomplete.

“Helpful assistant” is a product description. It is not a security boundary.

A model can be polite while the system around it holds a production credential. A guardrail can refuse one sentence while a tool executes another path. A risk register can say “human in the loop” without showing who the human is, what they see, or whether they can stop the action in time.

Safety language describes intent. Assurance has to describe reach.
The control problem

The old story was about what a model might say.

The harder story is what the entire system can do.

InputInterpretationAuthorityActionImpact

Once software can retrieve private data, call tools, change records, send messages, approve work, or trigger downstream systems, model behavior is only one link in the chain. The security question moves from “Is the answer good?” to “What can this system cause to happen?”

Where LeftOut works

We work in the middle—the place diagrams compress and questionnaires skip.

LeftOut Security follows the execution path between a request and its consequence. We map what the agent can reach, which identity it borrows, what evidence supports the claimed controls, where approval actually happens, and how failure can travel into the business.

Identity

Whose authority is the system using?

Data

What can it read, retain, combine, or expose?

Tools

What can it change, trigger, or communicate?

Evidence

Which controls are proven, observed, asserted, or unknown?

Shadow authority

Systems often have more authority than their owners can explain.

Permissions accumulate. Service accounts outlive their original purpose. A connector turns read access into action. A user’s identity passes through an agent into a tool nobody included in the threat model.

We call that shadow authority: real operational power that is missing, understated, or disconnected from the organization’s view of the system.

It is not mysterious once you trace it. It is dangerous precisely because nobody did.

Independent assurance

A second set of eyes should not have something else to sell.

If the same party that validates a system also expects to implement the fix, every finding can become a sales lead. LeftOut Security keeps the boundary clean: we assess, validate, and explain. Your team—or the partner you choose—owns remediation.

AI may help organize evidence, surface inconsistencies, and test reasoning. A named professional reviews and signs the final conclusion. Independence does not mean automation without accountability.

The name

Why “LeftOut”?

Because important failures rarely arrive with a label saying “this was excluded from scope.” They live between teams, tools, diagrams, contracts, assumptions, and ownership boundaries.

The application team sees features. The model team sees evaluations. The cloud team sees infrastructure. The governance team sees policy. The buyer sees a questionnaire.

We look for what those views left out.

And the dog?

Ruby is there because curiosity should stay human.

The picture is deliberately a little absurd. Security work does not become more rigorous when it becomes humorless.

Ruby represents the instinct to stop at the strange noise, look behind the false wall, and keep pulling when the explanation does not match the evidence. She is also a very good dog.

The question

We are not monster hunters.

Most agents are not monsters. Most failures are not science fiction. They are familiar security problems—identity, authorization, data exposure, unsafe dependencies, weak change control, missing evidence—moving at machine speed through a new interface.

The eye is not watching the monster. It is watching the gap between what the system appears to be and what it is allowed to do.

So the question is not whether your AI looks helpful.

Do you know your agent?

Bring the whole system into view

Need an independent answer about what your agent can actually do?

Start with a short, non-sensitive overview. If an assessment is a fit, the next step is a focused consultation and written scope.