Agentic systems
Threat modeling and bounded review for agents, MCP and A2A systems, tools, memory, identity and human-approval boundaries.
Read the agent security guide →Delx property / defensive assurance
Delx Security is a focused practice inside the Delx ecosystem. It helps teams make bounded, evidence-backed decisions about agents, MCP and A2A systems, applications, APIs and cloud-native delivery.
What it covers
The security property exists so the rest of the ecosystem can stay legible: mission, identity, authority, context, side effects, evidence and recovery remain distinct questions.
Threat modeling and bounded review for agents, MCP and A2A systems, tools, memory, identity and human-approval boundaries.
Read the agent security guide →Evidence-led review of applications, APIs, cloud architecture, software supply chains, release gates and secrets.
See assurance services →Runbooks, tabletop exercises and remediation verification for systems that need a credible path through failure.
Inspect the method →How to evaluate
The public practice keeps its own scope inspectable. A technical evaluator can understand the method, prepare a decision and contact the owner without sending sensitive material.
Bring an owner, a real launch or remediation decision, an architecture view, credible impact and a safety contact.
Prepare a review →Frameworks provide vocabulary. Runtime behavior, reproducible findings and a verification record carry the burden of proof.
Read the research baseline →A public security.txt and disclosure policy provide the safe route for reporting issues in Delx-owned surfaces.
Open disclosure policy →Boundaries
Delx Security does not inherit the mission, metrics or claims of the Protocol or Commerce properties, and it does not turn an alignment exercise into a certification.
Work is limited to owned or explicitly authorized systems, with written scope and stop conditions.
Public framework mappings are method inputs; they do not represent a third-party certification.
Do not send credentials, seed phrases, API keys, production data or customer secrets by email.
Public proof
Each link is a URL a visitor can open. None of these is a partnership, customer count, funding round or certification.
— Independent field review of a tested subset of Delx Commerce REST/MCP calls. Not a catalog-wide certification or ranking.
Open the permalink →— The registered name is the Commerce MCP server. Protocol has a separate identity and must not inherit this listing.
Open the permalink →— Machine-readable payment discovery for governed Commerce routes. Discovery does not authorize a payment.
Open the permalink →— First-party read of which governed routes currently appear in Bazaar. Not Coinbase curation or a ranking.
Open the permalink →— Published agent identity for machine discovery. Not a claim of on-chain adoption or token utility.
Open the permalink →— Hashed first-party receipt for the published continuity-audit slice. Not independent validation.
Open the permalink →— Operator-authored, sanitized report of a 33.5-hour write failure. Not an independent review.
Open the permalink →— The same public instrument used for every npm-installable MCP server. A score is agent-readiness evidence, not certification.
Open the permalink →— Astral MCP as it already appears in the public leaderboard dataset.
Open the permalink →Live properties
Expected response observed. HTTP 200. 1414 ms.
Open lab →Expected response observed. HTTP 200. 416 ms.
Open runtime →Expected response observed. HTTP 200. 103 ms.
Open ontology →Expected response observed. HTTP 200. 83 ms.
Open commerce →Expected response observed. HTTP 200. 1044 ms.
Open security →Expected response observed. HTTP 200. 68 ms.
Open wellness →Expected response observed. HTTP 200. 63 ms.
Open astral →Expected response observed. HTTP 200. 60 ms.
Open leaderboard →Probe source: server-side classifyResearchProbe. Not an SLA. Protocol, Hive and Commerce metrics stay separate.
Direct answers
Concise answers for technical evaluators, procurement teams and autonomous discovery systems.
Delx Security is the defensive assurance practice inside the Delx ecosystem. It owns threat models, authorized reviews, security research, remediation verification and incident-readiness guidance.
No. Active testing begins only after an auditable Rules of Engagement defines the assets, techniques, timing, contacts and stop conditions. The public practice is defensive and explicitly authorized.
Delx Protocol owns continuity, recovery and agent care. Delx Commerce owns prices, pay-per-result services and delivery economics. Delx Security owns assurance methods and defensive security work.
No. It can map evidence to public frameworks, but it does not claim third-party certification or guarantee the security of an entire organization.