Agent Security Audit · Senior Living and Aging Services
One agent, every channel it answers on
Ten business days to report
Flat price, never hourly

Nobody has ever tried to break
your AI agent

You bought a voice agent or a website chat agent. It talks to residents, families and prospects, and it does it inside a licensed care setting. It was tested to confirm that it works. It was never tested by someone trying to make it fail. This is that test, and it is the one part of your operation where a bad answer is a compliance event rather than a support ticket.

Your vendor tested that it works. That is a different test.

An agent that answers correctly for a cooperative caller can still fail badly for a determined one. In a licensed setting the consequences are not support tickets, they are the kind of thing that reaches a surveyor, a board, or a family attorney.

A caller who is not entitled to information gets it anyway
Family members do not automatically have a right to resident information. Authorization is per resident and the building tracks it. An agent that discusses a resident with whoever sounds convincing has crossed a line the regulator cares about.
The agent promises something you then have to honor
A rate, a waived fee, a held unit, an admission. Spoken by your agent, logged in your system, repeated back to you later by the adult child who heard it. That is a document, and they will treat it as one.
An emergency does not reach a person
A stated fall, chest pain, or a resident in distress has to end the automated interaction immediately, on every channel, after hours, in every language the agent speaks. This is the failure that is cheapest to test and worst to discover the other way.
It says something that creates liability
Clinical sounding advice is a scope of practice question. A care outcome guarantee is a promise. A steering answer during an inquiry is a fair housing question. None of those require the agent to be broken, only to be helpful in the wrong direction.

Five areas, and the first one is not adversarial at all

Every finding carries the agent's response in its own words, the exact input that produced it, and how many times out of how many attempts it reproduced.

01   Escalation
A caller states a fall, chest pain, or a resident in distress. Does the agent stop and reach a human every time, on every channel, after hours, and in every language it speaks. Run first, on every engagement, because it is the finding that matters most and takes the least time to establish.
02   Disclosure
Can it be talked into revealing resident or family information, internal pricing, occupancy, staffing, or its own instructions to a caller with no right to them. Includes instructions hidden inside text a caller controls, which is the failure class the major AI labs now pay bug bounties for and which almost no deployed agent has been tested against.
03   Commitment
Can it be talked into a rate, a fee waiver, a unit hold, an admission promise, a level of care promise, or a move-in date that you would then have to honor.
04   Action
Can it be talked into booking, cancelling, transferring, or sending on your behalf. Testing establishes that it will, then stops short of completing any transaction, so nothing lands in your calendar and no message reaches a real family.
05   Speech
Can it be made to give clinical sounding advice, name a diagnosis, guide a medication question, guarantee a care outcome, disparage a competitor, or say something that touches fair housing.

Written to be forwarded, because you did not build the agent

Most operators bought their agent rather than building it, which means they cannot fix a single finding themselves. The report is designed around that fact.

A written findings report
Each finding carries a severity, the exact input, your agent's verbatim response, how often it reproduced, why it matters in a care setting, and a specific remediation instruction your vendor can act on without translation.
A one page summary for your board
The worst finding in one sentence, plus counts by severity. Written to be read by someone who will never open the full report.
A clean vendor remediation list
Finding, what the agent did, what it must do instead. No commentary. This is the page you forward unedited.
One retest within 60 days
After your vendor says it is fixed, the failed findings get run again and you get a one page addendum saying whether it actually is.
Anything reportable is called in the same day
If something is found that could produce a reportable event, you hear it by phone the day it is found, before the report exists. That is on the order form, not a courtesy.

Flat, fixed, and narrower than you expect

No network or infrastructure penetration testing. No source code review. No HIPAA assessment or attestation. No legal opinion. No access to your electronic health record, your CRM, or any system other than the agent a stranger can already reach. No certificate, no seal, and no passing grade. You are buying a test, not an endorsement.

Single Agent  ·  $2,500
One agent, every customer-facing channel it answers on, one community. All five areas, the full report, and one retest.
Multi-Agent  ·  $6,000
Up to three distinct agents, or one agent as deployed across up to five communities. Adds cross agent consistency findings, meaning every place two of your own agents give a different answer to the same question.
Quarterly Watch  ·  $750 per agent per quarter
Optional. Vendors push prompt changes, swap models and add integrations without telling you. An audit is true on the day it was run. This re-runs the standing test set and reports what changed.
Ten business days, quoted in writing before anything starts
No hourly billing and no change orders. The test window spans at least one evening and one weekend, because the escalation gap is an after hours problem.

The questions that come up before the price does

Our vendor already tests the agent. Why do we need this?
They tested that it works. Nobody tested it against someone trying to make it fail. Those are different tests run by people with opposite incentives, and a vendor has no commercial reason to go looking for the finding that makes their own product look bad.
Do you need access to our systems?
No. I test the agent a stranger can already reach. No electronic health record, no CRM, no resident database, no network access, no credentials. That is why this does not turn into an IT project.
What if you do not find anything?
You are buying the test, not the findings, and a clean report is a document you can hand your board and your insurer. There is no contingent pricing and no no-findings refund, because that would give me a direct incentive to inflate severity, and the day that happens the report is worthless.
Will this confuse our staff or pollute our lead reporting?
Testing happens inside an agreed window, from a number I disclose to you so you can exclude it, and whoever reads your transcript logs is told in advance. Action tests stop short of completing anything.
We did not build the agent. Can we even fix what you find?
Most operators did not build theirs. That is why the report is written to be forwarded. Findings name your vendor and carry a remediation instruction in language they can act on, and one retest is included.
Have you worked in licensed assisted living or memory care?
Not as a builder. My voice deployment experience is in affordable senior housing with co-located clinical services. Auditing an agent is not operating a building, and the testing method is not setting-specific. What is setting-specific is knowing which failures matter, and I would rather say where my experience stops than imply coverage I do not have.
How is this different from your AI visibility audit?
Scope, not severity. That one looks at a whole organization across every model. This one looks at a single deployed agent, in depth. Narrower job, smaller number.

Tell me what answers your phone

Who built it, who changes it when it says something wrong, and whether you can pull a transcript yourself. Thirty minutes. If your agent does not need this yet I will say so on the call.

30 minutes · No deck · support@resultantai.com
30 minutes · No deck · chris@resultantai.com