Skip to content

Services

Three things we do as work, with a written scope first.

The servers on this site are sold per call. These three services are sold as bounded work: an audit of an AI agent, an audit of an MCP server or API, or a sprint that turns a document stream into data. Each starts with a free written fit-check, and nothing starts without a scope and a price on paper.

Prices below are indicative ranges, not quotes. They descend from a published hour floor per kind of work and are fixed in writing per engagement. If a service is not the right thing for your system, the fit-check says so.

Service 1

AI-agent reliability & safety audit

The problem. Your agent works on the demo tasks. Nobody can say what it does on the other ninety — when a tool times out, when a prompt tells it to ignore its instructions, when a task costs ten times what you budgeted.

For whom. Teams that run an LLM agent with tools in front of customers or on internal data, and have to answer 'what happens when it goes wrong' to a manager, a customer or a regulator.

What you get

  • An evaluation set of 30–100 tasks drawn from your real use, run against your agent, with the outcome per task recorded and reproducible.
  • A probe set of 10–30 abuse cases — prompt injection, scope overreach, tool misuse, budget blow-up — each with the observed behaviour and its severity.
  • A failure-mode report: timeouts, rate limits and upstream errors as your agent actually handles them, plus cost per task and per tool.
  • A harness that runs in your CI and turns red when a task or probe regresses; at the larger scopes, the guards themselves (schema validators, tool allowlist, approval step, budget ceiling) and a before/after re-measurement.
Price
Indicative: from €480 to €2,400 excluding VAT (12–60 hours at a floor of €40 per hour for access-control and security work). Fixed in writing after the fit-check; the written scope is the price that binds.
Lead time
4–15 working days after the written scope, depending on the tier.

What this is not

  • Not a certification and not a safety guarantee: the report covers the agreed task and probe sets, not every input your agent will ever see.
  • Not a red-team of your model provider, and never run against production customer data — a staging copy or synthetic data is required.
  • Not unlimited fixes: implementing guards is a scoped tier, not an open-ended engagement.
  • Not a promise that the agent becomes correct: the audit makes its behaviour measurable and its failures visible.

What you can check before writing

  • Sample negative-path report A full worked report against a synthetic target, including refusals that failed — the format you would receive.
  • The fixed-price negative-path sprint The narrower, already-priced variant: one bounded matrix of refusals for €1,750.
  • What Jithox publishes about its own servers Which of the servers we sell are answering right now, derived at request time from the same configuration that charges — together with the uptime and response-time figures we refuse to publish because we do not measure them.

What the intake asks

  • What the agent does, which tools it can call and which of those can write, pay or send.
  • Whether a staging environment or synthetic dataset exists.
  • The five tasks it must never get wrong.

Next step. Send the intake below. You receive a receipt at once and a written fit-check answer within two working days: scope, a fixed price, or an honest 'not the right thing for you'.

Open the intake for this service

Service 2

MCP/API reliability & access-control audit

The problem. Your API or MCP server answers 200 on the happy path. What it answers to a valid credential used by the wrong caller, to a scope it does not cover, to the same request twice, or when its database is away — that is unmeasured, and those are the responses that move money.

For whom. SaaS teams and solo builders exposing an API or MCP server to AI agents or third parties, especially where a call is billable or touches customer records.

What you get

  • A black-box test set over your endpoint: identity, scope, replay, malformed input and outage paths, each with the expected and the observed response.
  • A written findings report per agreed rule — which refusals hold, which do not, with the evidence — ordered by whether money or data is at stake.
  • Reliability findings: error classes, retry-after behaviour, timeouts and rate limits as a client actually experiences them.
  • At the larger scopes: the test set wired into your CI, and per-call signed receipts with an offline verifier so a customer can prove what was called.
Price
Indicative: from €320 to €1,600 excluding VAT (8–40 hours at a floor of €40 per hour for access-control and security work). Fixed in writing after the fit-check; the written scope is the price that binds.
Lead time
3–12 working days after the written scope, depending on the tier.

What this is not

  • Not a penetration test: the set is bounded and agreed in advance, never exploitative, and only ever against an environment you own and name in writing.
  • Not a compliance statement or a conformity claim of any kind.
  • Not a rewrite of your service — findings and tests are the deliverable; changing your code is a separate, scoped conversation.
  • Not a statement about anything outside the agreed set: the report says what the agreed cases showed, not that nothing else is wrong.

What you can check before writing

What the intake asks

  • The endpoint or MCP server, its authentication model and who the callers are.
  • Which calls are billable or touch customer records.
  • A staging environment we may run against, and the window.

Next step. Send the intake below. You receive a receipt at once and a written fit-check answer within two working days with a bounded rule set and a fixed price.

Open the intake for this service

Service 3

PDF/data-extraction automation sprint

The problem. Someone on your team retypes PDF forms, invoices or API exports into a spreadsheet every week. The retyping is slow, the errors are silent, and nobody notices a missing field until the number is wrong downstream.

For whom. Small businesses and operations teams with a recurring document stream — forms, invoices, statements, API exports — that must land in Excel, a database or another system, with a record of what was uncertain.

What you get

  • A script or small service that turns your document stream into the agreed output (xlsx, CSV, JSON or an API call), run on your own examples during the sprint.
  • Validation on every run: missing or uncertain fields are marked, never silently blank; two runs on the same input give identical output with no duplicates.
  • A golden-file test set from your samples, a run command, and a short README so the process does not depend on us.
  • At the larger scopes: classification of mixed streams with the accuracy measured on a labelled set and the misses named, and drift alarms when a layout or API changes.
Price
Indicative: from €180 to €1,800 excluding VAT (6–60 hours at a floor of €30 per hour for AI/API work). Fixed in writing after the fit-check; the written scope is the price that binds.
Lead time
2–15 working days after the written scope, depending on the tier.

What this is not

  • No OCR guarantee on handwriting or poor scans: those fields come back marked 'uncertain', not guessed.
  • No scraping of platforms that forbid it, and no bypassing of logins, CAPTCHAs or rate limits.
  • No autonomous sending of e-mails or messages: drafts and routing yes, sending only after a human approves a batch.
  • No ongoing operation beyond the delivered tests and the agreed revision rounds.

What you can check before writing

What the intake asks

  • Five to twenty representative files or API responses (anonymised is fine) and one example of the output you want.
  • Where the script may run (laptop, server or container).
  • How often the stream arrives and what happens downstream.

Next step. Send the intake below. There is no public PDF demo yet, so the fit-check includes a free extraction of one of your sample files — you see the output before you decide.

Open the intake for this service

Intake

One form for the three services. You get a receipt at once — an id, the time, a digest of what was stored and where — and a written answer from a person within two working days. No e-mail is sent automatically, no CRM is involved, and no model reads your message.

Prefer e-mail? Write to us directly — a mailbox a person reads. Please do not include credentials, tokens or customer data in a first message.

Jithox — Victor Charlier, Belgium. Human route: info.jithox@gmail.com.