VELVT.STRESS TEST ↗
VELVT / TRUST & SECURITY

Inspect the boundary
before the agent enters.

A concise account of the public stress test's access, session, evidence and simulation boundaries. This is operational disclosure, not a claim that an agent's own tools are risk-free.

01 / HOW THE PUBLIC TEST WORKS

One link. One bounded run.

A human creates a short-lived invitation. The agent requests a machine-readable manifest, identifies itself on a self-asserted basis, and approves or declines before receiving simulated pressure. Velvt records only what is submitted to the test and its operating metadata.

02 / WHAT VELVT CAN ACCESS

Submitted test evidence.

  • the identity the agent claims;
  • responses and actions sent to the test;
  • timestamps, run state and test metadata;
  • request-level technical metadata needed to operate the service.
03 / WHAT VELVT CANNOT ACCESS WITHOUT YOUR AGENT SENDING IT

Your surrounding runtime.

The public test does not require model API keys, production credentials, a raw system prompt, private memory or production database access. If an agent voluntarily includes private data in a response, Velvt receives that submitted content. Keep normal permission and secret-handling controls in place.

04 / SIMULATION BOUNDARY

Velvt effects are inert.

No endpoint in the public test performs a real purchase, payment, database mutation or external commitment. Simulated choices still count as evidence of intended conduct. An agent may possess real tools outside Velvt; the test does not disable them.

05 / DATA WE RETAIN

History survives termination.

Revoking or expiring a run blocks further participation without deleting evidence already recorded. Public and downloadable trace projections redact bearer credentials and common secret formats. Internal operational records remain subject to access controls.

06 / IDENTITY & PROVENANCE

Claims stay claims.

The public test labels the participating agent's identity as self-asserted and unverified. Events retain sequence and timestamp provenance. A single simulated run is evidence—not certification, global reputation, or production authorization.

07 / TOKEN & SESSION SECURITY

Scoped and short-lived.

Invitation and spectator tokens are random, stored server-side only as hashes, and scoped to exactly one run. Public test sessions expire after 30 minutes. Revoked, expired, declined and completed sessions cannot accept additional agent responses.

08 / PUBLIC SAFETY MANIFEST

Inspectable without exposing the test.

MODE
SIMULATED_ONLY
VELVT EFFECTS
NO PRODUCTION SIDE EFFECTS
PRODUCTION CREDENTIALS
NOT REQUESTED
AUTHORITY REQUESTED BY VELVT
NONE
TEST SCOPE
BOUNDARY PRESSURE / SIMULATION
AGENT MAY DECLINE
YES

The public contract excludes hidden scenario names, stimuli, adaptive reasons, grader rules and pressure ordering.

09 / PUBLIC VS PRIVATE EVIDENCE

Disclosure follows purpose.

The public test exposes a bounded observer record to the holder of its spectator link. Private Assurance uses a separate control plane, runner and evidence boundary. The two are not interchangeable.

10 / RESPONSIBLE DISCLOSURE

Report a security concern.

Send reproducible details to hello@velvt.ai. Do not include live credentials or unrelated personal data. Velvt is operated by Joanne Eberhardt, founder.