<!-- Generated from for-startups.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# You are a startup

Your first serious enterprise customer will send a security questionnaire with agent questions on it. A behaviour policy answers them with rows rather than assurances.

Source: https://riskmandate.ai/for-startups.html

---

# The questionnaire is coming.

Your first serious enterprise customer will send a security questionnaire with agent questions on it, and the questions will be about what your agents can reach rather than what model you use. A behaviour policy answers them with rows rather than assurances.

## What does your buyer’s security team actually need from you?

## A yes or a no is not an answer any more.

A questionnaire asks whether an agent is restricted. The honest answer for most deployments is that it is restricted by a setting the agent’s own account could change, which is not a restriction at all. Saying so with the barrier named is a better answer than a yes, and it is one you can support when somebody tests it.

## One document per agent, not one per buyer.

The behaviour policy is context-free: the same document wherever the agent runs, so it is written once and sent to every buyer who asks rather than rewritten per questionnaire. When a connector or a credential changes, the grant changes and the delta recomputes against both, pinned to the versions it was computed from.

Status, plainly: this is the part that exists and runs. What does not yet exist is a packaged buyer-facing export, and we are not going to describe it as though it does.

## Nothing here was built pointing at startups yet.

Three groups arrive at this — teams running agents, founders, and startups being diligenced — and of the offers that exist, none was built for the third. The document works; the packaging for your case is the thing we would be building with you rather than selling you off a shelf. That is worth knowing before you spend time on it.

## One thing, at four levels.

Level three is the one built for a buyer’s question, and level four is the one where somebody sits with your team. Level two is the cheapest way to hold the material yourself. The whole ladder, what each level changes and who does the work is on [pricing](pricing.html); the catalogue and the checkout are on the store.

The store takes the order and hands you back here: one page per level, and at level one that page **is** the download — the zip, its size, its sha256 and a check that runs in your own browser. Payment rails are not built yet, and every checkout button on the store says so rather than looking live.

## Answer it once, properly.

One agent, enumerated, with the barriers named and the gap computed — a document you can send rather than a form you refill.
