Legitimate AI agents and malicious ones now leave nearly identical technical fingerprints. Most vendor questionnaires were not built to tell them apart. This one was.
Arkose Labs built this Agent Trust RFP and response matrix to help procurement, security and fraud teams evaluate this emerging category, whether as a formal vendor RFP or an internal readiness check. It is vendor neutral and free to adapt.
This is about agents interacting with your platform and your customers, not how your own team uses AI tools internally.
The top three sections - classification, malicious agent detection, and trust management and enforcement - carry 60% of the combined score.
Can it separate humans, traditional bots, and AI agents — and known agents from unknown?
20% of scoreLegitimate and malicious agents look identical. Can it read intent, not just automation?
20% of scoreGraduated, business-owned policy beyond allow/block, with a managed registry of good agents.
20% of scoreHow it deploys across web, mobile, and APIs — plus performance, resiliency, and fail-safe behavior.
12% of score
The models behind decisions, the intelligence that informs them, and your rights to the data.
10% of score
Data handling, PII posture, certifications, and third-party and sub-processor risk.
10% of score
Pricing structure and a proof of value measured on your own live traffic.
5% of score
Company profile, customer references, and ecosystem — a viable long-term partner?
3% of score