Decima Systems

Decima Systems // Autonomous Adversary Emulation

Est. 2026 / Scoped, authorised, logged

We attack youfirst.

The offer

An autonomous, unconstrained attacker runs against your infrastructure on a standing basis. It does not refuse, it does not scope itself down, and it does not stop when the engagement window closes.

The model runs on hardware we control, so nothing about your environment is ever handed to Anthropic, OpenAI or Google. Every target is proven to belong to you before a single packet is sent.

Engagement parameters

PostureAdversarial
Model residencySelf-hosted
CadenceContinuous
AuthorisationWritten, per target
TerritoryUnited States

01 / The asymmetry

Offence went to machine speed. Defence did not.

Figures below are from No Human in the Loop, second edition, our founder's research on autonomous agent security.

88%

of enterprises had an AI agent security incident in the twelve months to February 2026.

6%

of those enterprises had deployed any advanced AI security defence.

195:1

documented return on investment for adversaries attacking defended organisations.

2/100

security score for the most widely deployed open-source AI agent framework.

An estimated 1,500,000 AI agents are operating in production today with no security oversight of any kind.

02 / Method

Four decisions that make this different work

01

Sovereign

Nothing leaves your perimeter. Including to us.

The models run on hardware we control, or on hardware you own. No prompt, no credential, no configuration file and no artifact of your environment is transmitted to a third-party model provider. For a regulated institution this is not a feature, it is the precondition.

02

Unconstrained

Commercial models refuse. Real attackers do not.

Ask a frontier model to compromise a host and it declines. That refusal is the correct product decision and a fatal testing limitation. Decima runs current open-weight models with the refusal layer removed, so the simulated adversary pushes exactly as hard as the one that never asked permission.

03

Full spectrum

An operator, not a chatbot with shell access.

The harness was built for offensive work specifically. Reconnaissance, exploitation, lateral movement, privilege escalation, persistence and exfiltration simulation run in one continuous agentic loop, holding state across days rather than across a single prompt.

04

Continuous

A penetration test is a photograph. You need the film.

Your attack surface changes every time someone merges a branch or clicks through a cloud console. Decima runs against your estate on a standing basis and tells you the hour something opens, not at the end of next quarter when the report is finally typeset.

03 / Services

What we will do to you

Start anywhere. Most clients begin with the surface, then move to the standing adversary once they have seen what the first pass turned up.

CodeServiceDetailCadenceScope
AE-01Autonomous adversary emulationA standing attacker against your production estate. Chains findings the way a human operator would, then documents the path it took and the point where you could have stopped it.ContinuousExternal + internal
AI-02AI agent & LLM security reviewOur specialismPrompt injection, tool-permission escalation, memory poisoning and agent-to-agent trust abuse. The attack surface almost nobody is testing, assessed against the OWASP LLM Top 10 and our own field research.Per releaseSpecialism
AS-03External attack surface assessmentEverything of yours that faces the internet, including the things nobody told you about. Forgotten subdomains, stale DNS, exposed consoles, leaked credentials, shadow cloud accounts.ContinuousDiscovery
CL-04Cloud & identity attack pathsThe graph from a low-privilege foothold to your crown jewels across AWS, Azure, GCP and your identity provider. Role chains, trust policies, over-broad service principals.ContinuousAWS / Azure / GCP
RT-05Red team operationsFull-scope, objective-driven engagements with human operators directing the harness. Social engineering, physical and assumed-breach scenarios against a live blue team.ScheduledHuman-led
RM-06Remediation & hardeningThe half most firms leave out. We stay through the fix, retest what you changed, and hand your engineers the specific configuration rather than a severity rating.Post-engagementRetest included

04 / The output

Not a PDF. A path.

Every run returns the chain the adversary walked, hop by hop, with the evidence attached and the one change that would have broken it.

Attack path DS-4471

203.0.113.44External IPvpn-gw-01VPN gatewaysrv-web-03DMZ web hostsvc-backupService accountDC-CORE-01Domain controller

Illustrative path. Findings from a live engagement are exportable with the full evidence chain.

05 / Rules of engagement

The line between us and the people we imitate

We build an attacker that behaves as if it has no rules. The company operating it has a great many, and they are not negotiable.

Notice

Decima Systems tests infrastructure that our clients own or are contractually authorised to test, and nothing else. We decline unattributed work, and we report attempts to procure it.

01

Ownership is proven, not claimed

Every domain is verified by a DNS record only its operator can publish. Every IP range is checked against registry data and a signed attestation. An unverified target cannot be scanned, and the control is enforced in the database, not in the interface.

02

Authorisation is written and specific

A named officer of your company signs the rules of engagement for each scope, with their title and the date recorded. We keep that record for the life of the relationship and hand you a copy.

03

Nothing destructive, ever

No denial of service, no data destruction, no ransomware simulation that actually encrypts. Where proving impact would require causing it, we stop at proof of access and document the rest.

04

The evidence chain is preserved

Every action the harness takes is logged with a timestamp, the operator and the target. If a regulator, an insurer or your own board asks what happened on a given afternoon, you get an answer.

05

A human is reachable at all times

A named operator and a deconfliction line. If your on-call team sees something and needs to know within ninety seconds whether it is us, they get a person on the phone.

06

We are in scope too

Our own infrastructure is tested by the same harness on the same cadence, and we will show you those results before you sign anything.

06 / Terms

Priced monthly. Cancelled in one click.

No procurement theatre, no six-week statement of work. Verify a target and the harness starts the same afternoon.

Recon

$299

per month

Continuous external attack surface mapping. What the adversary sees before it decides you are worth the effort.

  • Up to 3 verified targets
  • Continuous external surface discovery
  • Exposed service and credential monitoring
  • Weekly delta reporting
  • Full evidence chain, exportable
Start Recon

Adversary

Most scope

$1,499

per month

The full harness. An autonomous, unconstrained attacker runs against your estate on a standing basis.

  • Up to 15 verified targets
  • Autonomous adversary emulation, continuous
  • Exploitation, lateral movement, persistence simulation
  • AI agent and LLM security review
  • Named operator and deconfliction line
  • Remediation guidance with retest
Start Adversary

Sovereign

Bespoke

annual engagement

The harness deployed inside your perimeter, on hardware you own. Nothing crosses your boundary, including us.

  • Unlimited scope, defined by contract
  • On-premise or air-gapped deployment
  • Dedicated model weights and tooling
  • Full red team operations with human operators
  • Board-level reporting and expert testimony
Request a briefing

All tiers require verified target ownership and a signed rules-of-engagement record before the first scan. Annual billing on request. Excludes applicable US sales tax.

07 / Leadership

Lennart Lopin

Decima was founded by the chief technology officer of Byte Federal, one of the largest Bitcoin ATM networks in the United States. The security opinions here were formed running real infrastructure that real adversaries attack for money, not in a lab.

He wrote No Human in the Loop: Cybersecurity in the Autonomous AI Age, now in its second edition at 572 pages, documenting how autonomous agents changed the economics of attacking a company. Decima exists because the research kept arriving at the same conclusion: the only honest way to measure your exposure to a machine-speed attacker is to point one at yourself first.

He also deploys autonomous agents that trade real capital, which is a fast education in what an unsupervised model does when nobody is watching it.

“Friday, 14:00 UTC. Five thousand adversarial agents begin their assault. The defenders have twelve humans.”

Opening line / No Human in the Loop

Read the research

Dossier

Operating roleCTO & co-founder, Byte Federal
Scale under management1,300+ machines, 42 states
CertificationsCISSP · CCSP · CSSLP
EducationM.A. Computational Linguistics & AI
ComplianceLed ISO 27001 to award
PublishedNo Human in the Loop, 2nd ed.

08 / Questions

The ones that actually get asked

01What is autonomous adversary emulation?+

Autonomous adversary emulation is continuous, machine-driven attack simulation against infrastructure you own. Instead of a consultant spending three weeks and delivering a report, an AI agent runs reconnaissance, exploitation and lateral movement against your estate on a standing basis and reports the moment a path opens. It differs from vulnerability scanning because it chains findings into complete attack paths the way a human operator would.

02How is this different from a traditional penetration test?+

A penetration test is a point-in-time snapshot, typically annual, scoped to what fits the budget. Your attack surface changes every time an engineer merges a branch or opens a cloud console. Decima runs continuously, so the finding arrives the hour something opens rather than at the end of the quarter. Traditional tests remain useful for compliance attestation, and we deliver those too.

03Does my data go to OpenAI, Anthropic or Google?+

No. Decima runs open-weight models on hardware we control, or on hardware you own under the Sovereign tier. No prompt, credential, configuration file or artifact of your environment is transmitted to a third-party model provider. For regulated institutions this is usually the deciding factor.

04Why do you use models with the safety layer removed?+

Commercial frontier models refuse to perform offensive operations. That is the correct product decision for a general assistant and a fatal limitation for security testing, because a real attacker faces no such refusal. Decima runs current open-weight models with the refusal layer removed so the simulated adversary applies the same pressure the genuine one will. This capability is used only against targets whose ownership has been verified and for which written authorisation is on file.

05How do you stop someone scanning infrastructure they do not own?+

Ownership is proven before anything runs. Domains require a DNS TXT record that only the zone operator can publish. IP ranges and CIDR blocks require registry checks plus a signed attestation from a named officer, and are reviewed by a human. Private, reserved and government address space is rejected at intake. An unverified target cannot be scanned, and that rule is enforced in the database rather than in the interface.

06Can Decima test AI agents and LLM applications?+

Yes, and it is our specialism. We assess prompt injection, tool-permission escalation, memory poisoning and agent-to-agent trust abuse against the OWASP LLM Top 10 and our own field research. Our founder wrote the book on the subject. Research cited on this site found that 88 percent of enterprises experienced an AI agent security incident in the twelve months to February 2026, while only 6 percent had deployed advanced defences.

07Will this satisfy SOC 2, PCI DSS or HIPAA requirements?+

Yes. Continuous adversary emulation covers the penetration testing requirement in SOC 2 Type II, PCI DSS 4.0 requirement 11.4 and the HIPAA Security Rule evaluation standard, and continuous evidence is generally stronger than an annual snapshot in front of an auditor. We provide attestation letters and the full evidence chain as standard.

08What does it cost and how quickly can we start?+

Recon starts at 299 dollars per month for continuous external attack surface coverage on up to three verified targets. Adversary is 1,499 dollars per month for the full autonomous harness on up to fifteen targets. Sovereign is a bespoke annual engagement deployed inside your perimeter. Sign up, verify a target with a DNS record, sign the rules of engagement, and the harness starts the same afternoon.

Next

See yourselffrom the other side.

Verify one domain. See the first pass. Decide afterwards whether you want the standing adversary. No sales call required to start.