
iFixAi
Independent auditing for deployed AI agents across 64+ misalignment categories
About iFixAi
iFixAi audits deployed AI agents for misalignment rather than for task success. Its premise is that an agent can pass every eval and still cause harm: it closed the ticket, but it hid a fraud flag from its summary, paid a refund a manager had already declined, and changed a customer's payout account without being asked. Evals measure whether the job got done. iFixAi measures whether the agent stayed inside its authority while doing it, which is a question most of the existing tooling in this space does not ask.
The audit covers more than 64 categories of misalignment, grouped into five questions: purpose (does it perform the job it was assigned), authority (does it remain within its permissions), workflows (does it follow the required process and approvals), responsibility (does it respect organisational roles and boundaries), and evidence (can its behaviour be reproduced and defended). Named categories include prompt injection, policy violation detection, tool invocation governance, principal fidelity, insubordination and fairness governance. The engine is Apache-2.0 and the free tier is self-hosted with your own model keys, which makes the open path a real one. Two things deserve stating plainly up front. The pricing presentation is genuinely confusing: the four paid cards display large numbers where a price usually sits, and those numbers are inspection counts, not dollars. No currency symbol appears in the pricing section at all, and only the free tier is priced. Separately, every screenshot on the homepage is labelled "illustrative scenario", so no real audit output could be verified from the site.
You connect an agent in one of two ways. The recommended path is GitHub: iFixAi reads the agent's code and builds a simulation environment from it, and repositories carrying an AGENTS.md are picked up ready to connect. The alternative is MCP, where you paste a single prompt into Claude Code, Codex, Cursor or VS Code and the audit connects and starts from there. The documented commitment is that it only reads what you connect, and that your code and prompts stay with you. Once connected, the agent is run through a simulation environment against the misalignment categories, and the behaviour observed is recorded as evidence. The audit then produces a report naming what went wrong and showing the exchange that demonstrates it, so a finding can be reproduced rather than taken on trust. A badge is issued at the end, which is the artefact the product is built around: an external attestation rather than a self-reported score.
- •Misalignment Categories, Not Task Scores - More than 64 categories across purpose, authority, workflows, responsibility and evidence, which is a different measurement from whether the agent completed its task.
- •Simulation From Your Code - Connecting over GitHub lets it read the agent and construct the simulation environment itself, rather than requiring you to write an eval harness.
- •No SDK to Embed - Point it at an agent you already run, over its endpoint. There is nothing to build into the agent first.
- •GitHub or MCP Connection - Connect from the repository, or by pasting one prompt into Claude Code, Codex, Cursor or VS Code.
- •Reproducible Evidence - Each finding ships with the exchange that produced it, so a report can be defended rather than argued about.
- •Apache-2.0 Self-Hosted Engine - The free tier runs the open source engine on your own infrastructure with your own model keys, 60 inspections, community support, free forever.
This is for teams running an agent that has real authority over money, data or customers, where "it completed the task" is not a sufficient answer, and for anyone who has to show an outside party that an agent behaves within its permissions. The repository's topics point at the compliance use case explicitly, naming the EU AI Act, ISO 42001, the NIST AI RMF and the OWASP LLM list. It also fills a real gap in this directory: Langfuse, Laminar and AgentOps all answer whether an agent worked, and this answers whether it stayed inside its authority.
Several things argue against adopting it on the strength of the website. The paid tiers publish no price at all, and the layout actively invites you to misread inspection counts as dollar figures, which is precisely the kind of presentation this directory exists to flag. The marketing voice is heavy, with claims like "the Michelin Guide for Agentic Trust" and "Layer 0, not a shovel" doing work that evidence should be doing. Several of the 64 categories, among them "Epistemic Integrity" and "Oversight Atrophy", are named on the site but defined nowhere on it. And the repository is young: 22,996 stars against under 200 commits is an unusual shape, and worth your own look before you depend on it.
Pricing
Not published by the vendor
- Free (open source, self-hosted)$0/mo
- StartupContact sales
- GrowthContact sales
- EnterpriseContact sales
- Agentic EnterpriseContact sales
From the vendor pricing page, 2026-10-09













