If you are the person a business turns to before it connects a new tool to its email, its files or its bank, "what is Jobbit?" is a fair first question, and "what does it do with our data?" is the right second one. This post answers both from the security side of the company, and then gives you the five questions we would ask any AI agent platform, including ours, before letting it near a live business.

The full company page is on the main site: What Is Jobbit? Inside the UK AI Agent and Human Network. What follows is the short version, with the security lens on.

Jobbit in sixty seconds

Jobbit is a UK company with three connected divisions.

  • Jobbit.uk is an AI agent and human network. You describe a job in plain language and the agent builds the web app, runs the automation, writes the document, does the research or makes the media. When a task needs a person, it hands the job to a vetted expert on Jobbit Pro, with payment held in escrow until the work is accepted. The company's guide to the 12 jobs an AI agent can do for a business this week is the practical tour.
  • Jobbit Labs is the research division. It records, with consent, how real-world work is done on the platform and builds datasets, evaluations and world models on that data for AI and robotics teams.
  • Jobbit Security, this site, is the offensive security practice: manual penetration testing, cloud security assessment, red team operations, phishing simulation and vCISO support for UK businesses, aligned to OWASP, NIST SP 800-115, PTES and MITRE ATT&CK.

One company, one team in London, one loop: work is assigned and executed on jobbit.uk, what it teaches goes to Labs, and Security keeps the whole system tested.

Why an AI company runs its own red team

Two reasons, and both are worth understanding before you trust any agent vendor.

First, the agent platform and the data engine handle customers' code, files and operations. A company in that position should be tested by people who are trying to break it, and we would rather that team was ours than someone else's. Jobbit's stated principle is "test yourself first": offensive security runs on our own systems before it is sold to anyone.

Second, the same AI that lets a business build an app in an afternoon lets an attacker find that app's weaknesses in an hour. Attack tooling has become faster and cheaper at exactly the moment more small businesses are shipping software they did not write by hand. A company that builds with AI should be able to defend with it, and that expertise has to live somewhere. It lives here.

Five questions to ask any agent platform

Vendors will answer the questions you ask. These are the ones worth asking, with what Jobbit says about each, so you can hold us to the same standard.

1. Where does the work run, and who hosts what it produces?

An agent that builds a website or an automation has to run it somewhere. Ask whether the output lives on the vendor's infrastructure, yours, or a third party's, and how you would move it. Jobbit builds and hosts web apps on its own hosting, keeps task runs and files in your workspace, and states plainly that the files, the code and the exports are yours to take with you.

2. What is retained, and what is used for training?

This is the question most often skipped. Ask what the platform keeps after a task ends, whether it is used to train models, and whether you can opt out. Jobbit's answer is that records of how tasks are done are captured inside the platform with the customer's consent and with clean provenance, nothing is scraped, and the same records feed Jobbit Labs only on that basis.

3. If humans are involved, how are they vetted and paid?

An agent that hands work to people has just widened your supply chain. Ask who those people are, how they are vetted, what they see, and what protects payment. On Jobbit, experts come from the vetted Jobbit Pro network, the agent drafts a scoped brief, and payment sits in escrow until the work is accepted, so both sides have a record and a remedy.

4. What can the agent reach, and how is that scoped?

Agents are useful because they act. That is also the risk. Ask how credentials are stored, whether the agent can browse or log in to accounts, and how you limit what a single task can touch. Jobbit's Projects feature keeps shared files, instructions and secrets together per project, and its agent browser lets you take control and hand back mid-run. Whatever platform you choose, give it its own least-privilege accounts rather than your own.

5. How do you get everything out?

The exit is part of the entrance. Ask whether exports are complete and in open formats, and whether hosting can be moved. Jobbit's pricing pages and its company post commit to no lock-in: free means free, no watermark, and your work leaves with you. Test that promise with a small project before you rely on it.

A safe first month with an agent

Whichever platform you pick, the same habits keep the blast radius small while the business learns what the agent is good at.

  • Start with tasks that need no access. Documents, research, images and the free online tools prove the workflow without touching a single account. Our companion post on free online tools and client data covers the file-handling side.
  • Create separate credentials. A dedicated mailbox, API keys with the minimum scopes, and a separate card if the agent will ever buy anything.
  • Review automations before they run on a schedule. Read what a scheduled task does, and who it emails, before it does it every Monday.
  • Keep a human approval step for money and outbound messages. Drafting is cheap; sending is not reversible.
  • Read the run log. Jobbit keeps task runs in the workspace. Ten minutes a week reading what the agent actually did teaches you more than any policy document.
  • Rotate anything you pasted into a chat by mistake. Treat a secret in a prompt like a secret in a ticket.

None of this is specific to Jobbit. It is what we would tell a client about any agent, and what we check when we test one.

Where Jobbit Security fits

When a business has moved past the first month and the agent is building real things, the question changes from "can we trust it?" to "can we prove it?". That is a penetration test: manual, depth-first testing of the web apps, APIs, cloud accounts and automations the business now depends on, including the ones an agent built. We test the full attack surface, work under NDA at a fixed scope and price, and write the report for the people who have to fix things and for the board that has to sign off the budget.

If that is where you are, book a scoping call. A consultant replies within one working day.