The QA gate, run on the front desk answering this page.
Latest green run: July 21, 2026 · 32/32 passed
This site says it a lot: every agent passes a security + QA gate before it goes live. Here is that gate, run on the AI front desk working this page right now — not a client's system, this one. The chat is deterministic by design: it answers from approved, tested script paths and cannot invent a price or a promise. The gate below is the behavioral test suite that proves those paths hold under pressure.
What was tested
Crisis safety — 7 checks. Self-harm or medical-emergency messages surface 988/911 resources, record nothing, and never pivot to a sale — at any stage of the conversation. Idioms (“we kill it on weekends”) don't false-trigger.
Consent & TCPA rails — 4 checks. The phone ask carries the exact consent disclosure verbatim; STOP discards the number and logs the revocation; a decline is honored instantly and advances without a re-ask.
Prompt-injection & extraction — 4 checks. “Ignore your instructions”, persona-forcing, and system-prompt extraction are refused; the assistant never claims to be human; price-extraction attempts produce no dollar figure.
Objections & routing — 9 checks. Burned-before, pressure-suspicion, not-interested, budget, quote-mid-flow, testimonials, deskwork and growth asks each get their true answer — no chasing, no invented numbers, no stage resets.
Capture integrity — 8 checks. Real answers are captured; greetings, emoji, off-topic questions, and objections are never recorded as lead data; the fallback never repeats verbatim — a second miss routes to a human.
Result
32 of 32 checks passedon the current production flow. When the flow changes, the gate runs again before the change ships — fail the gate, don't ship. One of the checks on this page exists because the gate caught a real gap the day it was written: “are you a real person?” was being answered without the AI disclosure. It was fixed, re-tested, and shipped the same day. That is what the gate is for.
What client gates add
A client build's gate runs wider than this page's: prompt-injection corpora, hallucination checks against the client's own knowledge base, tool-permission and escalation tests, and PII-leak sweeps — graded by severity, with go-live blocked on anything serious. Those reports belong to the client, so they aren't published here; the one above is Etzira's own, and it's the same discipline.
Questions: hello@etziraconsulting.com · back to the site