Humanbound is an open-source adversarial testing engine, SDK and CLI for AI agents, with an optional hosted platform. It connects to a live agent endpoint, extracts or accepts a declared scope, and drives multi-turn adversarial and behavioural conversations against the running agent. Attack scenarios cover prompt injection, goal hijack, jailbreaks, tool misuse, scope violation and data exfiltration, in single-turn, multi-turn and agentic modes, with score-guided refinement that adapts strategies across a campaign. Responses are evaluated by LLM-as-a-Judge against the user’s declared security policy and returned as deduplicated findings with an open, stale, fixed and regressed lifecycle, plus a 0 to 100 posture score. Failing test cases can be exported as guardrail rules and enforced at runtime by the Humanbound Firewall, a multi-tier filter that runs local checks first and calls an LLM judge only when the local tiers are uncertain. A continuous assurance engine cycles through scan, assess, investigate and monitor on a schedule, using coverage tracking and statistical drift detection to decide what to test next. Runs locally with no account, in CI via a pytest plugin and GitHub Actions, or against the hosted platform. Findings export to SIEM. Apache 2.0.