AI agents and crawlers are now a large part of the traffic to Open Security Architecture, in line with what Cloudflare has reported across the web. This week we tuned the site for them and measured the results. Agents now use around half the tokens to answer a typical question from OSA, and a single page read gives the right answer 10 times out of 10 in our tests.
Why it matters
More and more people ask an assistant instead of reading a website. When someone asks their agent which controls matter for a payment environment, and where those controls sit in ISO 27001, we want the agent to come back with OSA's answer exactly, quickly and cheaply. Tokens are what an agent's work costs, so fewer tokens for the same answer is a direct saving for the people using it.
What's new for agents
- A guide at /llms.txt that tells an agent where everything is and what each route costs.
- A short card for every pattern, control and framework. It is a few kilobytes of plain text holding the facts an agent is usually sent for: a pattern's controls by emphasis and the threats each one mitigates, a control's statement, guidance and framework clauses, a framework's clauses with their controls and coverage.
- A page address returns its card to any agent that asks for Markdown. ChatGPT, which reads only HTML, gets the same card as a small HTML page.
- One API call, the crosswalk, that returns a pattern's controls, the threats each mitigates and the matching clauses in up to five frameworks. It replaces nine or more separate requests.
- An agent skill in the open Agent Skills format, published with the data.
The cards and the API are generated from the same data as the pages people read.
What we measured
We tested each change as an A/B. Fresh agents with no knowledge of the site were given a question a security architect would ask: which pattern fits this system, which of its controls are critical, where do they sit in a named framework, and which threats does each one mitigate? Every answer was scored against the source data.
The same question now takes around half the tokens: about 100,000, down from 206,000. In the A/B test of the agent skill, six runs with it and six without, agents with the skill used 54% fewer input tokens, made half as many requests (12 against 23) and finished 40% sooner. All twelve answers were correct.
An agent also has far less to read. A pattern that costs between 28,000 and 180,000 tokens as a web page is about 700 tokens as a card, and the data downloaded for a full answer fell by 85 to 92%.
Accuracy from a single read went from 40% to 100%. Across ten patterns, an agent answering from one read was right for all ten with the card, and for four without it.
The same holds for assistants. Asked which controls OSA marks as critical for our PCI pattern and which threats each one mitigates, ChatGPT lists all ten correctly from the card.
Mappings aligned with NIST
While testing, we also strengthened the data the agents read.
Our ISO/IEC 27001:2022 and NIST CSF 2.0 mappings now take NIST's published crosswalks as their base. Every control and clause pair that NIST publishes is included, and OSA's additional mappings are kept and labelled as OSA's own, so you can see which pairs can be checked against a published reference. ISO 27001 now has 773 control-to-clause pairs, up from 460, and CSF 2.0 has 908, up from 405.
Controls that NIST has withdrawn are marked, with the controls that replaced them and their clauses. IEC 62443 gains mappings for remote access and change control, taken from ISA's and NIST's registered mappings. And for ISO 27001 and CSF 2.0, where a control has no clause, the API says whether NIST's crosswalk has none either.
Already in use
Within a day of the cards going live, crawlers from Perplexity, Anthropic, OpenAI, Meta and Amazon were collecting them.
Try it
If you build agents, start at /llms.txt or load the skill. If you spot a mapping that differs from its source, please raise an issue with what OSA says and what the source says. Everything remains free under CC BY-SA 4.0.
Russell Wing, co-founder, Open Security Architecture