Validation of agents for use by third parties

Hey - new to this group. Wondering if other builders of agents that are to be used by third parties have issues with them not being verified that they were built by a bonefide company or can show that they were built in line with specific security requirements? Keen to hear how people are working around this?