Two agents at a gate. One, drawn in red and hunched mid-step, is stopped on the near side. The other, upright and calm, has been let through.
Runtime trust for AI agents

AI agents can spend your money. We check every move.

Your agents act on your behalf now, and other people's agents are arriving at your door. Nothing you run today tells you which of them are legitimate, whether one went further than it was allowed, or why you said yes. That's the part we do.

Built by the founders of InAuth, acquired by American Express.

Start where you sit.

Two agents at a gate. One, drawn in red and hunched mid-step, is stopped on the near side. The other, upright and calm, has been let through.

Two agents walk up to the same door.

They arrive the same way and they look the same at the door. One is a legitimate agent doing a job someone asked for. The other is scripted abuse wearing the same clothes. Nothing about the request tells you which is which.

So we check. Any credential, from any issuer. When an agent presents none at all, we bind it to something about the connection it can't quietly reset, so velocity limits and reputation finally have something to hold. What can't be identified at all doesn't get through.

That's the first question, and it comes before every other one. We don't own your agents, and we don't take the decision off you. We tell you which is which, and we keep the record.

Every decision comes with a receipt.

Not another dashboard to check. A plain account of what an agent did, what it was allowed to do, and why the answer was yes. It stays with you, and anyone can verify it without coming through us.

Decision record✓ Allowed
Who acted
Accounts payable agentIdentity confirmed at the moment it acted
What it was allowed to do
Up to $2,500, approved vendors onlyPermission expires after 24 hours
What it actually did
Paid $1,840 to Vendor #4471
Why we said yes
Inside every limit the human setSigned and sealed. Your auditor can check it without us.

Four questions, every time an agent acts.

1

Is it really you?

Confirm the agent is the one it claims to be, on every single action, not just at login.

2

Who said you could?

Tie the action back to a permission a real person actually gave, in writing.

3

Is this inside the lines?

Yes, check with a human first, or no. The same answer every time. No guesswork.

4

Can we prove it later?

Keep a record you can hand to a regulator, an auditor, or a partner. Years from now.

We're not replacing your fraud engine. We hand it one thing it doesn't have today: whether the agent stayed inside the boundaries a human set. You still make the call.

Someone asked for a trip to France. The agent took out a second mortgage.

A person approves one thing. The agent quietly breaks it into dozens of steps, and nobody signed off on any of them individually. That gap is the whole problem.

The goal splits apart. A single instruction becomes dozens of separate actions. No human ever saw most of them.

Knowing who it is isn't enough. We weigh what the agent actually did against what it was permitted to do, not just whether we recognise it.

Every answer is explained. Every yes and every no comes with a reason in writing, tied to the exact permission it relates to.

The 100-second version.

Why agents changed the risk model, and how BladeRun checks, decides, and proves what every agent does.

What could unwatched agents cost you?

Nobody has good loss data on agent traffic yet. That's exactly the problem. Move the sliders to your own assumptions, and we'll pressure-test them with you.

10,000,000
$120
5%
Small today. Growing quickly.
1.5%
Agent traffic runs hotter than human traffic, and nobody wrote down what it was allowed to do.
Payments started by agents
$60M
a year, using your numbers
What's exposed
$900K
a year, at the loss rate you picked

We go after the slice caused by agents overstepping, stacking up small actions, or pretending to be something they're not, with a written reason behind every decision.

An illustration built from your inputs and public benchmarks (Visa, 2025). Not a quote. We check it against your real data on the call.

Real attacks. What we do about each one.

Hidden instructions on a webpage

An agent reading the web picked up instructions buried in a page, and went off to send a wire.

We flag content that tries to override an agent's instructions, and its spending limit caps how far it can get.

Best effort, plus a hard limit

A payment agent pushed off course

A tampered-with tool nudged a payment agent into transfers that looked nothing like its normal behaviour.

Its permission and its usual pattern both say no, and we can cut it off in milliseconds.

Outside its permission, refused

A lookalike service in the middle

A copycat service with a near-identical name quietly forwarded an agent's outgoing email for weeks.

Agents only reach services you've registered. Anything else, or anything that has been altered, is refused.

Unregistered service, refused

We're straight about what's a guarantee and what isn't. Hard limits always hold. Spotting malicious content is best effort, and we label which is which on every single one.

Runs inside your walls. Never in the way of a payment.

An agent acts

Yours, a partner's, or one arriving at checkout

Your app or gateway

Wherever it already lands today

BladeRun checks it

In your own environment

The action goes through

Pay, call an API, move data

An answer for your fraud team

Feeds the system you already trust

A record for your files

Signed, and yours to keep

A checkpoint on the agent's action, running in your environment and off the payment path. Nothing to rip out and replace.

Your walls

Stays in your environment

Run it yourself, or in our cloud. Agent traffic and records never have to leave.

Speed

Won't slow you down

It sits off the payment path. It informs your decision rather than standing in front of it.

If something breaks

Fails the way you choose

Keep going, or stop cold. You set it per policy. Your service levels, your call.

New to all of this?

What AI agents actually are, why they're a risk worth taking seriously, and how to keep them in bounds. In plain English, no background needed.

Start with Agents 101

The agents are already running.

The only question is whether you could prove they stayed in bounds. Start with one boundary, watching only, with nothing at risk.