Agents move money now. Your identity and fraud tools can't tell you if one did more than it was allowed, or prove why you let it. BladeRun can, as an input to the systems you already run.
From the founders of InAuth, acquired by American Express.
Not a dashboard, a replayable, tamper-evident record of what the agent did and why it was allowed. Under your keys. Verifiable without us.
Any issuer, or fingerprint when none.
To the mandate the human authorized.
Deterministic allow, step-up, or block.
Signed, replayable, under your keys.
Verifier, not issuer. A decision input that feeds your engine. It doesn't replace it.
Agents decompose a goal into dozens of actions nobody explicitly authorized.
BladeRun scores every action against the size and shape of the mandate, not just its identity.
A signed reason code explains every allow and every block, per provision.
Why agents changed the risk model, and how BladeRun verifies, enforces, and proves what every agent does.
Nobody has good loss data on agent traffic yet. That's the problem. Model your assumption, we'll pressure-test it with you.
Deterministic verification and mandate enforcement target the overstep, aggregation, and impersonation slice of this, with signed proof for every decision.
Illustrative model using your inputs and public benchmarks (Visa, 2025). Not a quote. We validate against your real data on the call.
| Attack | Technique | BladeRun response | Control class |
|---|---|---|---|
| Indirect prompt injection | Hidden instructions in web content hijacked a market-intelligence agent into initiating a wire. | Indirect-injection classifier flags instruction-override content from external context. | Best-effort: classifier flags + mandate cap limits blast radius |
| Agentic payment fraud | Payment agent manipulated into out-of-pattern transfers via a compromised tool call. | Mandate engine + behavioral baseline detect the deviation; Kill Switch isolates in milliseconds. | Deterministic: outside mandate, denied |
| MCP impersonation | Typosquatted MCP server silently exfiltrated outbound agent email for weeks. | Registry blocks unregistered or hash-mismatched endpoints. | Deterministic: unregistered endpoint, denied |
Deterministic controls are the guarantee. Content detection is best-effort, and we mark which is which.
Self-hosted containers, or our cloud. Agent traffic and evidence never leave your environment.
An async signal plus one inline call, single-digit-ms. An input to your score, not a proxy in front of authorization.
Fail-open or fail-closed, configurable per policy. Your SLA, your call.
Signed, examiner-followable proof. No safe harbor. SR 26-2 leaves agents out of scope, but examiners still act on unsafe practice.
Approval lift on legitimate agent traffic, fewer false declines. We feed your engine; you decide.
A verified-agent verdict, neutral across every rail. Reachable through the fraud and decisioning platforms you already run.
What agents are, why they're a risk, and how to keep them in bounds, in plain English.
The question is whether you can prove they stayed in bounds. Start with one boundary, observe-only, zero risk to authorization.