Runtime trust for AI agents

Did it overstep?
Can you prove why?

Agents move money now. Your identity and fraud tools can't tell you if one did more than it was allowed, or prove why you let it. BladeRun can, as an input to the systems you already run.

From the founders of InAuth, acquired by American Express.

Prove why you allowed it

Every decision leaves a signed record.

Not a dashboard, a replayable, tamper-evident record of what the agent did and why it was allowed. Under your keys. Verifiable without us.

Signed evidence recordunder your keys
agent    acct-agent · rfc9421-sig
mandate  cap $2,500 · payee allow-list · expiry 24h
action   transfer $1,840 → vendor#4471
verdict  ✓ ALLOWED, within mandate
signature ed25519:9f2c…e71a · verifiable offline
content digest sha256:9f2c…e71a
The primitive

One bound, scoped session per agent.

01

Verify

Any issuer, or fingerprint when none.

02

Bind

To the mandate the human authorized.

03

Enforce

Deterministic allow, step-up, or block.

04

Prove

Signed, replayable, under your keys.

Verifier, not issuer. A decision input that feeds your engine. It doesn't replace it.

AGENTS THAT ACT BLADERUN · THE TRUST LAYER SYSTEMS YOU ALREADY RUN Your internal agents Partner / third-party agents Agentic checkout (network rails) ONE BOUND, SCOPED SESSION Verify → Bind → Enforce → Prove ALLOW · STEP-UP · BLOCK in your environment · under your keys Fraud & decisioning Identity / issuers Payment networks Bank core / ledger the action verdict + evidence
We sit in the path of the agent's action, then feed a verdict and signed evidence into the systems you already run. A decision input, not a competing engine.
The moat

The request was "book a trip to France." The action was a second mortgage.

Decomposition

One goal, dozens of actions

Agents decompose a goal into dozens of actions nobody explicitly authorized.

Mandate shape

Size and shape, not identity

BladeRun scores every action against the size and shape of the mandate, not just its identity.

Reason codes

Every decision, explained

A signed reason code explains every allow and every block, per provision.

The overview

The 100-second version.

Why agents changed the risk model, and how BladeRun verifies, enforces, and proves what every agent does.

Quantify it

What could unmonitored agents cost you?

Nobody has good loss data on agent traffic yet. That's the problem. Model your assumption, we'll pressure-test it with you.

10,000,000
$120
5%
Small today, compounding fast.
1.5%
Agent traffic runs hotter than human. Unverified agents carry no logged intent.
Agent-initiated payment volume
$60M
per year, at your inputs
Estimated annual exposure at risk
$900K
per year, at your assumed loss rate

Deterministic verification and mandate enforcement target the overstep, aggregation, and impersonation slice of this, with signed proof for every decision.

Illustrative model using your inputs and public benchmarks (Visa, 2025). Not a quote. We validate against your real data on the call.

Coverage

Documented attacks. Here's the control that stops each one.

AttackTechniqueBladeRun responseControl class
Indirect prompt injectionHidden instructions in web content hijacked a market-intelligence agent into initiating a wire.Indirect-injection classifier flags instruction-override content from external context.Best-effort: classifier flags + mandate cap limits blast radius
Agentic payment fraudPayment agent manipulated into out-of-pattern transfers via a compromised tool call.Mandate engine + behavioral baseline detect the deviation; Kill Switch isolates in milliseconds.Deterministic: outside mandate, denied
MCP impersonationTyposquatted MCP server silently exfiltrated outbound agent email for weeks.Registry blocks unregistered or hash-mismatched endpoints.Deterministic: unregistered endpoint, denied

Deterministic controls are the guarantee. Content detection is best-effort, and we mark which is which.

Architecture

Runs in your environment. Out of the payment path.

Agent request an agent goes to act Your app / gateway where the action lands BladeRun checkpoint verify · bind · enforce Action pay · call API · move data Verdict → your fraud engine Signed evidence → your ledger SaaS or self-hosted · out of the payment path · under your keys · no rip-and-replace
A checkpoint on the agent's action, deployed in your environment, off the payment path. It emits a verdict to your fraud engine and signed evidence to your ledger.
Boundary

In your VPC

Self-hosted containers, or our cloud. Agent traffic and evidence never leave your environment.

Latency

Off the path

An async signal plus one inline call, single-digit-ms. An input to your score, not a proxy in front of authorization.

Failure

Fails your way

Fail-open or fail-closed, configurable per policy. Your SLA, your call.

Who it's for

Three roles in the agent transaction. One governance plane.

Banks

Govern the agents you run

Signed, examiner-followable proof. No safe harbor. SR 26-2 leaves agents out of scope, but examiners still act on unsafe practice.

Merchants

Keep the decision

Approval lift on legitimate agent traffic, fewer false declines. We feed your engine; you decide.

Networks & platforms

The input you don't build

A verified-agent verdict, neutral across every rail. Reachable through the fraud and decisioning platforms you already run.

New to AI agents?

Start with the basics.

What agents are, why they're a risk, and how to keep them in bounds, in plain English.

Read Agents 101 →

The agents are already running.

The question is whether you can prove they stayed in bounds. Start with one boundary, observe-only, zero risk to authorization.