The two questions

Did it overstep? Can you prove why?

Agents are initiating payments now. Your engine scores the device and the behavior, but it can't tell you whether the agent did more than the human authorized, or produce a record of why you allowed it. That's the verdict BladeRun feeds you.

01

Did it overstep?

Cap, payee, purpose, expiry, aggregation, did the agent exceed what the human actually authorized?

02

Can you prove why?

A signed, replayable record of the mandate and the verdict, attached to the decision your engine already makes.

The primitive

One bound, scoped session per agent.

01

Verify

Any issuer, or fingerprint when none.

02

Bind

To the mandate the human authorized.

03

Enforce

Deterministic allow, step-up, or block.

04

Prove

Signed, replayable, under your keys.

Verifier, not issuer. A decision input that feeds your engine. It doesn't replace it.

How it plugs into your stack

One inline call, before your engine scores.

One S2S call

Inline at authorization

Your decision engine calls BladeRun before it scores, a deterministic verified-agent verdict, inline at authorization.

Next to your signals

You keep the decision

The agent verdict sits alongside your device and behavioral signals. You keep the decision.

Nothing routed through us

An input, not a proxy

No traffic redirected, no re-platform. An input to your score, not a proxy in front of your traffic.

An input to your score, not a proxy. The inline gateway exists only when you want self-hosted enforcement.

Neutral by design

The one signal a single rail can't neutrally produce.

Across every rail

Or none at all

Any card network, open banking, or none (fingerprint). We verify what a single rail can't neutrally verify.

Complements the networks' agent protocols

The overstep verdict

The card networks authenticate the agents routed on their own rails. We add the overstep verdict and evidence, across the whole estate.

Evidence you control

Under your keys

Signed, replayable, under your keys, not on a public chain.

Questions risk teams ask

Additive, not a competitor. Here's the proof.

Do you compete with our decisioning platform?
No, and we are built not to. We produce a signal you cannot: the verified-agent overstep verdict plus signed mandate evidence. You keep the decision. We make your engine agent-aware.
Is our traffic routed through you?
No. One inline server-to-server call before you score. Nothing redirected, no re-platform, no proxy in front of your traffic.
What is the latency?
Single-digit milliseconds inline. The behavioral scoring runs alongside, off the path, and never gates your decision.
What new signal do we actually get?
The runtime agent context your models never had: the mandate (cap, payee, purpose, expiry), aggregation across calls, the prompt origin, the tool call, all normalized into one verdict you can weight like any other feature.
Do you work across every rail, or only one?
Across every card network and open banking, or a fingerprint when no credential is presented. Neutral by design, which is exactly the signal a single rail cannot produce for you.
Do you replace our models?
No. The verdict sits next to your device and behavioral signals. Your models keep scoring and you keep ownership of the decision.
Can we offer this to the merchants and issuers we serve?
Yes. It is a decision input you can surface through your own platform. Talk to us about the channel.
A technical pilot

One decision element. One pilot.

01

Working session

One hour. Map where agent traffic already hits, and where we plug in. No commitment.

02

Signal pilot

Light up agent-trust on the existing path for a set of boundaries. Measure lift and latency.

03

Decision element

Score the verified-agent verdict inline and attach the signed record.

The agent verdict your engine is missing.

Neutral across every rail. You keep the decision.