Platform Platform
System
ConceptsEnginePolicy as codeDeclarationsSafe changeGatewaysIntegrationsObservabilityAdministrationSecurityHuman reviewAudit and evidenceData retentionSecrets and data classification
Controls
Registries and documentationAuthentication and authorizationInjection detectionData redactionCode fingerprintingRole and judge checksContent classificationSpend and loop limitsBusiness rules
Solutions Solutions
By what you do
Sell into the enterpriseControl the AI you run
By industry
Financial servicesDigital assetsInsuranceHealthcareLegalUser-generated content
By discipline
AI governanceTrust and safetyRisk and compliance
Cases Cases Embedded control planeSource-code leakTrading agents over MCPLive firehoseRefund assistant
Compare Compare LiteLLMNVIDIA NeMo GuardrailsOPAROOSTAgent Governance Toolkit
Resources Resources
Guides
Enterprise review questionsPrompt injectionAgent and control layerAgent architecturesDecision system mapAI control maturity model
Standards
Standards OWASP Agent Control StandardEU AI ActPMI AI standardNIST AI RMFERC-8004
Book a demo
Solutions · By industry

On-chain, the mistake is final.

No chargeback, no reversal, nobody to call. A control that runs after the transfer is a report. Digital assets and crypto get the widest pack we ship: the eight rule areas below.

What is in the pack

RuleWhat it stops
Sanctions screeninga transfer to a listed address, against the lists you subscribe to
KYC tiersa wallet doing more than its verification level allows
Daily volume caps and cooldowna wallet drained by many small transfers, each under the single-transfer limit, with a 24-hour cooldown after a breach
First-time destinationthe first send to an address nobody has seen, held for review
New-wallet draina freshly created wallet emptying itself
Bridge whitelist and token securityfunds leaving through a bridge you never approved
Geo restrictionactivity from a jurisdiction you do not serve
Recoverythe flow attackers actually target, because it is designed to work when the user has lost everything

These are declarations you read and edit. Change a tier limit and it goes through candidate, backtest and promote like any other rule.

When an agent is the one signing

The signed transaction reaches your node through a gateway. It decodes the asset, the recipient and the amount out of the signed bytes and decides before the transaction reaches the network. Your signing key stays where you keep it.

An agent moves faster than a person, acts on text it read somewhere, and will repeat the same wrong thing until something stops it. Two controls matter more than the rest.

Authorization, including the case where each action is permitted and the sequence is not. And a counter with a stop, because the loop is what turns one bad decision into an incident.

The instruction can also arrive inside the data. Injection detection reads what came in and what a tool sent back, because a tool's answer can carry an instruction of its own.

This one has been done

Sanctions and KYC screening, transaction caps with state, human review and the audit trail have run embedded in another product, under that product's brand, on its own infrastructure: the case.

Related: AI governance · Risk and compliance
Book a demo