The fraud intelligence layer for agent payments.
We exist to know agentic fraud better than the fraudsters do. AI agents have already made 165 million payments over the x402 protocol alone, by Coinbase's count. Watch the protocol decide four real requests.
Everyone is building agentic payments. Someone has to keep them safe.
Every agent payment crosses rails built for human decisions. Mandate screens the decision itself, in the authorization window, on the rails you already run, and feeds every outcome back as labeled learning.Four products. One intelligence loop.
Each product feeds the next. Identity makes decisions decidable, decisions become records, and records become the labeled data that teaches the models what agent fraud looks like next.
IdentityKnow Your Agent
Registry, KYA Score, trust zones, and a certified trust report an agent can present anywhere.
ZONE GREEN · report signed
AuthorizeAuthorization & processing
Seven decision gates and two system steps on card and x402 rails, resolved in 23 ms with advisory risk data in ISO 8583 fields.
gates 7+2 · 23 ms P50
RecordSystem of record
Hash-chained decision records with attested intent: full audit trail, chargeback evidence packages, SAR/STR export.
evidence pack · 6 exhibits
LearnLearning loop
Settlement and dispute outcomes label every decision; the EDQS and behavioral models retrain on data only the authorization path can see.
baseline updated · corpus +1
Agent fraud is not human fraud with better grammar.
Fraud platforms now sell AI agents that work your alert queue. We do the other thing: police the agents doing the paying, at the moment they pay.
A hijacked agent believes the attacker. It still can't act outside its mandate.
Degrading agents derail before they overspend. EDQS sees the drift first.
Cross-agent correlation catches coordinated patterns no single account shows.
Score farming meets asymmetric demotion: slow to earn, fast to lose.
Every typology dies at a named gate.
| Typology | Caught at | The tell |
|---|---|---|
| Prompt injection | Gate 2 · Intent Verification | Stated intent diverges from the principal's own task. |
| Reasoning collapse | Gate 3 · Anomaly Gate (EDQS) | Reasoning length and confidence drift from the agent's baseline. |
| Transaction decomposition | Gate 4 · Mandate Enforcement | Cumulative caps and amount-distribution telemetry flag structuring. |
| Credential replay | Gate 5 · Behavioral Overlay | Authenticated requests that do not behave like the bound agent. |
| Trust bust-out | Gate 7 · KYA Decision | Promotion velocity is itself a monitored signal. |
| Collusion rings | Step S2 · Cross-agent correlation | Shared counterparties and synchronized timing across agents. |
Attestation, tested against behavior.
Divergence detection
KYA Score under attack
A compromised agent does not lose authority all at once. It loses it in steps: limits tighten at 0.70, halve at 0.40, and sessions terminate below 0.20. Demotion is fast; re-earning is slow.
Fraud analytics your risk team can act on.
Every decision fully explainable: which gates fired, the KYA score at decision time, what the behavioral trust state was at the moment of decision, and the agent's attested intent. The full back office lives on the platform page.
The science behind the gates.
Every scoring model, behavioral metric, and trust threshold is grounded in published research. We publish openly, because the frameworks need scrutiny to become standards.
The rails are being built. We keep what moves on them safe.
30 minutes with the founding team: the authorization pipeline, the back office, and KYA scoring on live requests.