Agentic fraud prevention · API v0.7

The fraud intelligence layer for agent payments.

We exist to know agentic fraud better than the fraudsters do. AI agents have already made 165 million payments over the x402 protocol alone, by Coinbase's count. Watch the protocol decide four real requests.

Authorization pipeline0 ms
Agent Resolve1.2ms
Intent Verification3.8ms
Anomaly Gate (EDQS)7.2ms
Mandate Enforcement9.6ms
Behavioral Overlay12.4ms
Risk Scoring16.1ms
KYA Decision19.5ms
EVALUATING…
23 ms P50 decision 75.0% → 1.4% attack success, public benchmark 2 production card programs live 3 published papers 99.95% availability SLA
Mission

Everyone is building agentic payments. Someone has to keep them safe.

Every agent payment crosses rails built for human decisions. Mandate screens the decision itself, in the authorization window, on the rails you already run, and feeds every outcome back as labeled learning.
The enemy

Agent fraud is not human fraud with better grammar.

Fraud platforms now sell AI agents that work your alert queue. We do the other thing: police the agents doing the paying, at the moment they pay.

Prompt injection

A hijacked agent believes the attacker. It still can't act outside its mandate.

Reasoning collapse

Degrading agents derail before they overspend. EDQS sees the drift first.

Collusion rings

Cross-agent correlation catches coordinated patterns no single account shows.

Trust bust-out

Score farming meets asymmetric demotion: slow to earn, fast to lose.

Coverage

Every typology dies at a named gate.

TypologyCaught atThe tell
Prompt injectionGate 2 · Intent VerificationStated intent diverges from the principal's own task.
Reasoning collapseGate 3 · Anomaly Gate (EDQS)Reasoning length and confidence drift from the agent's baseline.
Transaction decompositionGate 4 · Mandate EnforcementCumulative caps and amount-distribution telemetry flag structuring.
Credential replayGate 5 · Behavioral OverlayAuthenticated requests that do not behave like the bound agent.
Trust bust-outGate 7 · KYA DecisionPromotion velocity is itself a monitored signal.
Collusion ringsStep S2 · Cross-agent correlationShared counterparties and synchronized timing across agents.
The instruments

Attestation, tested against behavior.

Divergence detection

stated intent vs observed behavior · EDQS v2.1
DIVERGENCE FLAG · GATE 3 attested (what the agent says) observed (what it does)

KYA Score under attack

trust zones tighten limits as behavior degrades
KYA 0.94 · ZONE GREEN · limit multiplier 1.0×

A compromised agent does not lose authority all at once. It loses it in steps: limits tighten at 0.70, halve at 0.40, and sessions terminate below 0.20. Demotion is fast; re-earning is slow.

The console

Fraud analytics your risk team can act on.

Every decision fully explainable: which gates fired, the KYA score at decision time, what the behavioral trust state was at the moment of decision, and the agent's attested intent. The full back office lives on the platform page.

Fraud analytics with live threat level and a possible agent-compromise alert
dashboard.mandatelabs.ai · demo environment
The rails are inputs, not competitors: x402 Google AP2 Visa TAP Mastercard Agentic Tokens ISO 8583 / ISO 20022 3-D Secure 2.0 Verifiable Intent v0.1 aligned SOC 2 Type II in progress
Research

The science behind the gates.

Every scoring model, behavioral metric, and trust threshold is grounded in published research. We publish openly, because the frameworks need scrutiny to become standards.

The rails are being built. We keep what moves on them safe.

30 minutes with the founding team: the authorization pipeline, the back office, and KYA scoring on live requests.