Every payment crosses seven decision gates.
The Decision Trust Protocol screens each agent payment in the authorization window: seven decision gates and two system steps, resolved in 23 milliseconds, on the rails you already run. Decisions are APPROVE, DECLINE, or STEP_UP, and every one is advisory: your engine keeps final authority.
Because the window is the only place prevention exists.
Everything after authorization is recovery: chargebacks, clawbacks, write-offs. Years of operating card programs taught us that the milliseconds of the authorization window are where a loss is prevented or accepted. So that is where we built.
The second reason is what the research says about defending agents. Detectors that read a hijacked agent's text get bypassed by whoever moves second; deterministic constraints on the action hold. The pipeline never trusts what an agent believes. It checks what the agent is allowed to do, and the public benchmark shows the difference: 75.0% attack success undefended, 1.4% behind the mandate stack.
Seven decision gates. Two system steps.
Card and x402. One trust engine.
On the card rail, decisions travel as advisory risk data in ISO 8583 authorization fields. On the x402 rail, approvals bind a signed attestation to one exact USDC transfer on Base. Same gates, same mandates; the rail only changes the evidence.
Prevention in the window, not detection after it.
Inside the window or pre-presentment.
Issuers consult the protocol during decisioning; agent platforms call it before a transaction exists. Both get the same enriched, advisory decision.