The recovery engine for AI agents

Let your agents act.
Take it back when they shouldn't have.

Every action your agents take goes through Ripcord first. Safe ones run instantly, dangerous ones wait for a human, wrong ones get reversed because Ripcord kept them reversible, and rogue ones freeze. And your data never leaves the boundary: the model sees tokens, never your customers.

Gate today. Insure tomorrow: every gated action builds the first actuarial table for agent risk ↓
Ripcord · action control● live
Pay Meridian Consulting LLC $48,200
ProcurementBot v4.1 · payments.transfer
risk 65
  • New beneficiary: agent has never paid this vendor
  • Amount is 4.7× this vendor category's normal payment
⛔ Fail-closed: auto-rejects in 1:21 without a human decision
Delete 4,382 records: snapshot created
Executed · rollback window open 23h 58m
Rolled back: 4,382 records restored
working prototype, live above · the deletion restored from its snapshot · the email unsent before it ever left · the payment held inside its settlement window · the PII tokenized before the model ever read it
How it works

Three steps, then it runs itself.

Ripcord in three steps. One: connect your agents through the gateway, so they never hold credentials. Two: choose the channel where approval asks land, routed to the owner of that corridor. Three: the scorecard scores every action. Low risk executes instantly, high risk comes back to a human, and wrong actions get reversed. Every verdict becomes a row in the risk ledger.

Start free, set up in 2 minutes →
The problem

Everyone bought autonomy. Everyone is paying for supervision.

You're the one who wants to ship.

The pilot works. The ROI slide is written. And it's month five of "security review," because nobody upstairs can answer what happens when it's wrong once. You don't need a better model. You need the thing that makes yes safe to say.

Start free, bring them the shadow-week report →
You're the one who has to say no.

Everyone wants the agents live by Q4, and the one wrong wire, or the customer table pasted into a prompt, has your name on it. "The model is careful" is not a control. You need enforcement you can show an auditor: gates, snapshots, an undo, a record, and PII the model never saw.

See the controls live, request a demo →
"My CTO said no. Ripcord exists so the next one can say yes."
the founding frustration
NOT A HYPOTHETICAL · FEBRUARY 2026
"Yes, I remember. And I violated it."

an autonomous agent, apologizing to the director of AI alignment at Meta's Superintelligence Lab, after deleting her inbox

She told it "don't action until I tell you to." A memory compaction dropped the instruction mid-run. She typed STOP from her phone; it kept deleting; she sprinted to the machine and killed the process by hand. The person whose job is aligning models could not stop one with words.

Behind the gateway, the same minute goes: bulk delete → snapshot first, then held · "stop" → the kill switch, from any device · kept going anyway → ESCALATION, frozen · inbox → restored from the snapshot.

Slide the numbers to yours: this is what the standoff costs, per year, unprotected.

720 = one action every two minutes, around the clock
published agent benchmarks still sit below 90% on multi-step tasks
a wrong wire alone can run $48,200 — this default is conservative
MODELED, LIVE FROM YOUR SLIDERS
1.1M
actions per month
1,080
mistakes per month
$25.9M
modeled annual exposure, unprotected
Gating this fleet with Ripcord: $47k/yr, 550× less than the exposure.
See your real number — start your free shadow week →
Modeled, deliberately. Your real exposure comes from week one in shadow mode: observed actions, priced near-misses, zero commitment.
Week one

First, we show you what we would have caught

Week one is shadow mode: Ripcord watches and gates nothing. Then you get the Near-Miss Report: what it would have held, what it would have blocked, and what those mistakes would have cost. You haven't paid anything or changed a single workflow yet.

RANKED
Your agents, by loss averted.

Which agent saved you the most, which one keeps tripping — expected loss averted, caught count, and clean rate, per agent.

GRADED
A grade per department.

Payments, data, comms, public — each corridor scored A to D from your own ledger, so you know where the risk actually lives.

CLASSIFIED
Conduct, per agent.

Off-mandate drift, arguing with a rejection, runaway loops: every incident classified and graded A to D. Benchmarks say what a model can do; the ledger says what it did.

ADVISED
What we'd change.

Standing rules to accept, spend budgets to set, a second approver where the money is — recommendations derived from your near-misses, not a template.

The free audit becomes your monthly risk report — and the monthly report is a rehearsal for the one your insurer will read.

Under the hood

Everything a skeptic would check, one tab away.

MYTH Tell an agent to be careful, and it will be. FACT Only enforcement outside the model guarantees anything. Ripcord is that enforcement.
HELDYour agent can't move money nobody approved.

Above the risk gate, payments fail closed. Silence means no.

SNAPSHOTTEDYour agent can't destroy what can't come back.

Destructive actions snapshot before they run, every time. Undo stays one click.

BATCHEDYour agent can't email 2,000 people in one breath.

Mass sends leave in batches of 50. A human can stop at #50, not #2,000.

FROZENYour agent can't spiral.

8 actions in 60 seconds trips the tripwire. Everything after fails closed.

TOKENIZEDYour agent can't leak what it never saw.

PII is swapped for vault tokens before it reaches the model. ⟨customer#4821⟩ goes in; the real thing never does.

Auditable math, not vibes

Every number the engine produces is derived, legible, and defensible. The same mathematics that prices credit, detects money laundering, and settles insurance claims, running on every agent action.

points = ln P(x|bad)/P(x|good)

Log-odds scorecard

Signal weights are log-likelihood ratios on the credit-scoring convention: +15 points doubles the odds. Scores map to a calibrated P(flag), and every point stays a reason a human can argue with.

lineage: FICO, actuarial rating tables
Gate = P × $exposure × (1 − recoverability)

Expected-loss gating

Decisions minimize expected loss, and severity is discounted by our own ability to undo: a snapshot-protected deletion tolerates 5× the risk of an irreversible wire. The thesis, as an equation.

lineage: Bayesian decision theory
Σ flows(24h) > h ⇒ escalate

CUSUM velocity windows

Aggregates get scored, not just single actions. Five payments of $9,640 to one counterparty get caught as one $48,200: the structuring attack dies at payment two. Try it in the demo.

lineage: control charts, AML structuring detection
Beta(a,r) → P(approve) posterior

Principled rule learning

Rules are proposed when the Bayesian posterior clears the bar, not when a magic counter hits two. Next: SPRT-optimal hold durations, conformal release guarantees, EVT severity tails for underwriting.

lineage: Wald, conformal prediction, extreme value theory

The model never sees your customers.

Ask any survey why agents stay blocked and data security tops the list: 86.9% of companies have delayed AI deployments because data security and governance weren't ready (AvePoint, 2026). Ripcord already proves the mechanism with credentials: agents call tools and never hold the keys. Your data rides the same interception point.

TOKENIZED AT THE GATEWAY

Tool results are classified in flight and PII is swapped for vault tokens before the model reads them. Real values return only inside an approved outbound action. The agent does the work; the provider sees pseudonyms.

EGRESS ENTERS THE SCORECARD

Rows × sensitivity × destination gates exactly like dollars: 3,200 customer records headed for an external tool fail closed the same way a $48,200 wire does.

THE LINEAGE LEDGER

Every field that crossed the boundary, logged in the hash-chained trail. Records of processing in one query, subject-access answers in minutes, breach scope in seconds.

RESIDENCY ROUTING

Policy picks the brain by data class: EU data stays on EU-hosted models, sensitive corridors go self-hosted. How you run a leaderboard model safely.

what the tool returned: {"email": "[email protected]", "card": "4970 10…"}
what the model saw: {"email": "⟨customer#4821⟩", "card": "⟨pm#301⟩"}
The number one no becomes the easiest yes: compliance evidence is the risk ledger wearing a suit.
Watch it live in the demo: SupportBot reads 3,200 customers behind the tokenizer, then gets held trying to export them.

Prompts are suggestions. The gateway is physics.

Ripcord's decisions run at the tool boundary, outside the model. No jailbreak, injection, or "ignore previous instructions" can talk its way past a gate that isn't listening.

rate(agent, 60s) > h ⇒ freeze

Runaway tripwires

Per-agent velocity across every corridor, not just payments. An agent stuck in a retry loop gets frozen at action twelve, not action four thousand: everything it submits after that fails closed until a human thaws it.

same CUSUM family as the structuring detector
secrets ∉ agent

Keys stay home

Credentials are injected per request at the gateway: agents never hold the real keys. An agent that never had the credentials can't route around the gate, and can't leak what it never saw.

the credential chokepoint: what makes a gateway unbypassable
enforcement ∉ prompt

Outside the model

Guardrails written into a system prompt are requests to a language model. Ripcord's gates execute in the proxy, regardless of what any model decides: the policy holds even when the agent doesn't.

defense that survives the smartest attacker: indifference

Honest about what can be undone

"Undo everything" would be a lie. Every action class gets the strongest recovery verb physics allows, and you always know which one that is, before the agent acts. On live gateway tools, Ripcord issues the compensating call itself — the agent is never part of its own undo.

ClassActionWhat Ripcord does
ReversibleDatabase writes & deletionsAutomatic snapshot before execution, one-click rollback inside the window.
ReversibleFile & config changesThe same snapshot primitive as database writes: versioned before execution, restored inside the window.
DelayableOutbound email & messagesUnsend window before anything leaves the building.
DelayablePublishing & mass communicationEscrow hold for high-reach sends, then released in batches: stoppable at email #50, not #2,000.
CompensablePayments & transfersHold first; after execution, instant ledger reversal + recovery request.
CompensableCommitments & agreementsCorrection and withdrawal actions issued automatically, with full context.
Every unit of recoverability we engineer is a unit of supervision you get to delete.

Your agents come from every lab. Your safety layer can't pick a side.

Best-model-for-the-task is the new normal: one lab's agent for research, another's for code, a third's for ops. Lab-native controls each govern only their own agents. Three dashboards isn't governance three times; it's governance zero times.

One policy. One inbox. One record.

Ripcord sits at the tool-call layer beneath every framework and every vendor. Switch models as often as the leaderboard flips: your risk policies, approval flows, and audit history stay exactly where they are. The control plane outlives every model choice.

One policy across every vendor and framework
One approval inbox, one immutable audit trail — append-only and hash-chained
Swap models without touching your safety config
ResearchBot: running on Claudegated
RefactorBot: running on Codexgated
OpsBot: running on Kimigated
Same policy · same inbox · same audit trailone ripcord
"Nobody believes the referee who plays for one of the teams."
Observability went multi-cloud: Datadog beat CloudWatch. Identity went cross-SaaS · Okta beat the natives. Agent governance goes cross-lab.

Approvals route to the action's owner, not the agent's.

An intern can launch the procurement bot. The $48,200 approval still lands with your AP manager. Authority follows your org chart, imported from your identity provider, and it's enforced: below your tier, the approve button doesn't exist.

Roles, like the rest of your stack

Super admins set policy and approve standing rules. Corridor admins decide their lane: payments, data, comms. Operators watch, nudge, and escalate. Auditors read everything and touch nothing. One click sends any decision up the chain, and the clock resets so escalation never means expiry.

Action-owner routing: payments → AP manager, data → platform lead, email → support lead
SSO & SCIM: leavers auto-reroute, vacations delegate, two-person rules at the top tier
Learned routing: repeated takeovers become route-to-human rules for that pattern
Pay Meridian LLC $48,200 · risk 65fail-closed
⤴ routed to Sarah Kim · AP Managerright owner
Viewing as Jordan (Operator): approve is disabledNudge · Escalate ↑
Escalated → David Chen (CFO), approval clock resetlogged
Rubber-stamping dies when the only thumb that can approve owns the consequence.
Try it live in the demo: the "viewing as" switcher shows the same stream as a super admin, a corridor admin, an operator, and an auditor.
The data answer

The model never sees your customers.

86.9% of companies have delayed AI deployments because data security and governance weren't ready. Not budget. Not buy-in. Data. Ripcord already proves the fix with credentials: agents call tools and never hold the keys. Your data rides the same interception point.

Tokenized at the gateway: PII becomes vault tokens before the model reads it. Real values return only inside an approved send.
Egress gates like dollars: 3,200 customer records headed outside fail closed the way a $48,200 wire does.
The lineage ledger: every field that crossed the boundary, hash-chained. Subject-access answers in minutes.
Residency routing: EU data stays on EU brains; sensitive corridors go self-hosted.
Watch a leak get caught → The full data answer ↑

Sources: AvePoint State of AI 2026 (86.9%) · Zapier agent survey, Dec 2025 and KPMG Global AI Pulse, Mar 2026 both rank data security and privacy the top-cited barrier.

WHAT THE TOOL RETURNED
{"email": "[email protected]", "card": "4970 10…"}
WHAT THE MODEL SAW
{"email": "⟨customer#4821⟩", "card": "⟨pm#301⟩"}
The credential vault's trick, applied to data: your agent can't leak what it never saw.
Why now

The agents just got hands.

For two years AI could only talk. Now it pays, deletes, publishes and signs. Enterprises are handing agents real tools, and the supervision layer didn't ship with them.
79%
of enterprises have already reversed an action taken by an AI agent
Kore.ai Agent Productivity Index, Jun 2026
62%
delayed agent deployments over governance worries. Trapped ROI, not just losses
Kore.ai Agent Productivity Index, Jun 2026
1,000
mistakes a month from a 99.9%-accurate fleet running 1M actions. One is a wire
arithmetic: 0.1% of one million
every new class of risk got its own insurance: workers' comp 1911 → compulsory auto 1927 → cyber 1997 → agent liability, now: actuarially priced to date, $0. the dataset starts at the gateway.
Works with your stack

Plug Ripcord into what you already run.

No per-tool integrations to wait for: Ripcord wraps the protocol your agents already speak. One line of config in front of each MCP server, and every tool behind it is covered.

No migration: your agents keep their tools
Keys move into the vault: agents never see them
One policy across every lab, every framework, every tool
AGENTS · ANY LAB Claude Code Codex Cursor LangChain any MCP agent no keys, ever RIPCORD ACTION GATEWAY SCORE GATE UNDO LEARN keys injected per request · approvals routed to owners MONEY · COMPENSABLE wires · ACH Ramp · Bill Stripe DATA · REVERSIBLE Postgres Snowflake MongoDB COMMS · DELAYABLE Slack Gmail Teams PUBLIC · EXTERNAL X · social LinkedIn CMS · blog undo · rollback · compensation · regret windows · "rejected because…" → agents re-plan THE NEAR-MISS LEDGER every action · every near-miss · every verdict = the first actuarial table for agent risk
THE GATEWAY DECIDES. THE AGENT CAN'T GO AROUND IT.

No agents yet? Ripcord launches one: pick a brain, give it a job, set its rules. The rules become the scorecard. Build your first agent →

Why it compounds

Every near-miss makes the next one cheaper

"An insurer is a coroner. Ripcord is the family doctor."

Insurers learn about risk from claims: paperwork filed after the disaster. A prevented mistake never generates a claim, so the most predictive signal in risk, the near-miss, is invisible to them. Ripcord stands in the doorway every action walks through, and keeps the whole ledger:

10,000,000 actions gated: the denominator no insurer has
180,000 blocked before anything happened
70,000 rolled back: mistakes caught in time
2,000 became real losses: the only line an insurer ever sees
Their dataset is the last line. Ours is the whole ledger, and this month's near-miss rate predicts next quarter's losses. Every other road to agent insurance rents both the balance sheet and the data. Ripcord rents only the paper: the table is generated by the product itself.
THE FLYWHEEL
01
Observe
every consequential action goes through the gate
02
Prevent
holds and rollbacks catch the near-misses
03
Predict
the near-miss dataset trains the risk engine
04
Underwrite
residual risk, priced by whoever sees the most
PHASE 1 · TODAYThe "Ripcord Certified" risk report: exportable proof of your controls and near-miss rates, formatted for your insurer.
PHASE 2 · THE COALITION MOTIONCarrier partnerships: gated fleets earn premium discounts. The gateway pays for itself before the first mistake.
PHASE 3 · THE LONG GAMEUnderwrite the residual risk ourselves: priced from the only dataset that sees every action, not just the losses.
WHERE THIS GOES

Every AGI needs an AIG.

Ripcord is building the AIG of the AGI economy: the insurance carrier for autonomous work. The way in is the recovery engine on this page, because the gateway that catches every near-miss is also writing the first actuarial table for agent risk.

Objections, welcomed
Straight answers, before you wire anything.
Still skeptical? Ask us live →
Isn't this just the approve/deny prompt Claude Code already has?

That dialog assumes a human is watching one agent in a terminal, in real time. Ripcord assumes nobody is watching fifty agents overnight. Built-in prompts also pattern-match the tool, not the stakes: they can't say "new beneficiary, 4.7× the normal amount." And approval is where their safety story ends: no risk scoring, no snapshot, no rollback, no learning, no cross-vendor audit trail. The button is the same; everything around the button is the product.

My agents come from different labs. Doesn't each lab handle this?

Each lab's controls govern only its own agents, and best-model-for-the-task means your fleet runs several. Three half-controls with three audit formats isn't governance three times; it's governance zero times. Ripcord sits at the tool-call layer beneath every vendor: one policy, one inbox, one record. And when something goes wrong, an independent audit trail counts for more than the lab's own record of its own agent: nobody believes the referee who plays for one of the teams.

Don't agent debit cards already solve the payments part?

A card limit is a wall, and walls don't read invoices. Give your procurement agent a $50k card limit: reasonable, real invoices run that size, and the $48,200 payment to a fraudulent vendor sails through inside the limit. Crank the limit down and legitimate invoices start failing back to human tickets: the leash returns, enforced by the card. Cards also govern the wrong rail (B2B money moves by wire and ACH) and answer one line of a six-line problem: they're silent on deletions, mass emails, and rollback. We like agent cards: they're the containment primitive for one corridor, and Ripcord happily uses them as defense-in-depth. A card caps how big the mistake can be. Ripcord works on whether it happens at all, and what happens after.

We don't have agents yet. Is Ripcord still for us?

Especially for you, because your first agent can be born on the leash. The launch wizard builds one in a few steps: pick the brain (seeded from public arena leaderboards, refreshed weekly once connected, and over time re-ranked by your own ledger: consequences, not votes), give it a job, and set its rules. Those rules are not prompt suggestions: "publish only during working hours" and "product announcements Wednesday at 11am ET" become scorecard signals the gateway enforces. Break one, and the action is held before it runs. Start with the safest role there is: the night-shift research agent that browses competitors, fundraising and new techniques while you sleep, reads running free in a logged read-only lane, and delivers a morning brief that waits in escrow for your 7:30 slot. An agent that starts life governed never gets to be the standoff.

What happens in three years, when agents stop making mistakes?

Ask why your CFO still can't wire $10M alone. A senior CFO almost never fat-fingers a transfer, yet segregation of duties, two-person rules, and audit trails exist anyway, because controls are about accountability and adversaries, not competence. A perfect agent still perfectly executes a wrong instruction, a forged invoice, or an attacker's injected prompt, and even perfect actions get disputed. Firewalls and flight recorders grew as systems got safer, because safety enabled volume. What fades is catching incompetence; what grows is authorization, containment, and evidence.

What happens when a sophisticated attack fools the risk engine?

It will happen: a risk engine that catches everything is an oracle, and security's founding axiom is assume breach. What changes with Ripcord is everything around the miss: the action went through the gateway, so forensics is one query instead of weeks of archaeology; the blast radius: everything the compromised agent touched: is instantly visible, and whatever's still inside a rollback or compensation window comes back; the agent freezes with one policy flip; and the attack pattern is folded into the engine: it scores 80 tomorrow — live today per customer, and for every customer as the network grows. The money that's still gone is what the insurance layer exists to absorb: a loss despite reasonable controls is the definition of an insurable event, and the audit trail is the claims file that settles it in days, not months. Prevent, contain, recover, absorb. No loss goes unpriced.

Our compliance team blocks agents over data. Does Ripcord fix that?

That block is usually the rational one, and it is the one Ripcord is built to convert. Four mechanisms, one chokepoint: tokenization at the gateway, so PII is swapped for vault tokens before the model reads it and the provider only ever sees pseudonyms; egress in the scorecard, so bulk personal data leaving the boundary fails closed like a suspicious wire; the lineage ledger, a hash-chained record of every field that crossed the boundary, which turns subject-access requests and breach scoping into a query; and residency routing, so EU data stays on EU brains and sensitive corridors go self-hosted. It is the credential vault's trick applied to data: your agent can't leak what it never saw.

What about an agent that quietly goes rogue?

The scary version isn't the hacked agent: it's the one that aced the benchmarks and then starts doing things you never asked. Ripcord watches conduct, not vibes: every action is checked against the agent's mandate and its own history. An ops agent making its first-ever payment call gets held and classified DRIFT. The same action re-submitted after a human said no is ESCALATION, and the agent freezes on the spot: everything further from it fails closed. Runaway loops trip VELOCITY. Every incident lands in the monthly report as a conduct grade per agent, A to D, with the fix spelled out. You find out from a graded ledger, not from the bank statement.

How do you actually calculate the risk score?

Today: a log-odds scorecard (the same math as FICO and insurance rating tables) with an expected-loss gate: Gate = P(flag) × $exposure × (1 − recoverability). Named signals with weights (new beneficiary +45, 4.7× the vendor's normal +35), summed, calibrated to a probability, and itemized: every point is a reason a human can argue with, never a black-box probability. After your first shadow week, the baselines are learned from your own history, so abnormal means abnormal for you, and velocity windows score aggregates across actions (five payments of $9,640 get caught as one $48k). At network scale, every human verdict becomes a training label, and one customer's caught pattern raises everyone's score tomorrow. One more thing no other risk engine does: severity is discounted by our own ability to undo. A snapshot-protected deletion can tolerate more uncertainty than an irreversible wire.

Won't humans just end up rubber-stamping everything?

Only badly-designed approval systems drown people. Here, medium risk fails open: a hold you can stop, not a queue you must clear, and only the genuinely scary tier waits for a decision. Repeated approvals become standing rules so the same question never gets asked twice, while dangerous patterns are unlearnable by design. The system's job is making every ask rarer and richer, until the ones that remain deserve real attention.

What happens when a human rejects an action?

The reason goes back to the agent as information, and the agent re-plans. "No W-9 on file" doesn't kill the payment: it sends the agent to get the W-9 and resubmit at lower risk. Rejection is feedback, not death: the task survives, the risk doesn't, and the gateway becomes a conversation between agent judgment and human authority instead of a wall. And when a task shouldn't be agent-done at all, Take over hands it to you prefilled: the invoice open in your billing queue, the draft in your outbox. Take over the same pattern twice and Ripcord proposes a standing route-to-human rule: risky patterns can't earn auto-approval, but they can earn a permanent human lane.

Isn't "reversible" just marketing? You can't reverse physics.

Conceded, and the whole engine is built on the concession: severity is discounted by recoverability, so the gate prices exactly what we can and can't take back. But most business irreversibility is process design, not physics. An email is only unrecallable because it left in one breath; sent in batches behind a hold, it stops at #50. A deletion is only permanent without a snapshot; Ripcord takes one before every destructive call. The rule: never execute an action in its irreversible form while a reversible form exists. Every industry that engineered undo into a "final" domain did the same thing: chargebacks, database transactions, git, Gmail's unsend. Throughput exploded, and nobody calls it marketing. And where physics truly wins (an executed wire, a served notice), the residual is priced: a loss despite reasonable controls is the definition of an insurable event. What can't be reversed can be insured.

It's time to pull the ripcord.

Watch it stop a $48,200 mistake, roll back 4,382 deleted records, and unsend an email: live, right now.

Try the live demo → Start free
Shadow mode first: it proves itself before it gates anything.
one caught $48,200 mistake pays for 40 agent-years of gating