Every other AI guardrail asks you to trust it: that it ran, that it wasn't bypassed, that the operator's word is good. PreFlight checks every agent action against your rules before it runs, blocks the ones that break them, and turns that trust into a receipt anyone can verify.
Try it risk free today | no credit card required | MCP enabled.
Built on the security foundations of cryptography and formal methods. Our peer-reviewed work spans verifiable inference and post-quantum commitments, presented at zkSummit and PQ Crypto 2026, featured at the NY Fed's Innovation Conference, and covered on the Zero Knowledge Podcast.
The agents can already draft, file, pay, and negotiate. The ceiling is trust: nobody can enforce, and then prove, that an agent followed the rules on the work that matters.
PreFlight does not recognize attacks. It checks actions against your policy. Model error, hallucinated clause, prompt injection, drifting agent: all fail the same check. It blocks the action, whatever caused it.
The wrong action never runs, and the receipt proves it.
The agent states what it wants to do, in the action text.
Your plain-English policy is translated to formal logic, checked for contradictions, and battle-tested before going live.
The agent's action either satisfies the policy or it does not. The decision is deterministic, not probabilistic.
A cryptographic, zero-knowledge proof is generated and verifiable in under a second, even across thousands of checks.
Every governance platform promises you can scale AI with confidence. Read the mechanism, and there is a human reading a dashboard inside it. We believe that security should be proactive and not reactive.
The agent runs at machine speed; the organization approves at the pace of inboxes. The gap between the two is work you cannot delegate.
The solver checks every action before it runs, at the speed the agent works, and the receipt proves it. Humans keep the two jobs that were always theirs: writing the rules, and judging the exceptions the rules route to them.
The volume of work you can govern stops being the volume a person can review.
PreFlight blocks the action, then hands you a receipt that leaves your trust boundary. A log is a statement your system makes about itself. The receipt is a statement the math makes about your system. Your auditor can argue with the first. Nobody argues with the second.
A log entryYour word for it |
A cryptographic receiptProof |
|
|---|---|---|
| Tamper resistance | –not edited or deleted after the fact | +tamper-evident — forging or editing it means breaking the cryptography |
| Policy | –the policy logged is the policy that ran | +against that exact policy |
| Input | –the input logged is the input that was checked | +on that exact input |
| Result | –the engine ran correctly rather than someone typing "deny" | +producing that exact result |
| Who can check it | –only someone willing to trust your systems | +verifiable by anyone in under a second, without trusting you or your systems |
| Privacy | –exposes the underlying policy and data to whoever audits it | +revealing nothing — your policy and your data stay private |
A rule decides, not a model. The gateway blocks before the action runs.
The system records that the rule fired. The operator writes the record, keeps it, and presents it.
A third party checks the math themselves. No account, no access to your systems, and no sight of your policy or your data.
Intent is fixed as a checkable predicate at the root. Every downstream agent, from the orchestrator to each sub-agent, proves conformance. One broken link surfaces before any action lands.
A variant of IVC · Incremental Verifiable Computation✓ The predicate propagates untampered. Every upstream agent stays clean. Only the drifting node fails.
Actions are only half of what agents produce. Verbatim is the same discipline for the words. Every price, date, and policy claim compiles into a decoding grammar, so the model is physically unable to generate a fact outside your spec. Not instructed not to. Unable to.
Ask about itDeterministic by construction, not by prompt.
"The domestic wire fee is $35.00."
Every character traced to a policy span.