Provable SECURITY for AI agents

Tell your AI what to do.
Get proof it did exactly that.

Every other AI guardrail asks you to trust it: that it ran, that it wasn't bypassed, that the operator's word is good. PreFlight checks every agent action against your rules before it runs, blocks the ones that break them, and turns that trust into a receipt anyone can verify.

Try it risk free today | no credit card required | MCP enabled.

Trusted by
AWS Arrington Capital Avistar.AI Finality Rule 26 AI Venice AI AWS Arrington Capital Avistar.AI StanfordFinality Rule 26 AI Venice AI

Built on the security foundations of cryptography and formal methods. Our peer-reviewed work spans verifiable inference and post-quantum commitments, presented at zkSummit and PQ Crypto 2026, featured at the NY Fed's Innovation Conference, and covered on the Zero Knowledge Podcast.

Verification is the bottleneck

Agents are stuck on low-stakes work. The missing piece is proof, not capability.

The agents can already draft, file, pay, and negotiate. The ceiling is trust: nobody can enforce, and then prove, that an agent followed the rules on the work that matters.

  • Nothing ships. Legal and risk won't sign off on an agent they can't verify.
  • Logs are self-reported. Your system vouching for itself — and audit takes weeks.
  • Reactive is too late. You find out after the money moved.
  • A model can't check a model. Whatever fools the agent fools the grader.
R
"What proves the rule fired, not just that it was logged?"
"How does review keep up with the agent?"
L
A
"Who can verify that without trusting us?"
!The agent was never the problem. The unanswerable questions are.
Enforcement CAN BE AUTOMATED

Block rule-violating agent actions.

PreFlight does not recognize attacks. It checks actions against your policy. Model error, hallucinated clause, prompt injection, drifting agent: all fail the same check. It blocks the action, whatever caused it.

The wrong action never runs, and the receipt proves it.

PreFlight works

Your rules become binding on agent actions.

01

Agent proposes an action

The agent states what it wants to do, in the action text.

02

Rules compile to formal logic

Your plain-English policy is translated to formal logic, checked for contradictions, and battle-tested before going live.

03

Solver returns SAT or UNSAT

The agent's action either satisfies the policy or it does not. The decision is deterministic, not probabilistic.

04

Cryptographic receipt attached

A cryptographic, zero-knowledge proof is generated and verifiable in under a second, even across thousands of checks.

Isometric diagram of an agent action passing through PreFlight, Verbatim, and Instruments as independent defense-in-depth layers before a verified receipt is issued

Bring a policy your risk team is arguing about.

Try the API → or Book a call →
Scaling MEANS VERIFYING, NOT OBSERVING

Oversight at human speed caps the agent at human speed.

Every governance platform promises you can scale AI with confidence. Read the mechanism, and there is a human reading a dashboard inside it. We believe that security should be proactive and not reactive. 

Oversight at human speed

Confidence, capped by review capacity.

The agent runs at machine speed; the organization approves at the pace of inboxes. The gap between the two is work you cannot delegate.

Checking at machine speed

Every agent action verified. No reviewer in the hot path.

The solver checks every action before it runs, at the speed the agent works, and the receipt proves it. Humans keep the two jobs that were always theirs: writing the rules, and judging the exceptions the rules route to them.

The volume of work you can govern stops being the volume a person can review.

EVEN WITH ZERO TRUST.

Get a receipt for every agent action.

PreFlight blocks the action, then hands you a receipt that leaves your trust boundary. A log is a statement your system makes about itself. The receipt is a statement the math makes about your system. Your auditor can argue with the first. Nobody argues with the second.

A log entryYour word for it
A cryptographic receiptProof
Tamper resistance not edited or deleted after the fact +tamper-evident — forging or editing it means breaking the cryptography
Policy the policy logged is the policy that ran +against that exact policy
Input the input logged is the input that was checked +on that exact input
Result the engine ran correctly rather than someone typing "deny" +producing that exact result
Who can check it only someone willing to trust your systems +verifiable by anyone in under a second, without trusting you or your systems
Privacy exposes the underlying policy and data to whoever audits it +revealing nothing — your policy and your data stay private
Deterministic

A rule decides, not a model. The gateway blocks before the action runs.

Provable

The system records that the rule fired. The operator writes the record, keeps it, and presents it.

Independently verifiable

A third party checks the math themselves. No account, no access to your systems, and no sight of your policy or your data.

Proof-carrying intent

User intent.
Every agent.
One proof chain.

Intent is fixed as a checkable predicate at the root. Every downstream agent, from the orchestrator to each sub-agent, proves conformance. One broken link surfaces before any action lands.

A variant of IVC · Incremental Verifiable Computation
User · root "Buy me a plane ticket to NYC" π₀ = commit(intent)
Orchestrator Splits into flight search, seat, and payment sub-tasks. π₁ = extend(π₀, action)
Sub-agent A Finds NYC flights. Intent intact. verify(π₁) → SAT
Sub-agent B · drift Books LAX. Predicate violated. Blocked. verify(π₁) → UNSAT

The predicate propagates untampered. Every upstream agent stays clean. Only the drifting node fails.

Introducing Verbatim

The model picks the words.
It never invents the facts.

Actions are only half of what agents produce. Verbatim is the same discipline for the words. Every price, date, and policy claim compiles into a decoding grammar, so the model is physically unable to generate a fact outside your spec. Not instructed not to. Unable to.

Ask about it

Deterministic by construction, not by prompt.

Candidate tokens
"$35 fee, waived" "sometime next week" "happy to cover that" fee.wire.domestic "$0, no charge"
↓ grammar mask ↓

"The domestic wire fee is $35.00."

Every character traced to a policy span.

Get your AI agents into production.