Agent safety

Real agents on production, without the risk.

Everything a CISO asks first, answered before they ask. Enforced in the engine, not just written in a policy.

Stop before pay

Outside a sandbox, every run stops at the payment step. Not configurable. Test cards and sandboxes only.

Learn more →

Three modes

Observe (read only), Act (fill forms, stop before pay), Commit (irreversible steps, sandbox + Approver only).

Learn more →

Polite by default

≤ 2 sessions per origin, 429 / Retry-After honoured, windows and blackouts respected.

Signed identity

Every request signed with Web Bot Auth and a documented user agent. Never spoofs a consumer agent.

Learn more →

Consent first

Ownership proof and a signed Test Authorization before any full-funnel run.

Learn more →

Kill switch

One click stops every run on a property, from the app or by email or phone.

No script injection

We drive a normal browser; nothing is injected into your payment pages (PCI DSS 6.4.3 / 11.6.1).

Synthetic data

Forms are filled with synthetic identities only; your production data is never entered.

Third parties protected

SSO, payment and chat embeds stay in Observe mode unless their owner authorises testing.

Security teams ask

Can your agents buy something on our live site?
No. Outside a sandbox every run stops before payment, and that setting cannot be turned off. Card entry uses processor test cards in sandboxes only.
What if a run misbehaves?
Either side can stop everything instantly with the kill switch. The engine also stops on error spikes, unexpected state changes or repeated 429s.
Will you overload our site?
Default is at most two concurrent sessions per origin, with 429 / Retry-After honoured automatically. Machine-paced load runs only on properties you explicitly authorise.

Bring your security team to the first call.

We start security and legal review in week one of every pilot.