Built to be trusted.

Safe to run while you sleep.

Security and governance go in with the first line of code, not bolted on after the incident.

You leave with a filled-in Job Card.

Never hand one agent all three keys.

Private data, untrusted content and a way out. Put all three in one agent and one bad email leaks everything.

The lethal trifecta

  • Private data

    Customer records, internal docs, anything the public shouldn't see.

  • Untrusted content

    Inbound email, web pages, PDFs, calendar invites. Anything an outsider can write.

  • A way out

    Sending messages, posting to URLs, calling outside APIs.

All three in one agent: one prompt injection from a leak.

Never shipped

How we build it

Reader agent

Reads the untrusted content. Has no network tool.

Passes a typed contract

Sender agent

Holds the network tool. Never reads raw input.

Allowlist only

Approved destinations, nothing else

We design the split during the build, not after the incident.

Five more ways in. Each one closed.

The threats that break agents in production, and the defense that ships with every agent we build.

Closed: 0 of 5

The same defenses ship with every agent. Nothing gets bolted on later.

Prompt injection

Text that becomes a command.

Untrusted text is kept apart from instructions, and every action is checked against an allowlist.

Retrieval access

The search index is the new lock.

Access is enforced at the index, scoped to the person asking. It can't surface what they can't see.

Shadow AI

Your team already uses AI.

We find which tools, with what data, then give people a safe default they actually use.

Tool sandboxing

No tool it doesn't need.

A written tool list, scoped credentials per environment, and kill switches that get tested.

Key hygiene

The key it uses is the key they steal.

One key per agent, short rotation, least permission. Never in the code, never in the logs.

It stops before anything it can't undo.

Sending an outside message, moving money, writing to a system of record, deleting data. The agent waits for a person.

  • The gate lives in the tool layer, not the prompt.
  • Your yes lands in the audit log, with your name on it.
  • One command stops it and hands the work to a person.

You approve what matters. It does the rest.

Every control ships a file you can open.

Governance lives in the code, not the deck. If a control doesn't produce an artifact, it isn't a control.

Six controls, six artifacts

Agent handbook

Its rules, versioned in your repo.

Handbook in the repo

Model-use policy

Which models, for which tasks.

Gateway allowlist

Data classification

What never goes in a prompt.

Redaction rules

Audit trail

Every action, escalation and override.

Append-only log

Kill switch and rollback

One command to stop. A tested way back.

Rollback runbook

Human approval gates

Written into the agent's charter.

Signoff in the log

One control table, three frameworks

EU AI Act

Risk class, transparency and human oversight, mapped to your gates and your log.

NIST AI RMF

Govern, Map, Measure, Manage: traced to the policy, the charter, the test set and the kill switch.

ISO/IEC 42001

Clause to control to evidence, in one pass.

You own the keys.

Code, keys and accounts in your name. Fire us and it keeps running.

Every YNDR agent also ships with Memory, Governance, Learning and a Night Agent. Ask about them on the call.

Every agent ships with two manuals.

One the agent reads every turn. One your team reads on day one. Both are versioned like code.

Every turn

For the agent

The Agent Handbook

  • Its scope, and the one workflow it owns
  • Its tools, and which ones need a person
  • Decision rules and lines it won't cross
  • Tone, format and voice
  • The test set it's graded against

Day one

For your team

The Operations Manual

  • Daily checks, and what healthy looks like
  • When the agent waits for a person
  • Known failure modes, and how to spot them
  • Kill switch and rollback steps
  • Where escalations go

Your team owns the agent, not the other way around.

For your security review

The standard questionnaire items, answered plainly. Ask on the call for anything not listed here.

Where your data lives
In your accounts. Code, keys and accounts stay in your name.
Approvals
Anything that moves money or leaves the building waits for a person's yes.
Logging
Every step, approval and override is written to an append-only log.
Model provider
Anthropic's Claude.

Ask us the hard questions.

Thirty minutes. Bring your security team and your worst process. You leave with a filled-in Job Card.

Book a 30-minute call