A Series B fintech let autonomous agents touch email, payments, and their production database. Here’s what broke before AgentKey, and what stopped breaking after.
The team had wired a handful of LLM agents into their internal tools: Gmail for support triage, Stripe for refunds, and a read-only copy of the customer database. Each agent had a broad API key with full-scope access.
It worked until it didn’t. One agent, asked to “clean up old support threads,” permanently deleted two years of emails. Another refunded a customer three times in a row because it retried on a timeout. A third read a prompt injected through a forwarded email and tried to exfiltrate a customer list to an external URL.
They routed every agent action through AgentKey. Instead of “can this agent use Stripe?”, each call now asks “can this agent run this action, with these parameters, under this policy?” and gets an answer in single-digit milliseconds.
Refunds now require human approval. Deletes are denied outright. Reads are allowed.
Every decision is a hash-chained, independently verifiable record. Compliance can recompute the chain independently, no trust required.
Tool output and emails are scanned for hidden instructions before reaching the agent, stripping prompt-injection payloads.
Monthly request caps are checked on every call, not trusted to the client.
After 90 days in production across five agents.
We stopped asking whether our agents were smart enough. We started asking whether we could prove what they did. That’s the whole game now.Head of Platform Security
Identity, action-level policies, and runtime controls for autonomous agents. Free to start.
Start for Free