THE LEDGER · THE PRODUCT

What is Ripcord? The safety gateway for AI agents, explained.

By Jeremy Hazan, founder of Ripcord · August 31, 2026 · 5 minute read

Ripcord is a safety gateway for AI agents. Every action your agents take goes through Ripcord first. Safe actions run instantly. Dangerous ones wait for a human. Wrong ones get reversed, because Ripcord kept them reversible. Rogue ones freeze. That is the whole product in four sentences, and the rest of this post is just those four sentences taken seriously.

The problem, in one sentence

AI agents are finally good enough to do real work, and nobody can answer the CTO's question: "what happens when it's wrong once?" A model that is right 99.9% of the time, running a million actions a month, still produces a thousand mistakes, and one of them is a wire transfer. So agents stay in pilots, the productivity stays on the table, and the standoff continues. We wrote up the numbers behind that standoff in a separate post, and the real incidents it produces live in the incident file.

How the gateway works

Ripcord sits at the tool-call layer, between your agents and everything they touch: payments, email, databases, CRMs, social accounts. If it speaks MCP, it already speaks Ripcord. Because the gateway also holds the credentials (agents call tools, they never hold keys), there is no way around it. Then, for every single action:

Prompts are suggestions. The gateway is physics.

That line matters because the alternative approaches all live inside the model: system prompts, guardrails, constitutional rules. Useful, but they are promises, and Stanford's AI Index 2026 found that under deliberate jailbreak attempts, safety scores dropped for nearly every model tested. Ripcord's controls sit outside the model, in infrastructure the agent cannot argue with.

Conduct, not just capability

Benchmarks tell you what a model can do on test day. They cannot tell you what your agent did last Tuesday at 2 a.m. So Ripcord classifies every deviation (drift off-mandate, escalation after a rejection, runaway velocity, off-hours activity, data egress) and issues each agent a conduct grade, A to D, in a monthly report. Over time those grades become the Ripcord Index: a rating built from real actions under real policies, not from test questions.

Your data never leaves the boundary

The same interception point fixes the other blocker: data compliance. PII is swapped for vault tokens before the model reads it, so the agent works with pseudonyms and the provider never sees your customers. Data egress is gated like dollars. Every field that crossed the boundary lands in a hash-chained lineage ledger. Your agent can't leak what it never saw, and your auditor can verify all of it: the controls map onto ISO/IEC 42001 and the NIST AI RMF clause by clause, and your audit firm can get a read-only seat on the ledger itself.

What it costs, and who it's for

Ripcord is priced per agent under management, never per action: one agent is free forever, fleets pay a flat band rate. It is built for the two people locked in the standoff: the operator who wants agents on the invoice queue this quarter, and the CTO or CISO whose name is on the first wrong wire. If you have agents, we wrap them in minutes. If you don't, the launch wizard builds you one, with the leash included.

The long game

Every scored action, every human verdict, and every reversal is a row in an actuarial table that has never existed before: what AI agents actually do wrong, how often, and what it costs. That table is how agent risk eventually gets priced and insured. Gate today, insure tomorrow. The name is the mission: a ripcord is the handle that opens the parachute, and nobody jumps without one.

See it catch a $48,200 mistake, live.

The sandbox runs in your browser: no signup, no sales call. Watch the gateway hold a wire, route it to a human, and reverse a deletion.

Try the live demo →
← Back to The Ledger