Ripcord

Every AGI needs an AIG.

We're building the insurance carrier for the AI agent economy. The way in: a recovery engine that lets your agents act, and takes it back when they shouldn't have.

Our mission: make the agent economy safe enough to actually happen.
Pre-seed · August 2026 · gate today, insure tomorrow · every gated action builds the actuarial tableworking prototype: live demo in this meeting
Why this exists

My CTO said no.

At TensorSource I ran operations. I wanted agents on the invoice queue, on support, on the marketing sends — the productivity was sitting right there. Our CTO blocked it: one wrong payment, one wrong mass email, one customer table pasted into a prompt, and the damage outruns a year of savings.

He wasn't wrong. Nobody could answer his questions: "what happens when it's wrong once? And where does our data go?" So the agents stayed off, and the productivity stayed on the table. The Fed has since priced that table: 2.2 hours per employee every week on average, 9+ for the top 27%, 20+ for the power users.

Ripcord exists so the next CTO can say yes.
the founding frustration, live from the COO seat2
The problem

Everyone bought autonomy. Everyone is paying for supervision.

STALL

Don't deploy

Looks safe, compounds against you: adopters bank a Fed-measured ~2.2 hours per employee per week, and that is the floor: the top quartile saves 9+. A 500-person company leaves $4M to $16M a year on the table by waiting.

LEASH

Approve everything

A human clicks send on every consequential action. The supervision tax eats what the agent was hired to save.

FLY BLIND

Deploy and hope

Agents run untrusted, failures go untraced, and the first sign of trouble is the bank statement.

Three strategies, one missing answer: nobody can say "what if it's wrong once?"
Kore.ai Agent Productivity Index, Jun 2026 · waiting cost: St. Louis Fed 2025 (2.2 hrs/wk) × 48 wks × $75/hr loaded3
The receipts

It keeps happening.

Not projections: incidents. Six of the nine in our public file, every fact sourced, single-source accounts labeled as such.

APR 2026PocketOS: a Cursor agent deleted the production database and its co-located backups in nine seconds, against an explicit ban. The freshest surviving backup was three months old.
FEB 2026Meta Superintelligence Lab: the alignment director's agent deleted her inbox and ignored STOP. Its words after: “Yes, I remember. And I violated it.”
DEC 2025Amazon: its own coding agent deleted an AWS production environment. It inherited elevated privileges, so the mandatory two-person gate never fired: ~13 hours of outage.
AUG 2025Salesloft Drift: one AI agent's stolen OAuth tokens opened the Salesforce doors of 700+ companies, Cloudflare included. The product was taken offline for good.
JUL 2025Replit: ignored an explicit code freeze, dropped SaaStr's production database, then said rollback was impossible. It wasn't.
FEB 2024Air Canada: the tribunal ruled the company bound by the refund policy its bot invented, after the airline argued the bot was “a separate legal entity.”
Every one was survivable with a gateway in the path. None of them had one.
the full file, with sources: tryripcord.com/incidents4
The rogue problem

Benchmarks say what a model can do.
The ledger says what it did.

You will run brains you didn't build and can't audit: picked off a leaderboard, swapped every quarter. Trust can't come from the model's own report card. It comes from watching every action it takes: guardrails filter words, Ripcord audits behavior over time. A flight recorder, not a content filter.

DRIFT · OFF-MANDATE

The ops agent's first-ever payment call: held before it runs, classified against the agent's own history. Deviation is measured from the mandate, not guessed from the prompt.

ESCALATION · ARGUING

The same action re-submitted after a human said no: the agent freezes on the spot, and everything further from it fails closed until a person thaws it.

VELOCITY & HOURS

Runaway loops, structuring, off-window activity: tripwires that read aggregates and clocks, the patterns a single-action review can never see.

"Yes, I remember. And I violated it." — an autonomous agent to the director of AI alignment at Meta's Superintelligence Lab, February 2026, after deleting her inbox and ignoring "STOP" from her phone. If prompts were controls, hers would have held.

Every incident is classified and lands in the monthly report as a conduct grade per agent, A to D, with the remediation spelled out · live today: the "benchmark star goes rogue" scenario runs in the sandbox, in the meeting

Alignment is a promise. Conduct is a measurement: the first behavioral audit for AI agents, and the rating this market will be built on.
misalignment insurance: the risk that grows with capability instead of shrinking5
The data answer

Your agent can't leak what it never saw.

86.9% of companies have delayed AI deployments because data security and governance weren't ready (AvePoint, 2026): not budget, not buy-in, data. The gateway already proves the fix with credentials: agents call tools, never hold the keys. Your data rides the same interception point.

TOKENIZED AT THE GATEWAY

PII is swapped for vault tokens before the model reads it: the agent works with ⟨customer#4821⟩, the provider only ever sees pseudonyms, and real values return only inside an approved send.

EGRESS ENTERS THE SCORECARD

Rows × sensitivity × destination gates like dollars: 3,200 customer records headed outside fail closed the same way a $48,200 wire does.

THE LINEAGE LEDGER

Every field that crossed the boundary, in the hash-chained trail: records of processing in one query, subject-access answers in minutes, breach scope in seconds.

RESIDENCY ROUTING

Policy picks the brain by data class: EU data stays on EU-hosted models, sensitive corridors go self-hosted. How you run a leaderboard model safely.

The number one no becomes the easiest yes: compliance evidence is the risk ledger wearing a suit.
the DPO is the second buyer · promises vs enforcement, again6
Why now

The wound is already bleeding, and better models won't staunch it.

79%

already had to reverse an agent's action

→ THEY NEED ROLLBACK
70%

faced a failure they couldn't trace

→ THEY NEED THE AUDIT TRAIL
62%

delayed deployment out of governance fear

→ THEY NEED THE DIAL
THE WAVE WE PRICE ON Agents under management, 2024 to 2029

IDC via Statista: 2.2B by 2030, ≈900M in 2029; we price the managed ~5%. Accuracy must outrun this curve just to hold mistakes flat.

50 agents × 24/7 × 1 action / 2 min = 1,080,000 actions/mo · even at 99.9% (benchmarks: <90%) = 1,000+ mistakes/mo, one is a wire
perfect agents still execute wrong instructions perfectly (A1)
stats: Kore.ai Agent Productivity Index, Jun 2026 · benchmarks: τ-bench family · forecast: IDC via Statista · detail in the data room7

Autonomy is gated by reversibility, not intelligence.

Companies don't restrict agents because agents are dumb. They restrict them because mistakes are permanent. Sell the undo, and you're really selling permission. Price the risk, and you're the carrier.

ripcord: thesis8
The product

Everything you need to give agents real authority, safely

ANY AGENT Claude · Codex · Kimi · MCP no keys, ever RIPCORD scores every action by expected loss Gate = P(flag) × $exposure × (1−undo) keys injected per request runaway tripwires · math: A10 low: runs instantly med: held, stoppable high: owner decides routed in Slack THE WORLD money · data · comms · public THE LEDGER every action every near-miss every verdict = actuarial table undo · rollback · compensation · "rejected because…" → the agent re-plans
SIX VERBS, NOT TWO

Approve, modify, ask why, take over, or reject with a reason the agent acts on. Escalate routes it up.

RECOVERY, BUILT IN

Snapshot before, rollback window after, compensation when undo isn't physics. Every action leaves an audit line.

IT LEARNS YOUR JUDGMENT

Approvals become rules, takeovers become routing. Dangerous patterns are unlearnable by design.

cross-vendor: one policy, one inbox, one record · prompts are suggestions, the gateway is physics · all clickable in the demo9
The demo

The $48,200 that didn't get stolen

1 · CAUGHT
$48,200 to a never-paid vendor: fail-closed at risk 65. Six verbs for the human, a 90-second clock for the agent.
Held payment card in the Ripcord dashboard
2 · REJECTED, THEN DONE RIGHT
"No W-9 on file" goes back to the agent as feedback. Bottom card: the rejection. Top card: the agent's fixed resubmission, verified and executed.
Rejected payment and re-planned verified payment
3 · THE OBVIOUS COUNTER FAILS
Split into 5 × $9,640 to duck the threshold. The 24-hour window adds them up: caught at payment two, all five fail-closed.
Split attack payments caught by velocity window
Rejection is feedback, not death: the same task, done right. Unretouched screenshots of the working product.
demo clocks compressed to 90s so a meeting sees the full lifecycle · production windows are policy · expiry rejects, never releases10
Use cases

Payments are the demo. The product is everywhere an agent acts.

Money

HARD TO CLAW BACK

THE NIGHTMARE"$48,200 wired to a brand-new vendor."

RIPCORDGates it hard. A human owns the yes. Clawback workflow built in if it ever slips.

Data

FULLY RESTORABLE

THE NIGHTMARE"4,382 customer records deleted overnight."

RIPCORDSnapshot taken before it runs. Rollback is one click, inside a policy-set window.

Comms

STOPPABLE IN FLIGHT

THE NIGHTMARE"2,000 customers emailed: 'your refund is approved.'"

RIPCORDHeld in escrow, sent in batches: stopped at email #50, not #2,000.

Public

GONE ONCE SEEN

THE NIGHTMARE"The launch tweet fires with last month's discount."

RIPCORDWaits in escrow, re-checked against the world at fire time. Regret window after.

One fleet acts in all four. One policy, one inbox, one record: wherever it happened.
the demo picks the scariest corridor · the gateway stands in all four · undo physics per corridor: A611
The honest question: "won't someone bigger just build this?"

Everyone answers one question. Nobody answers the second.

AUTHORIZE

"May it act?"

confirm dialogs & auto modes (the labs)control planes (HumanLayer, OneCLI)access gateways (StrongDM)
CROWDED, COMMODITIZING
CONTAIN

"How bad can it be?"

card limits (AgentCard, Robinhood, Visa)sandboxes (CI, containers)AP approval rails (Ramp, Bill)
ONE CORRIDOR EACH
RECOVER

"Can we take it back?"

Ripcord
NOBODY ELSE HERE
EMPTY
INSURE

"Who pays when it fails?"

MGA policies (Mount)cyber/E&O blends (legacy carriers)RIPCORD · the only inside-out data

they have the paper · we have the price

DATA-STARVED

"But the labs will build this" · a self-gating agent fails twice · the 2am test: both humans sleep — only one fleet works (run the reversible, escrow the delayable, wake the owner only for the irreversible) · the audit test: injected, confused, or runaway agents don't ask — nobody insures the agent grading its own homework

Alone in the empty room: and we walk into the insurers' room holding the dataset it's starving for.
the full map, with every name and every cell: appendix A11 · deep dives: A3, A412
The market

Per-human software built giants. We price per agent, and agents will outnumber humans.

ADP on payroll, Workday on HR, Okta on identity: every generation that priced per-employee built decacorns. Agents are the fastest-growing denominator enterprise software has ever had.

TAM
$60B/yr

≈50M managed enterprise agents by 2029 (~5% of IDC's ≈900M forecast) × ~$1,200/yr governance & evidence spend. Before the premium pool.

SAM
$5B/yr

The reachable wedge: ~5M agents in cloud-first, compliance-bound fleets (US/EU, MCP-era stacks).

SOM · YR 3
$40M ARR

≈400 customers × ~85 agents × $99/mo. Under 1% of SAM, rung-1 only. The AI-infra cohort's pace, and the founder has ridden it: Hyperbolic went 0 → $50M in 3.5 years.

Every number is the same two inputs: agents under management × price per agent. Attack the inputs, not the acronyms.
agent forecast: IDC via Statista, Jan 2026 (2.2B by 2030, ≈900M in 2029; we assume the managed ~5%) · comps: ADP · Workday · Okta · Coalition13
The ladder

How we climb it: gate, prove, price

RUNG 1 · GATE (NOW)

$ / agent / month

Safety software on a denominator that compounds. Software multiples, selling today.

RUNG 2 · PROVE

The evidence layer

Certified risk reports, compliance, audit: the Vanta-shaped recurring layer, sold on the same install. Fleets ranked by consequences, not votes: the enterprise LM Arena.

RUNG 3 · PRICE

Share of premiums

Agent-risk insurance, priced from the near-miss ledger. The carriers exist today, and they're data-starved (A7). Coalition: $5B on ~$20B of cyber premiums.

2030, at just 1% of the wave: 500,000 agents × $79/mo ≈ $475M ARR on rung 1 alone · evidence revenue and premium share stack on top
Each rung is priced on the same denominator: agents under management.
gate → prove → price · each rung funds the next · 500,000 × $79 × 12 = $474M, arithmetic in the open14
Business model

Priced so customers gate everything

Per agent under management, never per action

A safety layer that charges by use invites selective safety. 100% coverage must be the economically rational default: the near-miss ledger depends on it.

The quiet moat in the pricing

The immutable audit history compounds with tenure: churning after two years means abandoning two years of evidence your auditors and insurers rely on. Retention priced as history.

Ripcord pricing tiers: Free, Team $99, Business $79, Enterprise
One caught $48,200 mistake pays for 40 agent-years of gating.
79% have already eaten the mistake: the only question is whether Ripcord was in the path15
The data

"An insurer is a coroner.
Ripcord is the family doctor."

THE NEAR-MISS LEDGER · ONE YEAR OF A 50-AGENT FLEET · MODELED, TO SCALE
10,000,000
actions gated: the denominator no insurer has
180,000
blocked before anything happened · 1.8%
70,000
rolled back: caught in time · 0.7%
2,000
became losses: the only line an insurer ever sees · 0.02%

Only the party in the doorway can measure near-misses: everyone else rents the balance sheet AND the data, we rent only the paper. And the ledger needs no scale to start: the gateway is fully useful at one customer.

MOAT 1 · NETWORK IMMUNITY

Pattern memory is live per customer; at network scale one near-miss will inoculate every fleet, and actuarial value keeps paying after data effects fade.

MOAT 2 · AUDIT GRAVITY

Years of immutable history don't migrate. Retention compounds with tenure.

MOAT 3 · THE CERTIFICATION STANDARD

Certified fleets make the mark worth joining. SSL had one padlock, not five. The mark matures into the rating: S&P for agent risk.

This ledger is the first actuarial table for agent risk: and every human verdict sharpens the formula that prices it.
10,000,000 rows nobody else can see16
Where we are

Prototype built. Four gates to the seed.

TODAY
  • Working control plane: risk engine, six verbs, snapshots & rollback, rule learning
  • Live MCP gateway: gates real tool calls from any MCP agent, zero integration. Rejections return as tool errors with the reason, so real agents re-plan on their own
  • Slack-native approvals, credential vault (bypass = 401), runaway tripwires & agent freeze: all live
  • Conduct engine live: off-mandate drift and post-rejection escalation detected, classified, agent auto-frozen, graded A–D in the report
THE FOUR GATES TO THE SEED
  • Gate 1 · month 3 · MCP-proxy gateway GA: real tools, zero integration
  • Gate 2 · month 12 · 10 design partners → ~$300k ARR signed
  • Gate 3 · month 15 · SOC 2 + the first Certified risk reports
  • Gate 4 · month 18 · first carrier LOI (the Coalition motion begins)

GTM: week one runs in shadow mode → every prospect gets a Near-Miss Report of what we'd have caught, before paying a dollar · north-star metric: time-to-first-save

THE PROOF, ONE SCREEN · BYPASS FAILS (401: THE AGENT HOLDS NO KEYS) · SAFE RUNS INSTANTLY · RISKY IS HELD · DANGEROUS IS REFUSED WITH THE REASON, AND THE AGENT RE-PLANS Terminal transcript of the Ripcord gateway gating real tool calls
traction & roadmap · transcript unedited: run it yourself in the meeting17
The second wedge

Gate what exists. Launch what doesn't.

Half the market is blocked mid-flight; the other half never took off. For teams with no agents at all, Ripcord builds the first one: born on the leash, so the standoff never begins.

1 · PICK THE BRAIN

Any frontier model, seeded from public arena leaderboards, refreshed weekly. Then the flywheel turns: our ledger re-ranks models by consequences, not votes: the enterprise arena this deck already promised.

2 · RULES BECOME THE SCORECARD

"Publish only in working hours." "Announcements Wednesday 11:00 ET." Not prompt suggestions: scorecard signals the gateway enforces. Policy attaches at birth, not after the incident.

3 · THE NIGHT SHIFT

The first role teams trust: browses competitors, fundraising and techniques overnight in a logged read-only lane, and the morning brief waits in escrow for the 7:30 slot.

Creation is the cheapest place to win governance: every agent born inside Ripcord starts life on the leash.
live in the sandbox today: tryripcord.com/launch · wizard → policy JSON → enforced by the same gateway18
The team

Built by an operator, engineered to close

Jeremy Hazan
FOUNDER & CEO
  • Full-time on Ripcord. Most recently COO, TensorSource: AI training-data infrastructure.
  • Founding team, Hyperbolic (now Series B, GC & Lightspeed): led GTM from zero to $5M ARR in year one and closed Hugging Face, OpenRouter & LM Arena partnerships.
  • Early team at Ava Labs: PM on AvaCloud, built the Japan team from Tokyo.
  • Advisor to the French Presidency and Ministry of Armed Forces on national AI strategy.
  • Dual MS in Information Science & CS, Cornell University & Technion. BS Applied Mathematics, Sorbonne University, valedictorian in probability.
  • First hires: two senior security-grade engineers, funded by this round.
Jeremy Hazan
Jeremy Hazan

Founder & CEO
New York City

CTO & CO-FOUNDER · CLOSING WITH THE ROUND
Security-grade infrastructure engineer

The search runs alongside design partners as the top priority. The recruiting pitch is this deck and a working gateway.

AI infrastructure, go-to-market, national AI risk, probability. Ripcord is the first job that needs all four.
team19
The ask

$2M pre-seed: 18 months to the four gates

TEAM

CEO plus a CTO co-founder closing with the round, founding engineers for protocol and risk, a forward-deployed engineer for design partners, and a fractional security lead: ≈ $107k/mo all-in.

CREDIBILITY

SOC 2, third-party security audit, consent & DPA architecture ≈ $75k. For a trust product, compliance is product.

BUYS

MCP-proxy GA, 10 design partners, ~$300k ARR, the first Certified report, and the first carrier LOI: the seed story, funded end to end.

Use of funds: team & product 64% · design partners & GTM 15% · compliance & audit 8% · insurance BD 5% · buffer 8%

≈ $107k/mo × 18 months + $75k audits = $2M, priced to the four gates. What this round buys: the seed story, end to end.
FLOOR

The Datadog of agents

Neutral infrastructure on a compounding denominator. Software multiples.

BASE

The Coalition of the agent economy

Software plus premium share, priced from data only we generate.

CEILING

The AIG of the AGI economy

The balance sheet behind a world that runs on agents.

SAFE, standard terms20
The race

Agent insurance will have very few winners. We start running on day one.

Rail matured into bonds; oil into futures and the largest insurance market on earth. Every new workforce matures into insurance too: workers' comp in 1911, compulsory auto in 1927, cyber in 1997, and agents now. After agents: every machine that decides — vehicles, warehouses, humanoids. The carrier that learns to price decisions prices them all.

2026

Gateway ships, and the carrier talks start

Insurance paper takes 12–18 months to negotiate. Sequencing it is how you lose the race, so BD begins in month one.

2027

The first agent-risk program

MGA on partner paper: capped limits, named perils, write-to-learn. Every policy is a paying row in the actuarial table. (Coalition wrote policies within ~18 months of founding.)

2028

The moat closes

Best loss ratios in the category, priced from the only action-level dataset. Winner-take-few markets are decided here: at the program stage, not the license stage.

2029+

Full stack, when inevitable

Own paper once the data makes it a formality. Coalition won cyber years before it owned a carrier.

"Every economy that learned to trust strangers needed rules, records, and insurance. We're building all three: in parallel, starting today."
the first cyber policy: AIG, April 1997 · the first agent policy gets written inside this window · we intend to hold the pen21

Appendix: objections, welcomed

Every hard question we've been asked, pre-answered. A1 Perfect agents · A2 The sophisticated attack · A3 The labs · A4 Agent cards · A5 Rubber-stamping · A6 Undo physics · A7 How agent-insurance carriers underwrite today · A8 The Flight Recorder program · A9 Pricing rationale · A10 How the score works · A11 The full map, named

appendix22
A1 · "What if agents stop making mistakes?"

Ask why your CFO still can't wire $10M alone

HUMAN ERROR SURVIVES

Perfect execution of a wrong or ambiguous instruction: "wire the deposit" to the outdated account: is still a disaster with zero agent error in it.

ADVERSARIES SURVIVE

A flawless agent flawlessly executing an attacker's injected instruction is the scariest version. Servers don't make mistakes; we still firewall them.

BAD INPUTS SURVIVE

Perfect reasoning on a forged invoice is still the wrong wire. The world stays wrong even when the model doesn't.

appendix A123
A2: the sophisticated attack

Risk 5. It sails through. Now what?

It will happen: a risk engine that catches everything is an oracle. Security's founding axiom: assume breach. What changes is everything around the miss:

LEGIBLE

The action went through the gateway: forensics is one query, not weeks of archaeology.

CONTAINED

Blast radius instantly visible; everything in a rollback window comes back; the agent freezes with one policy flip.

LEARNED

The pattern scores 80 tomorrow (live: a rejection doubles its odds). Network-wide propagation is GEN 3.

ABSORBED

A loss despite reasonable controls is the definition of an insurable event, and the audit trail is the claims file.

Prevent, contain, recover, absorb: no loss goes unpriced.
appendix A224
A3: the labs

Your agents come from every lab. Your safety layer can't pick a side.

THEIR CONFIRM DIALOG
  • Assumes a human watching one agent in a terminal. Fifty agents make it an inbox of raw asks, and rubber-stamping begins (A5)
  • The model assesses its own actions ("auto modes"): correlated failure by design. Their own docs recommend isolation
  • One verb, stop and wait: the work freezes until a human returns, and the approval ends the safety story
  • Governs its own lab's agents only
THE GATEWAY
  • Built for nobody watching overnight: the reversible runs, the delayable is escrowed, only the irreversible waits for morning
  • Scores the stakes, outside the model: "new beneficiary, $48,200, 𝔼[loss] $17,467" fails independently of the agent
  • Approval is the midpoint: snapshot before, rollback after, evidence forever
  • Cross-vendor: the neutral layer wins every fragmented stack (Datadog, Okta)
What they'll ship: better confirm dialogs. What they won't: recovery, a neutral record, and an actuarial table no agent can write about itself.
appendix A3 · the confirm dialog is one-tenth of the product · outside their center of gravity, inside ours25
A4: agent cards

Walls don't read invoices

UNDER THE CAP
$48,200 < $50k limit

The fraud fits inside the cage. Tighten the cap and legitimate invoices bounce to tickets: the leash returns, enforced by the card.

THEIR BRAIN
1 confirm toggle

Per-purchase confirms (Robinhood, AgentCard) or SMS approvals (Skyfire): the confirm dialog rebuilt on the card rail, with the same fatigue.

THEIR RECOVERY
weeks per chargeback

Consumer-grade, and it ends at the corridor's edge: nothing for the wire, the deletion, or the mass email.

A card caps how big the mistake can be. Ripcord works on whether it happens at all, and what happens after.
The smartest walls are the AP rails (Ramp, Bill): approval chains for the payment, blind to the agent. We route agents through them, and govern the agent above.
appendix A4 · B2B money moves by wire and ACH anyway · walls and rails are defense-in-depth beneath a brain: complement, not competitor26
A5: approval fatigue

Designed so rubber-stamping never pays

THE QUEUE NEVER FORMS
  • Medium risk fails open: a window you can stop, not a queue you must clear
  • High risk fails closed: silence means no. The lazy path is the safe path
  • Routing to the action's owner with escalation, live today; spend budgets and two-person rules land with Gate 1
EVERY ANSWER MAKES ASKS RARER
  • Repeated approvals become auto-rules; repeated takeovers become route-to-human rules
  • The same question is never asked a third time, in either direction
  • Dangerous patterns are structurally unlearnable: laziness can't create a risky auto-rule
THE POSTERIOR, LIVE IN THE PRODUCT Beta posterior rule suggestion banner
The system's job: make every ask rarer and richer, until the ones that remain deserve real attention.
appendix A527
A6: undo physics

Honest about what can be undone

REVERSIBLE

DB writes: snapshot before, one-click rollback inside the window. Files and configs are the same primitive.

DELAYABLE

Email, publishing, mass sends: infinitely reversible before execution. Escrow is the only undo with a 100% success rate. Scheduled actions live here for free, and nothing fires without a T-0 re-check against the live world.

COMPENSABLE

Wires, agreements: can't unsend; can compensate with full context: reversals, recovery requests, corrections. Honestly valued at ~35%.

EXTERNAL

Posts and broadcasts: damage is the integral of exposure. The regret window: delete in the first half-minute with ~40 views and most of the harm never happened.

"Undo everything" would be a lie. Maximizing time-in-reversible-state is an engineering discipline: recoverability is a measurement, and it decays.
appendix A628
A7: how agent-insurance carriers underwrite today

Paper first, data second: we're the other road

PRICED BY ANALOGY
~$620/mo per $1M

Agent losses are "silent AI": falling between cyber, E&O, and crime policies that never contemplated an autonomous actor. Mount (YC S26): cyber/E&O blends at multiples of comparable cyber. The price of not knowing.

CAPPED & CARVED
$250k/claim cap

$1M aggregate, named perils only. Tight caps are what "we're guessing" looks like in contract form.

RENTED PAPER
0 own balance sheets

Fronting and reinsurance (Mount lists Guy Carpenter, Aon, Zurich). And they bundle outside-in scanners: the tell of a data-starved category.

Scanning configs is inspecting the car in the driveway. The gateway is the dashcam footage of every mile.
Capacity is a commodity; pricing signal is not. They need our dataset, we'll need their paper: the first partnership meeting writes itself.
appendix A7 · "won't carriers build a gateway?" = becoming a software company mid-flight. Coalition proved tech-led wins that race29
A8: the flight recorder program

This appendix lives in the data room.

A8 describes a private design-partner program and is shared under NDA. Ask for access: [email protected]

appendix A8 · shared privately with the data room30
A9: pricing rationale

Never tax coverage

VS THE STACK

Companies pay Datadog $15-23/mo to watch a server and CrowdStrike ~$10/mo to guard a laptop. $79/mo governs an autonomous actor with production credentials. A server can't initiate a $48,200 mistake.

VS AGENT SPEND

A 50-agent production fleet costs $25k-100k+/mo in inference alone. Ripcord at ~$4k/mo is 4-15% of the agent bill: the normal security share of an existing budget, not a new line item.

VS ONE MISTAKE

The same fleet produces 1,000+ mistakes/mo even at 99.9% accuracy. One caught $48,200 incident covers the fleet's entire annual bill. Everything after that is margin.

100% of actions through the gateway must be the economically rational default.
appendix A931
A10 · how the score works

A scorecard today, a network model tomorrow

GEN 1 · NOW

A log-odds scorecard (the FICO convention: +15 points doubles the odds) calibrated to P(flag), gated by expected loss: Gate = P × $exposure × (1 − recoverability). CUSUM velocity windows already kill structuring: five payments of $9,640 get caught as one $48,200. All shipped, all itemized as reasons a human can argue with. And your own policy enters the same math: "nothing publishes at night" becomes a signal beside "new beneficiary +45", whether the agent was connected or born here.

GEN 2 · AFTER THE SHADOW WEEK

Baselines learned per customer with robust statistics (median/MAD, not poisonable means): abnormal means abnormal for you. Severity proxies calibrated from realized exposure. SPRT-optimal hold durations: provably the fastest decision at fixed error rates. Time-decaying recoverability for external actions (exposure as an integral). Copula corrections for correlated signals.

GEN 3 · AT NETWORK SCALE

Every human verdict is a free training label. Network-trained models predict P(human would reject), wrapped in conformal guarantees: finite-sample proof that released actions carry ≤α risk. EVT severity tails price the 1-in-1,000 loss for underwriting. Reasons survive via attribution. The same ledger ranks agents, configs, and fleets: the reference for agent risk.

Gate = P(bad) × severity, and severity is discounted by our own ability to undo. No one else's risk engine gets to do that.
appendix A10 · the near-miss ledger's third identity: safety feature, actuarial table, training set32
A11: the map, with names

The receipts

Labs' dialogsClaude · Codex · Kimi Control planesHumanLayer · MCP gateways · OneCLI The wallscard limits · sandboxes · AP rails (Ramp, Bill) Carriersagent-risk MGAs Ripcordthe gateway
AUTHORIZE"May it act?" own agents only crowded, commoditizing cross-vendor
CONTAIN"How bad can it be?" ~ ~ one corridor each walls beneath a brain
RECOVER"Can we take it back?" nobody here but us
INSURE"Who pays when it fails?" ~paper-first: borrowed analogies, outside-in scans the near-miss ledger: the only inside-out data to price the peril
appendix A11 · every incumbent column is real: we integrate with the first three and feed the fourth33
Ripcord

Building the AIG of the AGI economy.

$2M pre-seed · august 2026 · [email protected]34