We're building the insurance carrier for the AI agent economy. The way in: a recovery engine that lets your agents act, and takes it back when they shouldn't have.
At TensorSource I ran operations. I wanted agents on the invoice queue, on support, on the marketing sends — the productivity was sitting right there. Our CTO blocked it: one wrong payment, one wrong mass email, one customer table pasted into a prompt, and the damage outruns a year of savings.
He wasn't wrong. Nobody could answer his questions: "what happens when it's wrong once? And where does our data go?" So the agents stayed off, and the productivity stayed on the table. The Fed has since priced that table: 2.2 hours per employee every week on average, 9+ for the top 27%, 20+ for the power users.
Looks safe, compounds against you: adopters bank a Fed-measured ~2.2 hours per employee per week, and that is the floor: the top quartile saves 9+. A 500-person company leaves $4M to $16M a year on the table by waiting.
A human clicks send on every consequential action. The supervision tax eats what the agent was hired to save.
Agents run untrusted, failures go untraced, and the first sign of trouble is the bank statement.
Not projections: incidents. Six of the nine in our public file, every fact sourced, single-source accounts labeled as such.
You will run brains you didn't build and can't audit: picked off a leaderboard, swapped every quarter. Trust can't come from the model's own report card. It comes from watching every action it takes: guardrails filter words, Ripcord audits behavior over time. A flight recorder, not a content filter.
The ops agent's first-ever payment call: held before it runs, classified against the agent's own history. Deviation is measured from the mandate, not guessed from the prompt.
The same action re-submitted after a human said no: the agent freezes on the spot, and everything further from it fails closed until a person thaws it.
Runaway loops, structuring, off-window activity: tripwires that read aggregates and clocks, the patterns a single-action review can never see.
"Yes, I remember. And I violated it." — an autonomous agent to the director of AI alignment at Meta's Superintelligence Lab, February 2026, after deleting her inbox and ignoring "STOP" from her phone. If prompts were controls, hers would have held.
Every incident is classified and lands in the monthly report as a conduct grade per agent, A to D, with the remediation spelled out · live today: the "benchmark star goes rogue" scenario runs in the sandbox, in the meeting
86.9% of companies have delayed AI deployments because data security and governance weren't ready (AvePoint, 2026): not budget, not buy-in, data. The gateway already proves the fix with credentials: agents call tools, never hold the keys. Your data rides the same interception point.
PII is swapped for vault tokens before the model reads it: the agent works with ⟨customer#4821⟩, the provider only ever sees pseudonyms, and real values return only inside an approved send.
Rows × sensitivity × destination gates like dollars: 3,200 customer records headed outside fail closed the same way a $48,200 wire does.
Every field that crossed the boundary, in the hash-chained trail: records of processing in one query, subject-access answers in minutes, breach scope in seconds.
Policy picks the brain by data class: EU data stays on EU-hosted models, sensitive corridors go self-hosted. How you run a leaderboard model safely.
already had to reverse an agent's action
→ THEY NEED ROLLBACKfaced a failure they couldn't trace
→ THEY NEED THE AUDIT TRAILdelayed deployment out of governance fear
→ THEY NEED THE DIAL
IDC via Statista: 2.2B by 2030, ≈900M in 2029; we price the managed ~5%. Accuracy must outrun this curve just to hold mistakes flat.
Companies don't restrict agents because agents are dumb. They restrict them because mistakes are permanent. Sell the undo, and you're really selling permission. Price the risk, and you're the carrier.
Approve, modify, ask why, take over, or reject with a reason the agent acts on. Escalate routes it up.
Snapshot before, rollback window after, compensation when undo isn't physics. Every action leaves an audit line.
Approvals become rules, takeovers become routing. Dangerous patterns are unlearnable by design.



THE NIGHTMARE"$48,200 wired to a brand-new vendor."
RIPCORDGates it hard. A human owns the yes. Clawback workflow built in if it ever slips.
THE NIGHTMARE"4,382 customer records deleted overnight."
RIPCORDSnapshot taken before it runs. Rollback is one click, inside a policy-set window.
THE NIGHTMARE"2,000 customers emailed: 'your refund is approved.'"
RIPCORDHeld in escrow, sent in batches: stopped at email #50, not #2,000.
THE NIGHTMARE"The launch tweet fires with last month's discount."
RIPCORDWaits in escrow, re-checked against the world at fire time. Regret window after.
they have the paper · we have the price
"But the labs will build this" · a self-gating agent fails twice · the 2am test: both humans sleep — only one fleet works (run the reversible, escrow the delayable, wake the owner only for the irreversible) · the audit test: injected, confused, or runaway agents don't ask — nobody insures the agent grading its own homework
ADP on payroll, Workday on HR, Okta on identity: every generation that priced per-employee built decacorns. Agents are the fastest-growing denominator enterprise software has ever had.
≈50M managed enterprise agents by 2029 (~5% of IDC's ≈900M forecast) × ~$1,200/yr governance & evidence spend. Before the premium pool.
The reachable wedge: ~5M agents in cloud-first, compliance-bound fleets (US/EU, MCP-era stacks).
≈400 customers × ~85 agents × $99/mo. Under 1% of SAM, rung-1 only. The AI-infra cohort's pace, and the founder has ridden it: Hyperbolic went 0 → $50M in 3.5 years.
Safety software on a denominator that compounds. Software multiples, selling today.
Certified risk reports, compliance, audit: the Vanta-shaped recurring layer, sold on the same install. Fleets ranked by consequences, not votes: the enterprise LM Arena.
Agent-risk insurance, priced from the near-miss ledger. The carriers exist today, and they're data-starved (A7). Coalition: $5B on ~$20B of cyber premiums.
A safety layer that charges by use invites selective safety. 100% coverage must be the economically rational default: the near-miss ledger depends on it.
The immutable audit history compounds with tenure: churning after two years means abandoning two years of evidence your auditors and insurers rely on. Retention priced as history.
Only the party in the doorway can measure near-misses: everyone else rents the balance sheet AND the data, we rent only the paper. And the ledger needs no scale to start: the gateway is fully useful at one customer.
Pattern memory is live per customer; at network scale one near-miss will inoculate every fleet, and actuarial value keeps paying after data effects fade.
Years of immutable history don't migrate. Retention compounds with tenure.
Certified fleets make the mark worth joining. SSL had one padlock, not five. The mark matures into the rating: S&P for agent risk.
GTM: week one runs in shadow mode → every prospect gets a Near-Miss Report of what we'd have caught, before paying a dollar · north-star metric: time-to-first-save
Half the market is blocked mid-flight; the other half never took off. For teams with no agents at all, Ripcord builds the first one: born on the leash, so the standoff never begins.
Any frontier model, seeded from public arena leaderboards, refreshed weekly. Then the flywheel turns: our ledger re-ranks models by consequences, not votes: the enterprise arena this deck already promised.
"Publish only in working hours." "Announcements Wednesday 11:00 ET." Not prompt suggestions: scorecard signals the gateway enforces. Policy attaches at birth, not after the incident.
The first role teams trust: browses competitors, fundraising and techniques overnight in a logged read-only lane, and the morning brief waits in escrow for the 7:30 slot.
Founder & CEO
New York City
The search runs alongside design partners as the top priority. The recruiting pitch is this deck and a working gateway.
CEO plus a CTO co-founder closing with the round, founding engineers for protocol and risk, a forward-deployed engineer for design partners, and a fractional security lead: ≈ $107k/mo all-in.
SOC 2, third-party security audit, consent & DPA architecture ≈ $75k. For a trust product, compliance is product.
MCP-proxy GA, 10 design partners, ~$300k ARR, the first Certified report, and the first carrier LOI: the seed story, funded end to end.
Use of funds: team & product 64% · design partners & GTM 15% · compliance & audit 8% · insurance BD 5% · buffer 8%
Neutral infrastructure on a compounding denominator. Software multiples.
Software plus premium share, priced from data only we generate.
The balance sheet behind a world that runs on agents.
Rail matured into bonds; oil into futures and the largest insurance market on earth. Every new workforce matures into insurance too: workers' comp in 1911, compulsory auto in 1927, cyber in 1997, and agents now. After agents: every machine that decides — vehicles, warehouses, humanoids. The carrier that learns to price decisions prices them all.
Insurance paper takes 12–18 months to negotiate. Sequencing it is how you lose the race, so BD begins in month one.
MGA on partner paper: capped limits, named perils, write-to-learn. Every policy is a paying row in the actuarial table. (Coalition wrote policies within ~18 months of founding.)
Best loss ratios in the category, priced from the only action-level dataset. Winner-take-few markets are decided here: at the program stage, not the license stage.
Own paper once the data makes it a formality. Coalition won cyber years before it owned a carrier.
Every hard question we've been asked, pre-answered. A1 Perfect agents · A2 The sophisticated attack · A3 The labs · A4 Agent cards · A5 Rubber-stamping · A6 Undo physics · A7 How agent-insurance carriers underwrite today · A8 The Flight Recorder program · A9 Pricing rationale · A10 How the score works · A11 The full map, named
Perfect execution of a wrong or ambiguous instruction: "wire the deposit" to the outdated account: is still a disaster with zero agent error in it.
A flawless agent flawlessly executing an attacker's injected instruction is the scariest version. Servers don't make mistakes; we still firewall them.
Perfect reasoning on a forged invoice is still the wrong wire. The world stays wrong even when the model doesn't.
It will happen: a risk engine that catches everything is an oracle. Security's founding axiom: assume breach. What changes is everything around the miss:
The action went through the gateway: forensics is one query, not weeks of archaeology.
Blast radius instantly visible; everything in a rollback window comes back; the agent freezes with one policy flip.
The pattern scores 80 tomorrow (live: a rejection doubles its odds). Network-wide propagation is GEN 3.
A loss despite reasonable controls is the definition of an insurable event, and the audit trail is the claims file.
The fraud fits inside the cage. Tighten the cap and legitimate invoices bounce to tickets: the leash returns, enforced by the card.
Per-purchase confirms (Robinhood, AgentCard) or SMS approvals (Skyfire): the confirm dialog rebuilt on the card rail, with the same fatigue.
Consumer-grade, and it ends at the corridor's edge: nothing for the wire, the deletion, or the mass email.
DB writes: snapshot before, one-click rollback inside the window. Files and configs are the same primitive.
Email, publishing, mass sends: infinitely reversible before execution. Escrow is the only undo with a 100% success rate. Scheduled actions live here for free, and nothing fires without a T-0 re-check against the live world.
Wires, agreements: can't unsend; can compensate with full context: reversals, recovery requests, corrections. Honestly valued at ~35%.
Posts and broadcasts: damage is the integral of exposure. The regret window: delete in the first half-minute with ~40 views and most of the harm never happened.
Agent losses are "silent AI": falling between cyber, E&O, and crime policies that never contemplated an autonomous actor. Mount (YC S26): cyber/E&O blends at multiples of comparable cyber. The price of not knowing.
$1M aggregate, named perils only. Tight caps are what "we're guessing" looks like in contract form.
Fronting and reinsurance (Mount lists Guy Carpenter, Aon, Zurich). And they bundle outside-in scanners: the tell of a data-starved category.
A8 describes a private design-partner program and is shared under NDA. Ask for access: [email protected]
Companies pay Datadog $15-23/mo to watch a server and CrowdStrike ~$10/mo to guard a laptop. $79/mo governs an autonomous actor with production credentials. A server can't initiate a $48,200 mistake.
A 50-agent production fleet costs $25k-100k+/mo in inference alone. Ripcord at ~$4k/mo is 4-15% of the agent bill: the normal security share of an existing budget, not a new line item.
The same fleet produces 1,000+ mistakes/mo even at 99.9% accuracy. One caught $48,200 incident covers the fleet's entire annual bill. Everything after that is margin.
A log-odds scorecard (the FICO convention: +15 points doubles the odds) calibrated to P(flag), gated by expected loss: Gate = P × $exposure × (1 − recoverability). CUSUM velocity windows already kill structuring: five payments of $9,640 get caught as one $48,200. All shipped, all itemized as reasons a human can argue with. And your own policy enters the same math: "nothing publishes at night" becomes a signal beside "new beneficiary +45", whether the agent was connected or born here.
Baselines learned per customer with robust statistics (median/MAD, not poisonable means): abnormal means abnormal for you. Severity proxies calibrated from realized exposure. SPRT-optimal hold durations: provably the fastest decision at fixed error rates. Time-decaying recoverability for external actions (exposure as an integral). Copula corrections for correlated signals.
Every human verdict is a free training label. Network-trained models predict P(human would reject), wrapped in conformal guarantees: finite-sample proof that released actions carry ≤α risk. EVT severity tails price the 1-in-1,000 loss for underwriting. Reasons survive via attribution. The same ledger ranks agents, configs, and fleets: the reference for agent risk.
| Labs' dialogsClaude · Codex · Kimi | Control planesHumanLayer · MCP gateways · OneCLI | The wallscard limits · sandboxes · AP rails (Ramp, Bill) | Carriersagent-risk MGAs | Ripcordthe gateway | |
|---|---|---|---|---|---|
| AUTHORIZE"May it act?" | ✓own agents only | ✓crowded, commoditizing | ✗ | ✗ | ✓cross-vendor |
| CONTAIN"How bad can it be?" | ~ | ~ | ✓one corridor each | ✗ | ✓walls beneath a brain |
| RECOVER"Can we take it back?" | ✗ | ✗ | ✗ | ✗ | ✓nobody here but us |
| INSURE"Who pays when it fails?" | ✗ | ✗ | ✗ | ~paper-first: borrowed analogies, outside-in scans | →the near-miss ledger: the only inside-out data to price the peril |