A2M and A2A rails

Fraud detection, built for agents.

4242  9F2C  0AEE  ACME
Acme Agents Ltd
12 / 26
ed25519 · 84a7…c93b
CVV842
Ledger#2daf69
stripe · x402 · erc-8004 · live
Recent decisionsAcme Corp · live
000
2daf69finance.aislack.com$315allow
5ad790crawler.mktaws.s3$158allow
bb3e65marketing.v2x402.rail$2.7kallow
76650abuyer.botquillify.ai$77kblock
2d79f1finance.aislack.com$113allow
c87343crawler.mktslack.com$267allow
3ffd0bmarketing.v2x402.rail$2.2kallow
a6cb1cmarketing.v2x402.rail$169allow
6924c0crawler.mktbedrock$240allow
e0228cchatgpt.travelx402.rail$311allow
Gordon · agent pay · v0.42
signed ed25519 · 84a7
Gordon · agent pay
signed9f2c0a
Scroll
Why now

Fraud attacks moved upstream. A poisoned catalog, an injected tool call, a counterparty that isn't who it claims to be. The payment that follows is perfectly well-formed.

The attack surface

A2M and A2A.
One control plane for fraud.

A2M · Agent → Merchant

Your agent. Their catalog. Your money.

poisoned catalogchatgpt.travelAGENTGordonCONTROLexpedia.comMERCHANT
A2A · Agent → Agent

Their agent. Unproven intent. Your risk.

intent driftmarketingAGENT AunderwritingAGENT Bx402RAILaudit trailLEDGERGordonCONTROL
The product

Detect the attack. Score it. Prove it.

Our fraud models

Trained on agent compromise. Not human fraud.

Prompt injection, catalog poisoning, counterparty spoofing, intent drift and self-dealing, each scored while the agent is still reasoning. Upstream of the rail, before anything is committed.

Risk · live
24h
Decisions
212,408
Blocked
4,902
Drift p95
0.62
hover to play
Scores & decisions

Block what's suspicious. Score everything you allow.

Our models don't just stop the obvious. Every agent carries a running trust score and every transaction gets its own. What you let through arrives with the reasoning that allowed it.

Decisions · live
p50 · 18ms
INJECTSPOOFDRIFT
hover to play
Agent trust
0.94
Txn score
0.97
Dispute evidence

Every transaction, callable when the chargeback lands.

Merchants and PSPs query the signed record behind any agent payment: what the agent intended, how our models scored it, and why it was allowed. Representment evidence, not a support ticket.

Evidence · live
Dispute API
Evidence endpoint
/v1/disputes
Signed records
8,327
Open disputes
4
Evidence served
100%
TxnAgent → VendorAmountStatus
  • TX-3402marketing Apollo$128.00Sealing
  • TX-3401sales Clearbit$59.00Signed
  • TX-3400dev Anthropic$487.30Signed
  • TX-3399data Snowflake$312.50Signed
  • TX-3398finance Stripe$1,240.00Signed
The pipeline

Intent in.
Signed decision out,
in milliseconds.

Gordon sits upstream of every payment rail. We score the agent's intent before it commits, then sign the decision so it travels with the transaction.

  1. 01
    Intake

    Agent identity, counterparty, intent, tool calls, retrieved context.

  2. 02
    Evaluate

    Hard policy first: allowlists, caps. Then the fraud models.

  3. 03
    Decide

    Score, approve, block, or route to review.

  4. 04
    Settle

    Visa, Mastercard, tokens, Stripe, x402, Base / Solana, ERC‑8004.

View