Stategram is internal controls for AI agents: it lets a company hand real money and contract decisions to agents, with every action bounded by policy, approved by a named person above the limit, and proven by a signed receipt. The AI can be wrong. The action cannot be.
The agent obeys.
The log shows it tomorrow.
The money left today.
Ten refunds, each under the €500 limit. Every one passes on its own. Only a running total sees the eleventh.
One wrong tool call is a real incident. A bad refund, proposal, or deploy is €74,200 and a customer call, not a failed unit test. The blast radius is production.
Your worst day becomes a number you chose.
Models can be tricked, drift, or simply err. It does not matter. Every action passes your policy before it runs. Inside the rules, the AI works free, no review queue, no checking department. Outside the rules, the action does not happen. Management owns the rules. Ops, devs, and vendors cannot bend them.
Ten refunds, each under the €500 limit. Every one passes on its own. Only a running total sees the eleventh. One daily total across every agent, every model, and every human. Your worst day becomes a number you chose.
The log shows what happened. The receipt shows it was allowed. The gate prevents; the receipt proves it. Signed by a layer nobody in the loop can edit. An auditor verifies it without trusting us, or you.
Everything above orchestrates or records. Stategram is the preventive control in front of them.
Every template arrives with the gates, rules, and approvers wired up, built from independently audited blocks. Start from known-good. The fastest way past the risk review is arriving with the control already on.
Agents auto-issue under €500, capped at €5,000 a day. Anything above either limit routes to a human in Slack.
Next: proposals, deployments, customer cases. Tell us which you need.
When someone asks who allowed the €74k refund, you hand them the receipt: what was tried, which rule fired, what evidence was checked, who approved. Signed at decision time, not reconstructed in hindsight.
It is also the screen you bring to the risk review. It tends to end the meeting.
Running agents already? Send a sanitized trace, get the memo back.
We can't rewrite history. Neither can anyone else.
We onboard your first agent. Two weeks with the founding architect: we embed with your operators, map one money-touching workflow, and ship it governed on a pilot deployment inside your perimeter. Limits, Slack approvals, and receipts live, verify tool in your hands, one-page memo for your risk team. Fail-closed by design. Then €499/mo hosted operations, or run it yourself from the installer repo.
One workflow per engagement. The second workflow is the second engagement. Production hardening (HA, failover, restore drills) scoped separately when you widen.
Book the auditArchitect-led launch plus ongoing tuning. We monitor quality, swap models, retire workflows that aren't earning their keep, and onboard new use cases as they emerge. Includes one new governed workflow per quarter.
Get a demoSelf-serve (shared ledger) from €49/mo is coming. The beta list below gets it first.
It remembers. State and counters live in the policy, so the daily total holds across every agent and every human.
It issues permits. Each action gets a permit for that action, now, from current state. Above a limit, a named person decides.
It cannot change quietly. Every policy is a signed version. A change is a new version with its own record, never a silent edit.
It stays readable. A risk officer can read it without an engineer, and the owner signs what it means.
Agents connect through MCP or one REST call. Decisions in under 100ms. Stategram approves; your systems execute.
If we hold the controls for your AI agents, we have to hold ourselves to the same standard. Hosted in Germany, encrypted end-to-end, with signed receipts that can be verified without trusting our servers.
Falkenstein, Germany (network zone eu-central). All data, signing keys, and receipts stay in the EU on infrastructure certified to ISO/IEC 27001:2022, BSI C5 Type 2, KRITIS-V / NIS-2, and PCI DSS.
TLS 1.3 with HSTS for every API call. AES-256 at rest with hardware-backed envelope encryption for state, receipts, and backups. Workspace-scoped API keys.
Standard processor DPA on request. Receipts are designed to support EU AI Act Article 12 record-keeping for high-risk AI systems.
Every decision is written where it can't be edited, denials included. Receipts are signed at decision time and can be verified against the ledger without trusting our servers.
SOC 2 Type II is on the roadmap. Read the full security & compliance overview · Contact [email protected] for disclosures.
Silver Sepp has spent twenty years on systems where a mistake costs money: the in-house trading platform of a global commodity trader (physical and paper) and, before that, Estonia's national court information system and its criminal case registry.
Since 2022 he has built Toolblox, money workflows drawn as state machines and compiled from building blocks audited by external smart contract security firms. On it, 4,500 registered users have drawn 6,000 workflows: stablecoins, funds, token-based communities, repayment schemes. He has authored hundreds of them himself.
Since 2024 he has been building agents with their own wallets and spending rules, before agent payments were an industry topic. Stategram is that work, built for companies whose agents touch money.
You could. Teams could also write their own identity provider, and almost none do. Identity tools verify who the actor is. Access tools decide which doors open. Nobody builds those in-house, because the value was never the code. It is being one layer outside the team it constrains. A limit your own service owns is a limit your own service can quietly raise. Ours cannot be raised by the people it applies to, and the receipt says so.
Those check one call, with no memory, inside your own stack. Stategram holds state across actions and actors, sits outside the team it constrains, and signs evidence an outsider can verify.
Policy made mandatory. Proof by default. Live in two weeks.