Sycure.ai Get the assessment
Agent security assurance for payments

Your agents can move money. We work out how far.

We assess one agent workflow, then hand your engineers the control files that bind it. It runs on questions your own staff answer. We never touch your systems.

The boundary problem

Agents are already releasing holds and approving refunds

Ask what a given agent is permitted to do, and up to what limit. Usually the answer lives in someone's head.

WHAT ONE REFUND AGENT CAN REACH Read a transaction Issue a refund Release a held payment Change a payout account Refund above the limit Act without approval Call a tool added last week Reach the ledger directly Written down as permitted Technically reachable, never decided

The dashed boxes are not hypothetical. They are what the identity already permits, on a workflow somebody signed off months ago.

There is no list

Which actions, under whose identity, up to what limit. In most estates that has never been written down, and the answer sits with whoever built it.

Audit has nothing to test

An auditor can only test a boundary that was declared somewhere. Your second line has the same problem.

Then it acts

The agent does something nobody decided it could do. The model behaved. The permissions did not exist.

What comes back

The answer arrives as files your engineers can deploy

We take one workflow at a time. Three things come back, and all three are yours to keep.

1

A score

Bounded or not, as of today, scored on a fixed instrument. Run it again next quarter and the number is comparable.

2

A ranked gap list

What is missing, in the order it matters. Written plainly enough to be uncomfortable.

3

A configuration pack

Machine-readable control files for your gateways and pipelines. Your engineers deploy them. You own them outright.

How we assess without system access

The assessment is a questionnaire. That is the whole mechanism.

Nothing to integrate and nothing to install. It runs on answers your own people give.

We do not connect to your systems

Not during the assessment, not afterwards. We built it this way so your risk function can approve the engagement on its normal path, without raising an exception for third-party access.

No credentials No production access No cloud accounts No agent frameworks No customer data
Your organisation The people who run the workflow Your agents, gateways and identities Your engineers, who deploy the pack THE BOUNDARY Sycure A fixed set of structured questions The scoring instrument The configuration pack, written Answers Configuration pack Nothing else crosses

Two things move across the line, in opposite directions. No credential, no endpoint and no production data is one of them.

01

Your team answers a fixed set of questions

One agent workflow: what it is allowed to do, and what stops it. Whoever runs that workflow can answer without preparing.

02

We score it against a fixed instrument

The same instrument every time, so this quarter's score can be set against last quarter's. Where you cannot show evidence, the score records it as unevidenced. We do not give credit for intent.

03

You receive the configuration pack

Control files, the score and the gap list. Deployment is your engineers' work, through your own change process.

04

We score it again each quarter

Scopes widen. Someone adds a tool. The re-score says what moved since the last one.

Where it maps

Two regimes, mapped clause by clause

Every control we specify carries the clause it answers to. Your compliance team can check the mapping before anyone signs anything.

Saudi Arabia

  • NCA AICG-1:2026Draft AI Cybersecurity Guidelines, published 30 June 2026. Forty-two guidelines across four domains, advisory. They name planning, memory and tool-integration components without specifying how any of them should be configured.
  • NCA ECC-2:2024The mandatory baseline. Artificial intelligence appears four times, never as a control.
  • SAMANo AI text in the Cyber Security Framework. One clause in the Counter-Fraud Framework, requiring that an AI system be auditable. That is the whole of it.

European Union

  • EU AI ActGPAI obligations and penalties applied from 2 August 2025. High-risk obligations follow on 2 December 2027 and 2 August 2028.
  • DORAIn force since 17 January 2025. Register of information under Article 28(3), contractual minimums under Article 30(2).
  • ISO/IEC 42001Certifies a management system. It says nothing about any individual agent.
Where to start

Pick the workflow that would hurt most

One workflow, assessed and handed back as a configuration pack. The first one costs nothing. If it turns out your estate is in good order, we will say so and leave you alone.

Before you fill anything in

We will not ask for credentials or system access at any stage, and the first assessment costs nothing.

A person reads it and replies.