Open runtime governance for AI agents

Let agents act. Decide what they're allowed to do, the moment they do it.

Deadlatch is an open stack of three primitives. Purse enforces what an agent can do, blackbox proves what it did, Tripwire watches for what slipped through.

You can't trust a black box to govern your black box.Every part is open, inspectable, and verifiable outside Deadlatch. No platform to take on faith.
enforce
Purse
prove
blackbox
watch
Tripwire
DEADLATCHlive consoleenforcing
max/action $100max/day $200approval > $50allow api.stripe.com, *.aws
agent → spend $12.00 to api.stripe.com
allowwithin policy
daily spend$0.00 / $200.00
blackbox · hash chainprove
verify() ✓ ok
tripwire · watchdetect
0actions caught
84
receipts on the playground chain
seq 83
anchored in log2025-1.rekor.sigstore.dev · entry 135312425 · 1 day ago
3 witnesses
cosign every anchor, none of them ours

Press a button, a real broker decides, and you get a receipt like this. No sign-up. Try it live ↗

Three primitives, one control loop

Prevent the wrong action. Prove what happened. Detect what slipped through.

Each is a small, open package you can adopt on its own.

The control loop

One action, routed through all three.

Purse decides it, blackbox records it, Tripwire watches the outcome.

1 · enforce
Purse decides it
caps, allowlist, approval out of band
2 · prove
blackbox records it
hash chained, head anchored outside
3 · watch
Tripwire watches the outcome
flags the wrong action inside one interval

You can't trust a black box to govern your black box.

01

Open, not a platform you take on faith

Every primitive is source you can read and run. The thing enforcing your policy is not itself a mystery box.

02

Verifiable outside the tool

The audit chain checks out with plain SHA‑256, on your machine, without Deadlatch in the loop. Proof you hold, not proof we assert.

03

Composable, adopt one at a time

Start with the one primitive you need this week. Grow into the full loop when you're ready. No rip‑and‑replace.

Why now

The rest of the field is arriving at the same three controls.

Independent security guidance and a US Senate draft point at the same loop.

SANS · practitioner ↗

"Your AI agent is an easily confused deputy. Cloud security needs a credential broker."

enforce · a credential broker is Purse
AI AGENT Act · US Senate draft

Calls for scope-limited delegation credentials, real-time revocation, and auditable records.

enforce + prove · grants, revocation, receipts

The Senate text is a discussion draft, not law. Both sources are named so you can weigh them yourself.

Evidence you can hand an auditor

The controls the new AI rules ask for. As proof you can verify yourself.

Human oversight, record-keeping, and monitoring. Deadlatch gives you the actual controls, open, and evidence an auditor can check without trusting us.

Run the free audit on your own setup ↗

Human oversight of risky actions
EU AI Act · Article 14
→
Purse
enforce
Automatic, tamper-evident record-keeping
EU AI Act · Article 12
→
blackbox
prove
Ongoing monitoring for unsafe behaviour
NIST AI RMF · Manage
→
Tripwire
watch
No compliance checkbox to take on faith. You get the open controls and evidence your auditor can verify outside the tool.Aligned with the EU AI Act and the NIST AI Risk Management Framework, not a certification.
Start with one

One npm install. No account, no platform.

Pick the primitive that solves today's problem. Each runs on its own, zero dependencies.

Then wire the action through it. Prevent. Bear witness. Track.