01Borrowed authority
The assistant inherits access nobody granted it.
It was wired up with a service credential so it would 'just work'. Now it reads every row a human never could, and no ticket records the moment that started.
Software that acts on its own is already inside your stack — booking payments, reading customer records, calling tools you never reviewed. CuriousDevs puts a decision checkpoint in front of every one of those actions, so autonomy stays answerable.
Built as one stack
There is no stack trace for a decision. The system runs green while doing precisely the wrong thing, and you find out from a customer, a regulator or a bank statement.
01Borrowed authority
It was wired up with a service credential so it would 'just work'. Now it reads every row a human never could, and no ticket records the moment that started.
02Instruction hijack
The page it retrieved carries a sentence written for the model, not the reader. The agent obeys. Your prompt never mentioned any of it.
03Quiet data exit
One integration widens its payload during an upgrade. Identity fields ride along to a vendor you never mapped, and the export looks routine in the logs.
04Machines in motion
The task was under-specified, so the fleet resolved the ambiguity itself. Every individual choice was defensible; the combined outcome was not.
The missing control
Four familiar categories, one shared blind spot: none of them stand between intent and execution while the system is live.
Recorded
They narrate the incident after the money left. Useful for the write-up, powerless at the moment of action.
Suggested
Text inside a prompt is persuasion. A long context, a clever input or a bad day is enough to talk the model out of it.
Snapshot
A binder describing last quarter's system. Your data flows changed on Tuesday and the evidence never caught up.
Approximate
Asking a model to police a model doubles both the uncertainty and the bill, and still yields no reproducible verdict.
How it Works
Pre-Production · Control Plane
Adversarial · Security · Compliance
Sandboxed reconstruction
Risk & compliance scoring
From observed failure modes
Reusable rules, deterministic, not prompt-based
Shift-left risk discovery
↓ Unified Policy Engine · Deploy
Runtime · Data Plane
Detect · Allow · Deny · before execution
Inline, deterministic, real-time
Every signal observed continuously
Full audit trail on every decision
Production tightens enforcement
No redeployment. No system modification.
01 · Pre-Production
Data maps and adversarial evals run against a sandboxed reconstruction of your agents and pipelines.
02 · Pre-Production
Behavioural baseline established. Risk and compliance scores generated from observed failure modes.
03 · Pre-Production
Failure traces become deterministic policy signatures, reusable across every agent and fleet.
04 · Runtime
Every tool call, LLM call, user input and machine command passes through the enforcement layer in real time.
05 · The Loop
Evidence exports map to SOC 2, ISO 27001 and DPDP. Telemetry feeds back and enforcement tightens continuously.
The path, 2026 to 2030
Gateway, SDKs and the rule engine ship where engineers can read them. Trust in security software is earned by being inspectable.
Anyone can see their exposure in two minutes. Teams that like the answer stay for the automation underneath it.
India's obligations become enforceable. We intend to be the boring, obvious choice by the time procurement starts calling.
Mission command for mixed fleets, standing on the checkpoint and evidence layers already in production.
When a board asks how they can trust machines acting without a human in the loop, we want the answer to be a product, not a policy memo.
What we believe
“Any action a machine takes on its own should have a name attached, a reason recorded, and someone who can answer for it.”
Bring one workflow you are nervous about. We will show you exactly where the checkpoint goes and what it would have stopped last month.
Questions
Short answers on how this runs, what it costs you in speed, and what you can hand to an auditor.
A decision checkpoint for software and machines that act on their own — it approves, trims, escalates or refuses each action, and keeps a signed record of why.