Agent Readiness Gate
The pre-deployment gate: attack pack, evaluation harness, cost baseline, permission audit, Agent BOM — one Evidence Report.
Product details →NewReadiness Kit v0.1 — our open-source agent attack pack and evaluation harness — ships on GitHub on 18 October 2026.Readiness Kit v0.1 — 18 Oct 2026.Open source →
Product 02 · In build — pilots from December 2026
A budget the agent cannot exceed — per task, per step, per model — enforced before the invoice, not after.

The problem
Gateways cap spend per key, team or month. Cloud billing alerts arrive about a day later. Neither knows what a task is — so a single agent can retry, escalate models, spawn sub-agents and burn a quarter's budget in an hour while every dashboard stays green. The Governor sits in the loop and knows the task.
>5×
rise in inference cost per agentic workflow through 2028 — 'unbounded costs' is now Gartner's phrase.
$50,000
burned by one accounting agent in under an hour, from 15,000 API calls, with no attacker involved.
~24 h
lag on cloud billing alerts, while the actions that caused the spend are in CloudTrail within minutes.
The place nobody else holds
Cost per finished task as test evidence. Of about 35 testing and assurance providers reviewed in October 2026, one names runaway cost as something it tests. The Gate measures it on real traffic and the Governor enforces the ceiling — a reliability result with a number, not a FinOps afterthought.
From the Lab's October 2026 review of the market — the six open places, and how we earn them.
What it does
A budget attached to the unit of work your business recognises — a resolved ticket, an invoice, a document, a case — not to an API key. When the ceiling is reached the task halts or degrades gracefully, and the owner is told why.
Maximum steps per task, maximum tool-call depth, maximum child agents. The controls that would have stopped the documented spawn storms and tool-chain amplification attacks that inflated single queries by hundreds of times.
Agents may not silently escalate to a larger model. Escalation is a policy decision with a budget, logged, not a prompt's whim.
Enforcement lives in the gateway, not in client code the agent can route around. Per-agent cloud accounts with CloudTrail-driven kill switches for the actions that cost money outside the model.
Client-side token counts reconciled against the provider's billing export every night; drift reported, because client counters and invoices have been shown to disagree by multiples.
Before and after, per agent and per task type, in a page your CFO reads without a glossary. The same event log feeds the Compliance Evidence Pack later.
What you receive
Who buys it
Mapped to
Built on open engines: LiteLLM, Open-source MCP gateways, AWS CloudTrail — under Rainkernel's corpus, rubric, report generator and BOM emitter.
Pricing
Inside the Run and Improve retainer
included
The retainer runs $8,000–15,000 a month; the Governor and its weekly report are its headline deliverable.
Ask about this tierStandalone — per estate
$2,500–5,000 / month
For agent estates Rainkernel did not build. Deployment inside your cloud; price by number of agents and gateways.
Ask about this tierPrices in USD and exclusive of applicable taxes; Indian clients are invoiced in INR with GST. Window: Build November–December 2026 · live in paying estates by January 2027. Our public commitment for this product: By 31 January 2027 the Governor is live in paying estates with published before-and-after cost per task and zero unbounded incidents — or we say so here.
FAQ
Gateway budgets are per key, team or month. They cannot tell a $4 task from a $4,000 one until the month's budget is gone. The Governor attaches the budget to the task and enforces it on every step, server-side.
The policy check is a local decision on the proxy — single-digit milliseconds. Reconciliation runs nightly, off the hot path.
Anything that speaks HTTP to a model or an MCP server: OpenAI, Anthropic, Bedrock, Azure OpenAI, Vertex, self-hosted. Framework-agnostic because it sits on the network, not in your code.
Works with
A 30-minute call with the engineers who build it, no deck, no charge. If it fits, a fixed-price proposal within 48 hours.