Agent Cost Governor
Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
Product details →NewReadiness Kit v0.1 — our open-source agent attack pack and evaluation harness — ships on GitHub on 18 October 2026.Readiness Kit v0.1 — 18 Oct 2026.Open source →
Product 05 · Design partners wanted — Q2 2027
Audit-grade records from your agents — generated, mapped and accepted, not improvised the week before the audit.

The problem
Colorado wants three-year records and 30-day explanations from January 2027; the EU AI Act's lifetime logging is deferred but unchanged; ISO/IEC 42001 certificates tripled in four months and the largest buyers now require it from AI suppliers. Compliance platforms collect documents; they do not generate evidence of model behaviour. The Pack records every agent step tamper-evidently and exports what each framework asks for.
3 years
of records and 30-day explanations for consequential AI decisions under Colorado SB 26-189, effective 1 January 2027.
350+
ISO/IEC 42001 certificates, up from about 100 four months earlier; Microsoft requires it from 'sensitive use' AI suppliers.
SOC 2
has no AI-specific controls; auditors are improvising evidence requests for agent behaviour.
The place nobody else holds
One test-and-evidence pack per domain. Rules push buyers hardest in insurance, banking, hiring, manufacturing, pharma and the public sector, and each asks for different records; governance platforms sell inventories, compliance platforms collect documents, and nobody sells the pack per domain to mid-market deployers. The Lab publishes the packs domain by domain.
From the Lab's October 2026 review of the market — the six open places, and how we earn them.
What it does
An SDK or MCP proxy writes every agent step to a hash-chained, signed log with optional external anchoring — intent, policy evaluation, human approval, execution, effects, context, code and delegation provenance.
Model, prompt and tool versions and the human approvals on each decision travel with the record, so an explanation can be reconstructed months later.
The Gate's harness re-run on a schedule, with results in the same log — continuous evidence rather than an annual snapshot.
An Article 12-style lifetime log; a Colorado-style decision record with explanation and human-review trail; change and incident records; and a mapped evidence pack.
ISO/IEC 42001 Annex A, CSA AI Controls Matrix, NIST AI RMF, EU AI Act Annex IV and the OWASP Agentic Top 10 — one record, several request lists satisfied.
Pushes to Vanta or Drata, or lands in an auditor's request folder. We build the format auditors accept; the hashing is the easy part.
What you receive
Who buys it
Pricing
Per estate — annual
$12,000–30,000 / year
Recorder, scheduled evaluations, four exports, one platform integration.
Ask about this tier'Run with evidence' retainer tier
retainer + evidence
For clients already on Run and Improve; priced in the order.
Ask about this tierPrices in USD and exclusive of applicable taxes; Indian clients are invoiced in INR with GST. Window: Build February–April 2027 on the Governor's event log · first audits mid-2027. Our public commitment for this product: We will not sell the Pack beyond design partners until an accredited auditor has accepted it in a real audit. That acceptance is gate five, due 30 June 2027, and it will be reported here.
FAQ
Vanta and Drata collect and track evidence you give them. Evidence of what your agents did — the decision, the approval, the model version — has to be generated by something sitting next to the agent. That is the Pack; it then pushes into Vanta or Drata.
Because the format an auditor accepts is the product, and that cannot be designed without an auditor in the room. Design partners get the recorder at cost and a say in the exports.
Works with
A 30-minute call with the engineers who build it, no deck, no charge. If it fits, a fixed-price proposal within 48 hours.