Enforce, do not merely observe
Policies can deny dangerous prompts, outputs and tool calls before execution.
AgentRiskLayer is operated by Guillaume Strohecker. The company is building a practical security layer for teams that need to know what an AI agent can do, stop unsafe actions and preserve evidence after every decision.
An agent can read private data, call tools, move money, publish content and create binding actions. Security must therefore cover the full path from untrusted input to real-world side effect.
Policies can deny dangerous prompts, outputs and tool calls before execution.
Human approval is signed, expiring and tied to the exact transaction being authorised.
Declared, observed, reproduced and retested evidence remain separate, with explicit limits.
Local tools exclude source contents and raw testing transcripts from uploaded evidence by design.
AgentRiskLayer is live with managed PostgreSQL, Stripe billing, transactional email, workspace roles, runtime enforcement and signed evidence. Independent penetration testing and formal certifications are not claimed until completed.