Product
A flight recorder for every agent transaction.
Capture authority and transaction evidence once, then use the same signed record for operations, disputes, audits, and risk analysis across every payment rail.
One schema across payment providers
Universal Evidence API
Send one canonical envelope whether an agent paid through a card API, bank rail, procurement platform, checkout protocol, internal ledger, or x402.
- Mandate, intent, offer, policy, execution, and receipt
- Inline, sidecar, and after-the-fact capture modes
- Rail-specific completeness requirements and recourse routing
Read the capture quickstart ↗Tamper-evident by construction
Signed evidence packets
Each artifact is content-addressed and bound into one packet root, preserving what the principal authorized and what every system reported at transaction time.
- SHA-256 artifact commitments
- Production Ed25519 signatures
- Durable packet storage with structured audit records
Evidence before opinion
Dispute cases and technical attribution
Investigators can reconstruct a transaction and distinguish merchant representation, agent interpretation, deployer controls, and execution-rail failures without changing the source evidence.
- Evidence-backed case drawer
- Notes, attribution, and redacted exports
- Rail-specific recourse workflow
Selective disclosure
Independent public verification
Create an expiring proof-only link that verifies packet commitments and signatures without exposing private mandates, prompts, payment instruments, or internal notes.
- Expiring verification links
- Public signature and packet-root checks
- No raw evidence payload disclosure
See how verification works ↗Decide before the agent pays
Pre-authorization enforcement
Preflight evaluates the active spend policy before execution and answers allow, review, or deny. It reserves budget against the daily and hourly limits, and the SDK commits or releases that reservation around the provider call. With no active policy the check fails closed.
- Merchant allowlist, per-transaction limit, daily budget, hourly velocity
- Review decisions above an approval threshold, approved by a human
- protectPayment wraps preflight, execution, and commit or release
Read the preflight guide ↗Roadmap · warranty on approved volume
Shield: stand behind the decision
Preflight already decides. Shield adds what the decision is worth: a signed authorization token bound to the packet, a latency budget that fits a checkout, and a warranty on the volume LedgerLens approves. The warranty is in design and is not available today.
- Cryptographically signed allow or deny token
- Warranty on approved transaction volume
- Merchant category (MCC) rules and a checkout latency budget
Talk to us about the design ↗Roadmap · payment provider integrations
Auto-clearing dispute network
The Stripe adapter captures evidence today. The next step is the return path: when a provider opens a dispute on a transaction LedgerLens already holds, assemble the packet and file it through the provider API without manual log work. Adyen is the second target.
- Inbound dispute webhooks from payment providers
- Automatic evidence assembly and submission
- Attribution reason codes on every filed case
Built for a production pilot
Protect the next transaction your agent initiates.