AI Payment Control Plane

The missing safety layer between AI agents and your money.

AI assistants draft payouts in plain language - "pay 850 USDC to Anna." APG checks every request against your policies, scores its risk, routes it for human approval, and executes only through a backend guard. The AI prepares; the backend, not the AI, moves the money.

• AI can draft, never execute - approvals and execution guards are enforced by the backend

• Policy + risk + approval - on every payout, before any money moves

• Immutable audit trail - who, what, and why for every money movement

• Crypto & fiat - one control layer across providers and rails

Early access - testnet today, real-money pilots opening soon.

We'll only use your email to contact you about access. Privacy

How APG works

A request becomes money movement only after it passes every control. The AI prepares; the backend decides.

  1. 1

    Draft

    AI

    An AI assistant turns a plain-language request - or a CSV/PDF import - into a payment intent. It drafts only.

  2. 2

    Policy

    Backend

    Deterministic policy engine checks the intent against your organization's rules. Allow, block, or require approval.

  3. 3

    Risk

    Backend

    Transaction risk is scored - new recipient, amount thresholds, velocity, duplicates, off-hours.

  4. 4

    Approval

    Human

    A person approves sensitive payouts. The creator can't approve their own. Execution stops here until they do.

  5. 5

    Execute

    Backend guard

    Only after every gate passes, a backend execution guard moves the money through the provider - idempotently.

  6. 6

    Audit

    System

    Every decision and action is written to an immutable trail: who, what, and why for each money movement.

The AI appears once - at step 1. It can never approve, execute, or move money on its own.

Ask in plain language. Get a draft, not a payment.

The assistant prepares a payment intent and stops. A human approves before anything moves.

Pay 850 USDC to Anna Petrova for the March design work.
I matched Anna Petrova in your contacts and prepared a draft payment intent. It needs your approval before it can execute.
Payment intent · draftAwaiting approval
Recipient
Anna Petrova (contact)
Amount
850.00 USDC
Policy
Requires approval (over $500)
Risk
Low · known recipient
The AI stopped here. Execution is blocked until a human approves.

Illustrative example.

Import a spreadsheet. Review a queue, not a pile of payments.

APG extracts rows, matches contacts, and flags anything ambiguous - then builds an approval queue.

contractors_march.csv· 5 rows
  • Anna Petrova

    850.00 USDC

    Draft ready
  • BrightLabs LLC

    1,200.00 USDC

    Draft ready
  • M. Cohen

    430.00 USDC

    Needs review
  • Studio Nord

    2,000.00 USDC

    Draft ready
  • (unknown payee)

    75.00 USDC

    Unresolved
3 drafts ready · 2 held for review0 executed - awaiting approval

Illustrative. Ambiguous and unresolved rows are held, never guessed - and nothing executes without approval.

One control layer before money moves

Requests never reach your payment rails directly. Everything passes through APG.

AI agents
ERP & systems
People
APG control plane
PolicyRiskApprovalExecution guardAudit

Deterministic backend services. The AI can draft a request, but it can never move past this layer on its own.

Payment rails - crypto & fiat providers

Built for finance teams that can't take chances

The controls your auditor asks about - enforced by the backend, not promised by the AI.

Separation of duties

The person who drafts a payout can't approve their own. Roles are enforced server-side.

Human approval required

AI can't approve or execute. A person signs off on sensitive payouts before any money moves.

Immutable audit trail

Every decision and action is recorded - who, what, and why - for each money movement.

Deterministic enforcement

Policy and risk verdicts come from backend services, every time - never a probabilistic model.

Idempotent execution

Provider timeouts and retries can't double-pay. Execution is guarded and idempotent.

Organization isolation

Data is isolated per organization at the database level, with role-based access.

Honest about maturity: testnet today, real-money pilots gated on documented controls. No autonomous payments - ever.