A fleet of agents is a systemic risk. Someone has to hold the other side of the table.
A single agent with a payment tool is a contained risk. A fleet of them sharing rails and running unattended is not. One prompt injection, one bad model update, one compromised agent can move real money at machine speed. AgentSnap is the layer that says no before it does.
Why an enforcement layer, not another dashboard
Every serious agent stack already has tracing, evals, and dashboards. They answer "what happened", and they answer it well. None of them can answer "did the money move?" with a no. That question needs a component that sits in front of the action, holds the policy, and fails closed. It cannot belong to the vendor that builds and profits from the agents, because that is the auditor auditing itself. And it cannot live in someone else's cloud, because regulated buyers will not ship transaction flows out of the building.
So AgentSnap is one self-hosted process, independent of the agent vendor, deterministic in every decision, with an audit chain the risk function can file. Monitoring is a feature. Evidence is the product.
How we operate
- Enforce, then observe. A control that cannot be the reason an action does not happen is advice. We build controls.
- Measurement honesty. Modeled numbers say modeled. Empty report sections render as checked-and-empty. The evidence map never says more than "Evidenced". No invented customers, metrics, or testimonials, ever.
- Sales-first, build on demand. Nothing gets built ahead of a named buyer. The roadmap on the product page is labeled roadmap because it is.
- Generalize by contract, not by customer. A fleet is a policy file. We do not do company-specific builds.
- The console is the product surface. Every demo runs on the real web console over real traffic. Nothing in a demo is a mockup.
Where the code came from
The codebase began as Aegis, built for the Amex Hackathon 2026 challenge "Governance Layer for Financial Agents", where it reached the top 6. It was a working control plane before it was a company: a fail-closed policy enforcement point in front of seven card-lifecycle agents, with spend caps, human-in-the-loop holds, a kill switch, Ed25519 agent identity, a hash-chained audit log, fleet economics, an agent dossier, a fleet report with a regulator evidence map, and a two-screen demo. It was adopted wholesale as the AgentSnap product on 18 August 2026 and de-branded: the demo issuer is now the fictional Meridian, and no real institution appears in demo data.
We say this openly because it is the strongest thing about the product. The build survived judges before it had a landing page.
The original AgentSnap CLI (snapshot and diff for a single agent's configuration) is open source and stays that way. The control plane is commercial and self-hosted.
The founder
Aarin Sheth
Founder · IIT KanpurSolo founder. Built Aegis for the Amex Hackathon 2026 and turned it into AgentSnap. Writes the policy engine, the console, the tests, and the emails. If you book a demo, this is who shows up.
Where we are, honestly
Pre-customer. We are onboarding a small number of design partners: teams running agents that touch money, customers, or records, who are stuck at the point where risk or security asks "and what stops it?". Free for eight weeks, deployed in your environment, your fleet policy written with you, your first agent integrated by us, and a weekly fleet report your risk function can actually file. If you are not a fit we will say so on the call.