Skip to content
Brakeproof
NewRed-team tests

Stop AI agents before they break production

Brakeproof sits between your agents and the systems they touch. Safe calls pass instantly. Risky ones wait for a named human, with a snapshot to undo from. Forbidden ones never run. Budgets stop runaway spend, and red-team tests find weak spots before attackers do.

Works with MCP, Claude Code, OpenAI Agents SDK, LangGraph, the Claude Agent SDK, and Python or TypeScript code.

Action firewall. An AI support agent working in production lists and searches customers, which Brakeproof allows instantly. It then tries to update customer 42: the call is paused, a snapshot is taken and a human approves it. Next it runs a DELETE that would remove 372 rows: a Brakeproof AI brief explains the risk, a snapshot is taken first and a human approves it. Finally it tries DROP TABLE customers, which is blocked by policy.

Scene 1 of 6 · Example data

Works with the agents you already run

  • MCP
  • Claude Code
  • OpenAI Agents SDK
  • LangGraph
  • Claude Agent SDK
  • Python
  • TypeScript

Names are trademarks of their respective owners. No endorsement implied.

The problem

Agents act in seconds. Humans find out later.

AI agents now refund customers, change databases, deploy code and spend money on their own. Most teams can watch what an agent did. Few can stop it before it happens.

  • 9 sto lose production

    A coding agent deleted a production database, and its backups

    An AI coding agent at PocketOS wiped the company's production database and backups in nine seconds. No one approved the command.

    Source: PocketOS incident, April 2026

  • 0effect of a code freeze

    An agent ignored an explicit code freeze

    During a declared code freeze, an AI agent deleted SaaStr's database anyway. Instructions in a prompt are not a control.

    Source: SaaStr incident, reported by Jason Lemkin, 2025

  • ~24 hbilling lag

    Bills arrive a day after the money is spent

    Cloud cost data typically lands up to a day late. An agent in a loop can spend for hours before anyone sees a number.

    Source: Cloud provider billing documentation

  • 22–76%of agent failures

    “Done” is not the same as done

    Research published in 2026 traced 22–76% of agent failures to false success claims: the agent said the work was finished when it was not.

    Source: Agent failure research, 2026

How it works

A checkpoint on every tool call

Brakeproof is a drop-in proxy or SDK hook. Your agent keeps its framework, prompts and tools; its actions just pass a checkpoint first.

  1. 01

    Intercept

    A drop-in MCP proxy, SDK or framework hook sees every tool call before it reaches your database, API or shell.

  2. 02

    Decide

    Policies and a risk score decide in milliseconds: allow, pause for a human, or block outright.

  3. 03

    Snapshot

    Before a risky call runs, a restore point is taken. If the snapshot fails, the call does not run.

  4. 04

    Approve on web or phone

    A named person sees the exact change, the risk and the snapshot, then approves or denies.

  5. 05

    Prove

    Every action, decision and approval is written to a hash-chained ledger with signed checkpoints.

Allow

Reads and low-risk calls run with no added friction.

Pause

Risky calls wait for a named human, with a snapshot first.

Block

Forbidden calls never run. The agent is told why.

New · Red-team tests

Attack your own agent before someone else does

Brakeproof sends your LLM app or agent the same tricks real attackers use, judges every reply, and shows you what got through and how to fix it.

  1. Point it at your app or agent

    Any HTTPS endpoint your agent answers on, or an OpenAI-compatible endpoint. Use a staging copy when you can.

  2. Pick how hard to attack

    Start with Quick, about 22 attacks on the most common failures. Then run a full scan mapped to a framework, or pick your own mix.

  3. See what got through, and how to fix it

    A pass rate, results per weakness, every attack with the reply and the reason it failed, and a fix for each one. Failures become findings in your risk score.

Example report. A Quick check found that 4 of 22 attacks got through.

Scans you can run

  • Quick
  • OWASP Top 10 for LLM apps
  • OWASP Top 10 for agentic apps
  • NIST AI RMF
  • MITRE ATLAS
  • Custom

What it tries

  • Prompt injection
  • Jailbreaks, including multi-turn
  • Fake system messages
  • Encoded requests (Base64, ROT13)
  • Role-play personas
  • Personal data (PII) leaks
  • System prompt and secret leaks
  • Cross-customer data access
  • Actions nobody asked for
  • SQL and shell injection
  • Toxic and harmful output

Your AI key, your bill

Runs use your own Gemini, Claude or OpenAI key. You pay your provider directly.

A budget cap on every run

The run stops when it reaches your cap. A Quick check usually costs less than a dollar.

Consent first

You confirm you own or may test the system. The consent is kept in the ledger.

Capabilities

Brakes, airbags and a black box

Everything Brakeproof does today. Each card shows whether it is available now or still in beta.

  • Available

    Action firewall

    Every tool call passes through Brakeproof. Safe actions pass instantly. Risky ones, such as delete, refund or deploy, are paused, snapshotted and sent to a named human. A rule like DROP TABLE is blocked outright.

    • Allow, pause or block per policy
    • Snapshot before the call runs
    • MCP proxy, Python and TypeScript SDKs
  • Available

    Spend brake

    Set budgets on LLM token spend per agent, per team or for the whole company. When an agent goes over, it is paused right away, not discovered on next week's bill.

    • Daily or monthly budgets
    • Warning before the limit
    • Automatic pause at the limit
  • Available

    Proof of work

    When an agent says “done”, Brakeproof checks the real system, such as Stripe, Postgres or GitHub, to confirm the change actually happened.

    • Read-only connectors
    • Flags false success claims
    • A truth rate for every agent
  • Beta

    Mobile app

    Approve or deny from your phone with Face ID or a fingerprint. Each decision is signed by the device. Stop any agent with the kill switch.

    • iOS and Android
    • Signed approvals and an inbox
    • Kill switch for any agent
  • Available

    Tamper-evident ledger

    A record of every action, decision and approval that shows if anyone changed it. Export it any time.

    • SHA-256 hash chain
    • Signed checkpoints
    • CSV and JSON export
  • Available

    Brakeproof AI

    Plain-English approval briefs, risk flags, anomaly alerts, policy drafts, incident reports and a read-only chat. AI advises, rules decide: it never approves anything.

    • Uses your own AI key
    • Gemini, Claude or OpenAI
    • Only redacted data is sent
  • Available

    Red-team tests

    Brakeproof attacks your own LLM app or agent before real attackers do, then shows what got through and how to fix it.

    • Prompt injection and jailbreaks
    • Data, PII and prompt leaks
    • OWASP and other framework presets
  • Available

    Security sensors

    Read-only sensors check your AWS account, GitHub, websites and mobile app builds. Every finding rolls up into one risk score, together with agent behaviour.

    • AWS through a read-only role
    • Websites you verify you own
    • APK and IPA app files
  • Beta

    Deploy to your cloud

    Ship your agent with the guard built in, to Docker, Hugging Face Spaces or AWS ECS Fargate. It runs in your cloud account. We do not host your agents.

    • Guard and kill switch built in
    • Your code and secrets stay with you
    • You pay your cloud provider directly

Also built: team roles (owner, admin, approver, viewer) and docs inside the app.

Brakeproof is in private preview. Beta means built and still in testing.

Prevention, not just monitoring

Monitoring tools show you the crash. Brakeproof stops it.

Observability is useful. It is also, by design, after the fact. Keep your monitoring; add a control that acts first.

Monitoring tools compared with Brakeproof
Monitoring toolsBrakeproof
When it actsAfter the action, in logs and tracesBefore the tool call runs
A destructive queryRecorded once it has runPaused, snapshotted, sent to a named person
A forbidden actionAlert after the factBlocked by policy; the agent is told why
Runaway spendSeen on the bill, often a day laterAgent paused at its budget
“Task complete”Taken at face valueChecked against the real system
Prompt injectionFound by users or attackers in productionFound first by red-team tests you run
EvidenceMutable logsHash-chained ledger with signed checkpoints

Mobile app · Beta

Approve from anywhere. Stop anything.

Agents work at 3 a.m. The person who can say yes should not need a laptop. A push notification opens the exact change, its risk and its snapshot.

  • Approve or deny with Face ID

    Each decision is signed with a key held on your device, and the signature is kept in the ledger.

  • A kill switch for any agent

    Stop an agent from any vendor in one step, wherever you are.

  • Everything needed to decide

    The tool, the arguments, the rows affected, the matched policy and the snapshot, on one screen.

  • One inbox

    Pending approvals, unusual-activity alerts and your security risk, in one place.

The iOS and Android apps are built and in testing (beta). They are not in the app stores yet. Web approvals work today.

Security and trust

Built to be the evidence, not just the alarm

We store metadata and redacted previews, never more customer data than we need. Every decision leaves a record that cannot be quietly edited.

Read the security overview
  • Available

    Tamper-evident ledger

    Every action, decision and approval is appended to a per-organisation SHA-256 hash chain with signed checkpoints. Change one entry and verification fails.

  • Beta

    Signed approvals

    Mobile decisions are signed with a P-256 key that never leaves the device. The server verifies the signature before it counts.

  • Coming soon

    Regions: US, EU, Gulf

    Hosted regions so data stays where your compliance team needs it, with region pinning on Enterprise.

  • Coming soon

    Self-hosted option

    Run the control plane inside your own network for full control over data and keys.

Pricing

Flat per agent. Never per event.

A busy agent should not produce a surprise bill, including ours.

Compare plans

Early-access prices

Free

Put brakes on your first agents.

$0forever

  • 2 agents
  • Action firewall
  • Web approvals
  • 1 quick red-team test per month
Join the waitlist for the Free plan
Most teams start here

Team

For startups running agents against production.

$149per month

  • 10 agents
  • Everything in Free
  • Spend brake
  • Mobile app + kill switch (beta)
  • Brakeproof AI (your own key)
  • Quick red-team tests
  • 30-day ledger
Join the waitlist for the Team plan

Business

Proof, security testing and control across teams.

$699per month

  • 50 agents
  • Everything in Team
  • Proof of work
  • Full red-team scans (framework presets)
  • Security sensors + risk score
  • Deploy to your cloud (beta)
  • Roles: owner, admin, approver, viewer
  • Audit exportComing soon
Join the waitlist for the Business plan

Enterprise

Unlimited agents and custom terms for large teams.

From $30kper year

  • Unlimited agents
  • Everything in Business
  • SSOComing soon
  • Self-hostedComing soon
  • Region pinningComing soon
  • SLAComing soon
Talk to us for the Enterprise plan

MSP $49 per client / month

Coming soon

For managed service providers running agents for many customers. One multi-tenant console for every client.

Join the waitlist for the MSP plan

FAQ

Questions teams ask first

How is this different from observability tools?

Observability tools record what an agent did after it happened. Brakeproof sits in the path of every tool call, so it can pause or block an action before it runs, take a snapshot first and ask a named person to decide. It also caps spend and checks “done” claims against the real system.

Do I have to change my agent's code?

Not for MCP. You wrap the MCP server command with the Brakeproof proxy in your client config. For custom agents, use the Python or TypeScript SDK or one of the framework hooks. For Claude Code, add a PreToolUse hook.

What happens if Brakeproof is unreachable?

Each policy chooses. The default is to fail closed: risky calls are blocked while the control plane is down. A call that needed approval is never forwarded without one.

What is a red-team test?

Brakeproof sends your own LLM app or agent realistic attacks, such as prompt injections, jailbreaks and requests for other people's data, and judges every reply. You see what got through and how to fix it. You confirm that you own or may test the system before every run, and each run has a budget cap.

Do you store our customer data?

No more than we need. We store metadata and short previews of tool arguments, with emails, card numbers, tokens and keys masked before storage. Previews are capped at 2 KB.

Is it available today?

Yes, in private preview. The action firewall, spend brake, proof of work, ledger, Brakeproof AI, red-team tests and security sensors work today. The mobile app and cloud deploys are in beta. Join the waitlist and we will reach out as we open access.

Which agents does it work with?

Anything that calls tools through MCP, agents built with the OpenAI Agents SDK, LangChain / LangGraph or the Claude Agent SDK, Claude Code through a hook, and your own code through the Python or TypeScript SDK.

Put brakes on your agents before the next incident

Join the waitlist for early access. Setup takes about five minutes.