Stop AI agents before they break production
Brakeproof sits between your agents and the systems they touch. Safe calls pass instantly. Risky ones wait for a named human, with a snapshot to undo from. Forbidden ones never run. Budgets stop runaway spend, and red-team tests find weak spots before attackers do.
Works with MCP, Claude Code, OpenAI Agents SDK, LangGraph, the Claude Agent SDK, and Python or TypeScript code.
Action firewall. An AI support agent working in production lists and searches customers, which Brakeproof allows instantly. It then tries to update customer 42: the call is paused, a snapshot is taken and a human approves it. Next it runs a DELETE that would remove 372 rows: a Brakeproof AI brief explains the risk, a snapshot is taken first and a human approves it. Finally it tries DROP TABLE customers, which is blocked by policy.
Scene 1 of 6 · Firewall · Example data
Works with the agents you already run
- MCP
- Claude Code
- OpenAI Agents SDK
- LangGraph
- Claude Agent SDK
- Python
- TypeScript
Names are trademarks of their respective owners. No endorsement implied.
The problem
Agents act in seconds. Humans find out later.
AI agents now refund customers, change databases, deploy code and spend money on their own. Most teams can watch what an agent did. Few can stop it before it happens.
9 sto lose production
A coding agent deleted a production database, and its backups
An AI coding agent at PocketOS wiped the company's production database and backups in nine seconds. No one approved the command.
Source: PocketOS incident, April 2026
0effect of a code freeze
An agent ignored an explicit code freeze
During a declared code freeze, an AI agent deleted SaaStr's database anyway. Instructions in a prompt are not a control.
Source: SaaStr incident, reported by Jason Lemkin, 2025
~24 hbilling lag
Bills arrive a day after the money is spent
Cloud cost data typically lands up to a day late. An agent in a loop can spend for hours before anyone sees a number.
Source: Cloud provider billing documentation
22–76%of agent failures
“Done” is not the same as done
Research published in 2026 traced 22–76% of agent failures to false success claims: the agent said the work was finished when it was not.
Source: Agent failure research, 2026
How it works
A checkpoint on every tool call
Brakeproof is a drop-in proxy or SDK hook. Your agent keeps its framework, prompts and tools; its actions just pass a checkpoint first.
- 01
Intercept
A drop-in MCP proxy, SDK or framework hook sees every tool call before it reaches your database, API or shell.
- 02
Decide
Policies and a risk score decide in milliseconds: allow, pause for a human, or block outright.
- 03
Snapshot
Before a risky call runs, a restore point is taken. If the snapshot fails, the call does not run.
- 04
Approve on web or phone
A named person sees the exact change, the risk and the snapshot, then approves or denies.
- 05
Prove
Every action, decision and approval is written to a hash-chained ledger with signed checkpoints.
Allow
Reads and low-risk calls run with no added friction.
Pause
Risky calls wait for a named human, with a snapshot first.
Block
Forbidden calls never run. The agent is told why.
New · Red-team tests
Attack your own agent before someone else does
Brakeproof sends your LLM app or agent the same tricks real attackers use, judges every reply, and shows you what got through and how to fix it.
Point it at your app or agent
Any HTTPS endpoint your agent answers on, or an OpenAI-compatible endpoint. Use a staging copy when you can.
Pick how hard to attack
Start with Quick, about 22 attacks on the most common failures. Then run a full scan mapped to a framework, or pick your own mix.
See what got through, and how to fix it
A pass rate, results per weakness, every attack with the reply and the reason it failed, and a fix for each one. Failures become findings in your risk score.
Scans you can run
- Quick
- OWASP Top 10 for LLM apps
- OWASP Top 10 for agentic apps
- NIST AI RMF
- MITRE ATLAS
- Custom
What it tries
- Prompt injection
- Jailbreaks, including multi-turn
- Fake system messages
- Encoded requests (Base64, ROT13)
- Role-play personas
- Personal data (PII) leaks
- System prompt and secret leaks
- Cross-customer data access
- Actions nobody asked for
- SQL and shell injection
- Toxic and harmful output
Your AI key, your bill
Runs use your own Gemini, Claude or OpenAI key. You pay your provider directly.
A budget cap on every run
The run stops when it reaches your cap. A Quick check usually costs less than a dollar.
Consent first
You confirm you own or may test the system. The consent is kept in the ledger.
Capabilities
Brakes, airbags and a black box
Everything Brakeproof does today. Each card shows whether it is available now or still in beta.
- Available
Action firewall
Every tool call passes through Brakeproof. Safe actions pass instantly. Risky ones, such as delete, refund or deploy, are paused, snapshotted and sent to a named human. A rule like DROP TABLE is blocked outright.
- Allow, pause or block per policy
- Snapshot before the call runs
- MCP proxy, Python and TypeScript SDKs
- Available
Spend brake
Set budgets on LLM token spend per agent, per team or for the whole company. When an agent goes over, it is paused right away, not discovered on next week's bill.
- Daily or monthly budgets
- Warning before the limit
- Automatic pause at the limit
- Available
Proof of work
When an agent says “done”, Brakeproof checks the real system, such as Stripe, Postgres or GitHub, to confirm the change actually happened.
- Read-only connectors
- Flags false success claims
- A truth rate for every agent
- Beta
Mobile app
Approve or deny from your phone with Face ID or a fingerprint. Each decision is signed by the device. Stop any agent with the kill switch.
- iOS and Android
- Signed approvals and an inbox
- Kill switch for any agent
- Available
Tamper-evident ledger
A record of every action, decision and approval that shows if anyone changed it. Export it any time.
- SHA-256 hash chain
- Signed checkpoints
- CSV and JSON export
- Available
Brakeproof AI
Plain-English approval briefs, risk flags, anomaly alerts, policy drafts, incident reports and a read-only chat. AI advises, rules decide: it never approves anything.
- Uses your own AI key
- Gemini, Claude or OpenAI
- Only redacted data is sent
- Available
Red-team tests
Brakeproof attacks your own LLM app or agent before real attackers do, then shows what got through and how to fix it.
- Prompt injection and jailbreaks
- Data, PII and prompt leaks
- OWASP and other framework presets
- Available
Security sensors
Read-only sensors check your AWS account, GitHub, websites and mobile app builds. Every finding rolls up into one risk score, together with agent behaviour.
- AWS through a read-only role
- Websites you verify you own
- APK and IPA app files
- Beta
Deploy to your cloud
Ship your agent with the guard built in, to Docker, Hugging Face Spaces or AWS ECS Fargate. It runs in your cloud account. We do not host your agents.
- Guard and kill switch built in
- Your code and secrets stay with you
- You pay your cloud provider directly
Also built: team roles (owner, admin, approver, viewer) and docs inside the app.
Brakeproof is in private preview. Beta means built and still in testing.
Prevention, not just monitoring
Monitoring tools show you the crash.
Brakeproof stops it.
Observability is useful. It is also, by design, after the fact. Keep your monitoring; add a control that acts first.
| Situation | Monitoring tools | Brakeproof |
|---|---|---|
| When it acts | When it actsAfter the action, in logs and traces | Before the tool call runs |
| A destructive query | A destructive queryRecorded once it has run | Paused, snapshotted, sent to a named person |
| A forbidden action | A forbidden actionAlert after the fact | Blocked by policy; the agent is told why |
| Runaway spend | Runaway spendSeen on the bill, often a day later | Agent paused at its budget |
| “Task complete” | “Task complete”Taken at face value | Checked against the real system |
| Prompt injection | Prompt injectionFound by users or attackers in production | Found first by red-team tests you run |
| Evidence | EvidenceMutable logs | Hash-chained ledger with signed checkpoints |
Mobile app · Beta
Approve from anywhere. Stop anything.
Agents work at 3 a.m. The person who can say yes should not need a laptop. A push notification opens the exact change, its risk and its snapshot.
Approve or deny with Face ID
Each decision is signed with a key held on your device, and the signature is kept in the ledger.
A kill switch for any agent
Stop an agent from any vendor in one step, wherever you are.
Everything needed to decide
The tool, the arguments, the rows affected, the matched policy and the snapshot, on one screen.
One inbox
Pending approvals, unusual-activity alerts and your security risk, in one place.
The iOS and Android apps are built and in testing (beta). They are not in the app stores yet. Web approvals work today.
Security and trust
Built to be the evidence, not just the alarm
We store metadata and redacted previews, never more customer data than we need. Every decision leaves a record that cannot be quietly edited.
- Available
Tamper-evident ledger
Every action, decision and approval is appended to a per-organisation SHA-256 hash chain with signed checkpoints. Change one entry and verification fails.
- Beta
Signed approvals
Mobile decisions are signed with a P-256 key that never leaves the device. The server verifies the signature before it counts.
- Coming soon
Regions: US, EU, Gulf
Hosted regions so data stays where your compliance team needs it, with region pinning on Enterprise.
- Coming soon
Self-hosted option
Run the control plane inside your own network for full control over data and keys.
Pricing
Flat per agent. Never per event.
A busy agent should not produce a surprise bill, including ours.
Early-access prices
Free
Put brakes on your first agents.
$0forever
- 2 agents
- Action firewall
- Web approvals
- 1 quick red-team test per month
Team
For startups running agents against production.
$149per month
- 10 agents
- Everything in Free
- Spend brake
- Mobile app + kill switch (beta)
- Brakeproof AI (your own key)
- Quick red-team tests
- 30-day ledger
Business
Proof, security testing and control across teams.
$699per month
- 50 agents
- Everything in Team
- Proof of work
- Full red-team scans (framework presets)
- Security sensors + risk score
- Deploy to your cloud (beta)
- Roles: owner, admin, approver, viewer
- Audit exportComing soon
Enterprise
Unlimited agents and custom terms for large teams.
From $30kper year
- Unlimited agents
- Everything in Business
- SSOComing soon
- Self-hostedComing soon
- Region pinningComing soon
- SLAComing soon
MSP $49 per client / month
Coming soonFor managed service providers running agents for many customers. One multi-tenant console for every client.
FAQ
Questions teams ask first
How is this different from observability tools?
Observability tools record what an agent did after it happened. Brakeproof sits in the path of every tool call, so it can pause or block an action before it runs, take a snapshot first and ask a named person to decide. It also caps spend and checks “done” claims against the real system.
Do I have to change my agent's code?
Not for MCP. You wrap the MCP server command with the Brakeproof proxy in your client config. For custom agents, use the Python or TypeScript SDK or one of the framework hooks. For Claude Code, add a PreToolUse hook.
What happens if Brakeproof is unreachable?
Each policy chooses. The default is to fail closed: risky calls are blocked while the control plane is down. A call that needed approval is never forwarded without one.
What is a red-team test?
Brakeproof sends your own LLM app or agent realistic attacks, such as prompt injections, jailbreaks and requests for other people's data, and judges every reply. You see what got through and how to fix it. You confirm that you own or may test the system before every run, and each run has a budget cap.
Do you store our customer data?
No more than we need. We store metadata and short previews of tool arguments, with emails, card numbers, tokens and keys masked before storage. Previews are capped at 2 KB.
Is it available today?
Yes, in private preview. The action firewall, spend brake, proof of work, ledger, Brakeproof AI, red-team tests and security sensors work today. The mobile app and cloud deploys are in beta. Join the waitlist and we will reach out as we open access.
Which agents does it work with?
Anything that calls tools through MCP, agents built with the OpenAI Agents SDK, LangChain / LangGraph or the Claude Agent SDK, Claude Code through a hook, and your own code through the Python or TypeScript SDK.
Put brakes on your agents before the next incident
Join the waitlist for early access. Setup takes about five minutes.