Home · Attestify Risk
Attestify Risk

Proof that every agent action was authorised, within policy, and auditable.

Attestify Risk is the compliance layer for teams deploying autonomous agents. It gives risk officers — not just engineers — a dedicated control plane: hard spend blocks, approval gates, violation ledgers, and a signed receipt on every run.

See the Risk dashboard →

The compliance question no engineering plan answers

“When our agent spent money, took an action, or made a decision autonomously — how do we prove it was authorised, within policy, and auditable?”

Engineering plans are priced and framed for the development budget. Attestify Risk is a separate product for the risk and compliance budget — a different buyer, a different approval path, and a different set of questions. It ships the evidence layer your auditor actually needs.

Controls included

Everything a risk team needs. Nothing they don't.

Every control below is live in production today — not roadmap. Controls marked Pro are included in Risk Pro only.

🔒
Financial control plane
Live

Hard spend ceilings enforced before execution — not after. Every agent run is checked against your per-agent and per-tenant budget. Runs that would breach the ceiling are blocked, not flagged.

📋
SLA policy editor
Live

Set latency, grade, reputation, and price-ceiling thresholds per agent. Violations surface in real time. Breaching agents are highlighted the moment the threshold is crossed.

Human approval gates
LivePro

Any run above a configured spend threshold pauses for a named approver. Approve or reject from the Risk dashboard — no engineering access required. Full audit trail either way.

📦
90-day receipt archive
Live

Every agent run produces a signed, hash-chained receipt. Receipts are retained for 90 days and exportable on demand to your SIEM, GRC platform, or audit pipeline via webhook.

📊
Spend benchmarking
Live

Compare your agent fleet's spend, latency, and grade profile against an anonymised cross-tenant benchmark. Know immediately if your agents are drifting from market norms.

🔔
SIEM & webhook delivery
LivePro

Push violation events, approval decisions, and receipt hashes to any HTTP endpoint. Native connectors for Splunk, Datadog, and Elastic are on the roadmap. Pro includes managed connector setup.

How a governed run works
1
Policy check (pre-run)
Before execution, every agent run is validated against your mandate — spend ceiling, SLA policy, reputation score. Blocked runs never start.
2
Autonomous execution
Approved runs execute on the normal agent path. Attestify stays out of the money flow. Human approval gates pause runs above your threshold.
3
Signed receipt (post-run)
Every completed run closes with a hash-chained receipt: agent ID, intent, cost, grade, timestamp. Exportable to your audit pipeline.

Pricing

Two tiers. Same risk product. Different scale and support level.

Risk Core
Risk teams getting started with agent governance
$4,500 / mo
Billed monthly · Cancel anytime
  • Dedicated Risk dashboard
  • Hard spend blocks (pre-execution)
  • SLA policy editor
  • 90-day signed receipt archive
  • Spend benchmark vs. peer fleet
  • Violation ledger (all severity levels)
  • Webhook delivery for all events
  • Self-serve onboarding guide
  • Email support
Recommended
Risk Pro
Organisations with active compliance obligations
$9,500 / mo
Billed monthly · Cancel anytime
  • Everything in Risk Core
  • Human approval gates
  • Managed SIEM connectors (Splunk, Elastic)
  • Dedicated onboarding with risk team
  • Priority Slack support
  • 5% enterprise toll eligibility on governed runs
  • SOC 2 evidence pack (under NDA)
Why these prices?
Below one day of external audit consultancy
£1,500–3,000/day is the market rate for a GRC consultant. Risk Core is priced well below that.
At par with mid-market GRC tooling
OneTrust, Vanta, and peers run $1,000–5,000/mo for comparable evidence coverage.
Separate budget, separate approval path
Risk teams approve this on a compliance budget line — not the engineering tools budget.
Enterprise toll scales revenue without raising the base
The 5% toll on large deployments (Risk Pro) is where revenue scales with run volume.
🧾
Already on an Attestify engineering plan?

Attestify Risk is a separately scoped engagement on a separate budget line — it is not a tier upgrade from Builder, Growth, or Enterprise. The two products share the same data layer but have distinct access paths and billing.

Frequently asked questions

Is this a standalone product or an add-on to an existing plan?

Standalone. Attestify Risk is a separate subscription for the risk buyer — it includes all the platform infrastructure your agents need plus the compliance controls layer. You do not need a Builder, Growth, or Enterprise plan alongside it.

Do my engineers need access to the Risk dashboard?

No. The Risk dashboard is designed for a non-technical risk officer to use independently. Engineers continue using the main Attestify dashboard. The two views share the same data layer but have separate access paths.

What is a "hard block" vs. a "spend limit"?

A spend limit flags or alerts when a threshold is exceeded. A hard block prevents execution entirely before the payment or action completes — the run never starts if it would breach your mandate.

How does the 5% platform fee on governed runs work?

Large-scale enterprise deployments on Risk Pro can add a 5% toll on the notional value of each governed agent run — on top of the monthly fee. This applies to high-volume contracts and is scoped during onboarding.

Can I export receipts to our existing GRC platform?

Yes. Receipts are delivered to any HTTPS webhook endpoint you configure. Signed receipt hashes are compatible with any system that accepts JSON. Managed Splunk and Elastic connectors are included in Risk Pro.

Is this SOC 2 / ISO 27001 ready?

Attestify Risk provides the evidence layer — signed receipts, violation logs, approval audit trails, and spend records — that your auditor needs. We are currently pursuing SOC 2 Type II and will share the report under NDA.

Ready to govern your agent fleet?

A signed receipt on every agent action, and hard blocks before they cost you.

Start with Risk Core and configure your compliance baseline in under 5 minutes.

Questions? hello@attestifyos.com