For teams told to adopt AI and stay secure
Blocking AI agents loses the race.
Letting them loose loses the audit.
Vertlock is the third option: agents get scoped, revocable, fully-receipted access to your tools — and your credentials never touch the model.
01The bind every company is in
The rock
Say no to agents
- Your competitors ship with them anyway — and your roadmap slows while theirs compounds.
- Your own engineers don't stop. They go around you: 67% of leaders say they approved AI tools under pressure despite security concerns.
- The ban doesn't remove the risk. It removes your visibility into it.
The hard place
Say yes, ungoverned
- Agents hold raw credentials to GitHub, Slack, and Drive — with no approval gate and no record of what they touched.
- Shadow AI is already a factor in 1 of 5 breaches, and adds an average $670K to the cost of each one.
- Only 24% of organizations can even see how their agents talk to their tools.
There's a third option.
Sources: Trend Micro global survey 2025 · IBM Cost of a Data Breach 2025 · Gravitee agent visibility survey 2026
02How Vertlock works
One gateway between your agents and everything they touch
01
Agent asks
The agent calls a tool through Vertlock instead of holding your credentials.
02
Identity checked
Every request is tied to the human behind it. No anonymous agents.
03
Policy applied
Access Packs decide per person: allowed, blocked, or needs approval.
04
Human approves
Dangerous writes wait for a one-tap approval on Slack or your phone.
05
Receipt written
Every call lands in a hash-chained ledger no one can quietly rewrite.
03Where it sits in your AI stack
One layer. Every agent above it, every tool below it.
Your agents — any vendor, any harness
every tool call, no exceptions
VERTLOCK
the governed gateway
IDENTITY
Every call tied to a human
POLICY
Allow · block · needs approval
CUSTODY
Credentials never reach the model
RECEIPTS
Hash-chained record of everything
brokered calls, scoped per person
Your tools and credentials
Scoped the way your company already is
Your design team doesn't need access to the accounting tools, and your accounting team doesn't need access to GitHub and Linear. Access Packs give each team's agents exactly what that team already has — nothing more.
Design's agents
Figma, Drive, the brand wiki
— not the general ledger
Accounting's agents
QuickBooks, invoices, spreadsheets
— not GitHub, not Linear
Engineering's agents
repos, CI, staging
— production deletes wait for a human tap
Support's agents
helpdesk, docs, CRM read-only
— not customer billing
04Why it's priority one
Governance is only cheap if it comes first
Agents first, governance “later”
4 agents × 5 tools = 20 ungoverned paths, 20 credentials to rotate, zero receipts. Every agent you add multiplies the mess — and you can't backfill an audit trail you never wrote.
Gateway first
4 + 5 = 9 governed connections, one policy, one ledger. Every agent you add later inherits identity, approvals, and receipts on day one.
A
It makes every other AI decision reversible. Wrong model? Bad agent? Pause or revoke in one click. Without the gateway, unwinding a bad AI bet means rotating every credential it ever touched.
B
You can't backfill an audit trail. When the auditor, the board, or the EU AI Act asks what your agents did last quarter, receipts you never wrote don't exist. The ledger only protects you from the day it's on.
C
The retrofit is the expensive version. Every agent added before the gateway is another integration to migrate later. Every agent added after it inherits policy on day one.
05The artifact auditors ask for
Every agent action, hash-chained. Even admins can't rewrite history.
This is the record your SOC 2 auditor — and the EU AI Act — will ask for: what the agent attempted, what policy decided, who approved it, and what actually ran.
06Open source, honestly scoped
Apache-2.0. Self-host it in five minutes.
The enforcement core is open source — your security team can read every line, run it inside your own network with Docker Compose, and never send us a byte. You're betting on code you can fork, not a vendor promise.
What Vertlock is not:
It governs and records tool access routed through it. It is not a full agent sandbox, not all-network data-loss prevention, and not a guarantee that data an authorized agent legitimately reads can't be misused afterward. We'd rather you know that now.
07Design partners
Five companies. Free enterprise setup for six months.
We set Vertlock up with you — approvals, brokered credentials, audit trail — before your auditors or your board ask for it. In exchange: thirty minutes of feedback every two weeks, and a case study if it works. Founding-customer pricing after, locked for life.