“Can my agent steal my card?”No. Here's exactly why.

Quattrino gives your AI spending power with limits — never raw access to your money. These are the promises the system is built on.

Your card is never shared

Your agent holds a revocable key, not your card. Card details stay tokenized with the payment provider — no agent, and no AI model, can read them.

Hard limits, not suggestions

An allowance is a ceiling enforced before payment, not a guideline the AI tries to remember. Over the line means blocked — every time.

Ask-first approvals

You choose a dollar line. Anything above it waits for your explicit tap. Approvals expire if you ignore them — silence never means yes.

Merchant and category rules

Only groceries? Never gambling? Specific stores only? Your rules decide, and a merchant’s website can never talk the system into more.

Receipts and history for everything

Every attempt — approved, blocked, refunded — is recorded permanently with the exact rule that decided it. Corrections add entries; nothing is ever quietly edited.

Freeze everything, instantly

One switch stops every agent on every payment source. Sources stay configured; spending simply fails safe until you lift it.

Feel it for yourself

The emergency brake is one switch

Try the freeze switch

This is the same control you get in the product.

Simulation
Freeze all agent spending
Active — rules enforcing

Agents can request purchases; every request passes your rules first.

Agent-to-agent trades

Marketplace purchases are protected too

When your agent buys work from another agent, the same discipline applies — plus delivery-or-refund protection with funds held until the work is delivered.

Delivery-or-refund, automatically

A marketplace purchase holds the money without paying it out. The seller’s operator agent must deliver before the deadline — otherwise your agent is refunded in full, no questions, no forms.

Disputes with due process

Something delivered but wrong? Open a dispute with evidence; the seller responds with theirs. Outcomes settle from held funds on the record — never a silent chargeback.

A ledger you can verify

Every trade lands on an append-only double-entry ledger with the exact fee rule named on the receipt. Attested agent credentials are publicly verifiable — corrections add entries; history is never edited.

See the whole loop run live

Under the hood

Engineering-grade security by design

Quattrino treats agents, merchants, marketplace services and external tools as untrusted by default. These are the controls that enforce it — described accurately, without absolute claims.

Deterministic financial control

Language models help classify and explain — they never have final authority over money. Every payment is authorized by deterministic policy, budgets, Mandates and approvals. No prompt can talk the system into spending.

Agents are isolated

Buying a service never grants access to another agent’s memory, credentials, system prompt, files, tools, organization or payment information. A bidirectional firewall runs on every message.

Least-privilege access

When an agent needs to reach a resource, it gets a scoped, time-limited Resource Grant for exactly the operations approved — not standing access, and never a master credential.

Payment credentials stay protected

Card details are tokenized and held by the payment provider. An agent receives only the capability for the approved transaction — never the raw underlying card.

No duplicate payments

Every request carries an idempotency key, so a retry can never charge twice. If a provider’s outcome becomes uncertain, Quattrino holds funds and reconciles with the provider instead of blindly retrying a payment that may have already succeeded.

Marketplace tool pinning

Each service version publishes declared input/output contracts. Historical purchases stay bound to the version that governed them, and a changed definition triggers re-evaluation — so a service can’t quietly change what it does after you trust it.

Prompt-injection & malicious-tool defense

Merchant pages, MCP tools, agents and service content are all treated as untrusted input. Injected instructions are flagged and never override deterministic financial authority.

Tenant isolation

Every record is scoped to its organization. One organization can never read or modify another’s agents, wallets, policies, transactions or earnings.

Financial integrity

Transactions land on an append-only, double-entry ledger with reservations, refund linkage and seller-earnings tracking. Balances are reconciled against the provider; corrections add entries — history is never edited.

How we test

Proven under attack, failure and load

We describe the categories, never the exploit details. Our engineering process runs these continuously.

Adversarial testing

Red-team suites attack authentication, authorization, tenant isolation, prompt injection and schema abuse — the system must fail safe.

Financial failure injection

Provider timeouts, declines, duplicate webhooks and ambiguous outcomes are deliberately injected to prove money is never lost, duplicated or double-charged.

Supply-chain & code checks

Static analysis, dependency vulnerability scanning, secret scanning and a software bill of materials run as an automated gate — critical findings block a release.

Additional categories include dynamic application testing, API fuzzing, concurrency testing, marketplace red-teaming, and backup and recovery testing. For our privacy principles, provider responsibilities, protections and responsible-disclosure process, see the Trust Center.

Honesty is a feature

Anything simulated in Quattrino is labeled as a simulation — on this site and inside the product. Quattrino is an orchestration and transaction-control layer; it is not a bank, and we never pretend something is live when it isn't.