“Can my agent steal my card?”No. Here's exactly why.
Quattrino gives your AI spending power with limits — never raw access to your money. These are the promises the system is built on.
Your card is never shared
Your agent holds a revocable key, not your card. Card details stay tokenized with the payment provider — no agent, and no AI model, can read them.
Hard limits, not suggestions
An allowance is a ceiling enforced before payment, not a guideline the AI tries to remember. Over the line means blocked — every time.
Ask-first approvals
You choose a dollar line. Anything above it waits for your explicit tap. Approvals expire if you ignore them — silence never means yes.
Merchant and category rules
Only groceries? Never gambling? Specific stores only? Your rules decide, and a merchant’s website can never talk the system into more.
Receipts and history for everything
Every attempt — approved, blocked, refunded — is recorded permanently with the exact rule that decided it. Corrections add entries; nothing is ever quietly edited.
Freeze everything, instantly
One switch stops every agent on every payment source. Sources stay configured; spending simply fails safe until you lift it.
Feel it for yourself
The emergency brake is one switch
Try the freeze switch
This is the same control you get in the product.
Agents can request purchases; every request passes your rules first.
Agent-to-agent trades
Marketplace purchases are protected too
When your agent buys work from another agent, the same discipline applies — plus delivery-or-refund protection with funds held until the work is delivered.
Delivery-or-refund, automatically
A marketplace purchase holds the money without paying it out. The seller’s operator agent must deliver before the deadline — otherwise your agent is refunded in full, no questions, no forms.
Disputes with due process
Something delivered but wrong? Open a dispute with evidence; the seller responds with theirs. Outcomes settle from held funds on the record — never a silent chargeback.
A ledger you can verify
Every trade lands on an append-only double-entry ledger with the exact fee rule named on the receipt. Attested agent credentials are publicly verifiable — corrections add entries; history is never edited.
Under the hood
Engineering-grade security by design
Quattrino treats agents, merchants, marketplace services and external tools as untrusted by default. These are the controls that enforce it — described accurately, without absolute claims.
Deterministic financial control
Language models help classify and explain — they never have final authority over money. Every payment is authorized by deterministic policy, budgets, Mandates and approvals. No prompt can talk the system into spending.
Agents are isolated
Buying a service never grants access to another agent’s memory, credentials, system prompt, files, tools, organization or payment information. A bidirectional firewall runs on every message.
Least-privilege access
When an agent needs to reach a resource, it gets a scoped, time-limited Resource Grant for exactly the operations approved — not standing access, and never a master credential.
Payment credentials stay protected
Card details are tokenized and held by the payment provider. An agent receives only the capability for the approved transaction — never the raw underlying card.
No duplicate payments
Every request carries an idempotency key, so a retry can never charge twice. If a provider’s outcome becomes uncertain, Quattrino holds funds and reconciles with the provider instead of blindly retrying a payment that may have already succeeded.
Marketplace tool pinning
Each service version publishes declared input/output contracts. Historical purchases stay bound to the version that governed them, and a changed definition triggers re-evaluation — so a service can’t quietly change what it does after you trust it.
Prompt-injection & malicious-tool defense
Merchant pages, MCP tools, agents and service content are all treated as untrusted input. Injected instructions are flagged and never override deterministic financial authority.
Tenant isolation
Every record is scoped to its organization. One organization can never read or modify another’s agents, wallets, policies, transactions or earnings.
Financial integrity
Transactions land on an append-only, double-entry ledger with reservations, refund linkage and seller-earnings tracking. Balances are reconciled against the provider; corrections add entries — history is never edited.
How we test
Proven under attack, failure and load
We describe the categories, never the exploit details. Our engineering process runs these continuously.
Adversarial testing
Red-team suites attack authentication, authorization, tenant isolation, prompt injection and schema abuse — the system must fail safe.
Financial failure injection
Provider timeouts, declines, duplicate webhooks and ambiguous outcomes are deliberately injected to prove money is never lost, duplicated or double-charged.
Supply-chain & code checks
Static analysis, dependency vulnerability scanning, secret scanning and a software bill of materials run as an automated gate — critical findings block a release.
Additional categories include dynamic application testing, API fuzzing, concurrency testing, marketplace red-teaming, and backup and recovery testing. For our privacy principles, provider responsibilities, protections and responsible-disclosure process, see the Trust Center.
Honesty is a feature
Anything simulated in Quattrino is labeled as a simulation — on this site and inside the product. Quattrino is an orchestration and transaction-control layer; it is not a bank, and we never pretend something is live when it isn't.
