Custogent Request access

Control plane & evidence · Financial services first · Pre-launch

Show your examiner what your AI agents were authorized to do with money, what they did, and that the record is intact.

Custogent is the control plane an AI agent must pass through to move money, and the tamper-evident, quantum-safe evidence ledger that turns each decision it makes into a record an examiner can verify without trusting you, or us. It shows that every recorded verdict on an agent’s instruction was computed under its named mandate and policy version, from disclosed inputs, and can be recomputed by anyone from the record.

Custogent never holds funds, card numbers or your agents’ private keys, is not a payment processor, and never substitutes its own judgment for yours: every policy verdict is your own policy version applied to your own inputs.

Verdict · receiptvd_01K4R8T2Q9
agent
ap-settlement-07 · owner: Treasury Ops
instruction
transfer 18,400.00 USD → counterparty 4471 · ACH same-day
mandate
m_0192 v4 · ceiling 25,000.00 · expires 2026-12-31
policy
ps_v17 · 3f9a…c2e1 · agg.spend.day.agent 71,300.00
verdict
hold · NOVEL_COUNTERPARTY · 2026-09-04T13:02:11Z
approval
approver ≠ mandate issuer · signed hash 8b1e…04d7 · 13:06:40Z
receipt
checkpoint #48,211 · RFC 3161 + second anchor · S3 Object Lock
signatures
EdDSA ✓ · ML-DSA-65 ✓
valid as of registry v12 at checkpoint #48,211 recomputable from the record

Illustrative record. Each verdict records the mandate and policy version it was evaluated under — or that one was missing — the values it evaluated and any approval, and carries a receipt anyone holding the evidence pack, our published keys and the verifier can check. What the record shows an agent did is its signed instruction, the verdict and, where your release point returns one, the release receipt: an allow on its own is not proof that a payment was made.

“Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.”

Model Risk Management: Revised Guidance · OCC Bulletin 2026-13, issued jointly with the Federal Reserve (SR 26-2) and the FDIC · 17 April 2026

Why now

There is no supervisory rulebook for agents that move money. There is still an examiner.

In April 2026 the banking agencies rescinded SR 11-7 and placed generative and agentic AI outside the replacement guidance. The request for information they promised had still not been published as of mid-September 2026, and the replacement third-party risk guidance the same agencies published for comment on 15 September 2026 does not mention AI. The rest of the rulebook still applies — safety and soundness, third-party risk management, BSA/AML and, for covered entities, NYDFS Part 500 — and sponsor banks are required to obtain evidence from their fintech partners. Institutions have to show it themselves.

Apr 2026

The framework excludes agents.

Revised interagency model risk guidance names generative and agentic AI as out of scope, and states that non-compliance will not result in supervisory criticism. It leaves the governance and controls for what it excludes to each bank’s own risk management. The model-risk yardstick no longer covers agents; the exam still does.

OCC Bulletin 2026-13 · FRB SR 26-2 · FDIC FIL-15-2026 · 17 Apr 2026

Dec 2025

Autonomy and auditability are named risks.

FINRA’s 2026 oversight report lists “AI agents acting autonomously without human validation and approval” and multi-step reasoning that is “difficult to trace or explain” among the risks of AI agents, and says firms may need supervisory processes specific to the agents they deploy.

FINRA 2026 Annual Regulatory Oversight Report · 9 Dec 2025

72% n=230

Least prepared where it counts.

Asked which part of AI incident response their institution is least prepared for, 72% of US banking professionals picked one of two: reporting an AI failure to a regulator (37.8%) or a model kill-switch protocol (34.4%).

Wolters Kluwer US Banking AI Risk and Governance Index · 28 May 2026 · 230 US banking professionals

Four in five fraud and risk leaders worldwide say their institution has already encountered attacks using agentic AI (BioCatch, 2026 Future of Digital Trust, 10 June 2026; 1,440 leaders, 25 countries). Visa’s rules now require agent platforms in its agentic-commerce program to register, and Mastercard says its agentic tokens are built to register, verify and recognize agentic transactions; American Express says its own agent-registration specification is still under development. The operating rules of the bank rails — ACH, RTP, FedNow — contain no AI-agent provision. No network can tell an institution whether its agents stayed inside the institution’s own policy across all the rails it uses, or hand its examiner that record. That job belongs to the institution.

Product

Three layers. One system of record for agent authority.

A gateway in the path of your agents’ money-moving instructions. A ledger that makes every recorded decision — and every recorded change to who may make one — tamper-evident and verifiable by a stranger. Evidence packs written for the person who has to sign the exam response. The sixth part proposes changes to the control set when the guidance changes underneath it. Everything below describes the product being built; none of it is running for customers yet.

01Gateway

Mandates

A signed grant of authority: this agent may take these actions, on behalf of this principal, within these limits, until this date. Issued by a named person signing with their own credential; revoked at a recorded instant, after which the gateway refuses the next instruction under it and outstanding authorizations stop at verifying release points within their freshness window. The record of authority an examiner is likely to ask for.

02Gateway

Policy and limits, in line

Per-transaction, daily, per-counterparty and fleet limits, novel-counterparty holds, channel restrictions and time windows — evaluated before release — designed for a p99 under fifty milliseconds — with the policy version and every evaluated value recorded in the verdict.

03Gateway

Maker-checker and kill switch

High-risk instructions hold for a qualified human who is shown what the agent proposed and signs over exactly that instruction; the signature does not by itself show what the person read. One switch stops new authorizations for an agent, a class of agents or everything, and records what it refused, when, and what was still outstanding. In enforcement it stops new Custogent authorizations the moment it is recorded, and blocks pending releases at every release point that verifies our token within the freshness window you set; where a release point does not verify tokens, it stops new authorizations only.

04Ledger

Tamper-evident, quantum-safe

Append-only, hash-chained, Merkle-tree records with checkpoints signed twice — classical and post-quantum (ML-DSA) — timestamped by an RFC 3161 authority and a second, separately operated anchor, and kept in retention-locked storage (S3 Object Lock, compliance mode), with a replicated copy in your own account. Verifiable offline by anyone holding the evidence pack, with our published keys, an independent timestamp and the published verifier.

05Evidence

Evidence packs and replay

A signed bundle for a period: a control narrative mapped to named sources, the receipts that support each control assertion, exceptions, approvals, kill-switch tests and disclosed gaps — and replay: would this instruction have been held under the policy in force in March? Mappings are not an examiner’s approval.

06Differentiator

Regulatory watch

Guidance, standards and rail rules from named sources held as versioned data. When a watched source changes — the promised interagency request for information included — the change arrives as a proposed difference against your control set, reviewed and approved by a person, with the whole trail on the ledger. It does not promise complete coverage or compliance.

Custogent is not a payment processor, a fraud model, an agent framework or an identity provider. It never screens, and never substitutes its own judgment for yours: every policy verdict is your own policy version applied to your own inputs, and the gateway’s own safety rules produce only a hold. It sits beside all of them and records what they submitted, decided and reported, and under which rules. Every deployment starts in shadow mode — record only, nothing blocked — and moves to enforcement only when the readiness conditions below are met and the institution signs the approval. Where the institution’s own gate enforces, the deployment stays an evidence-only mode, labeled as such.

How it works

One integration in the agent. One chokepoint across the release points you connect. One record the examiner can check alone.

An agent submits an instruction through the SDK; the Custogent gateway evaluates mandate, policy and limits and returns allow, deny or hold; allowed instructions proceed to the institution's rails; held instructions go to a qualified human approver; every verdict is appended to the ledger; evidence packs are produced from the ledger and verified by the examiner offline. YOURS CUSTOGENT YOURS AI agent Claude · LangGraph · MCP + one line: Custogent SDK signs, submits, waits Gateway mandate in force? policy · limits · velocity screening result, if policy needs it allow · deny · hold → human p99 target 50 ms · fails closed Your rails ACH · RTP / FedNow card · stablecoin via your PSP or core instruction allow Your approver qualified, not the issuer sees what the agent proposed · signs hold Ledger append-only · Merkle tree EdDSA + ML-DSA-65 checkpoints two time anchors · WORM mirror every verdict, approval, halt Evidence pack OSCAL · receipts · verifier Examiner verifies offline, alone
Left and right: what the institution already has. Center: what Custogent adds, and where the examiner’s question lands.
01 · In line, not after the fact

A recorder alone does not block a payment.

The gateway is on the path. A verdict is a decision, not a log entry. In enforcement mode — where your release point verifies our token, or our adapter in your environment does — the agent cannot proceed without it. Where your own gate enforces, we record your gate’s decisions and recompute them against your policy version, and every pack says the gate was yours; where neither, every evidence pack says so. It fails closed: no mandate, no policy snapshot, or no screening result where your policy requires one means hold, never allow.

02 · Verifiable by a stranger

You do not have to take our word for the calculation.

Every checkpoint is signed with a classical key and a post-quantum key, timestamped by an RFC 3161 authority and a second, separately operated anchor, and kept in retention-locked storage. An examiner holding the evidence pack, our published keys, an independent timestamp and the standalone verifier can check its records without an account, without our systems or yours, and without asking us. The report names what it still depends on: whose keys, whose assertions, which anchors.

03 · Replay

The policy that governed a decision is named in the decision.

Each verdict carries the exact policy version and every value it evaluated. A recorded instruction can be re-evaluated under another policy version when the inputs that version needs were recorded; a counterfactual run is labeled as one and states what it assumed — for a dispute, a lookback exam, or to show a proposed change would have caught the case that worried you.

04 · Built for more than one industry

Financial services first, on a core that carries no industry vocabulary.

The definitions of mandates, instructions, verdicts, approvals and receipts do not mention money. The financial-services pack supplies the rails, limits and control mappings; other regulated industries are a design goal on the same core, not an available capability.

Trust

What the record proves, and what it does not.

This is the design being built, stated with its limits, because a security team will find the limits anyway. Nothing here is a certification or an audit opinion.

01Quantum-safe

Integrity and transport, not everything.

Checkpoints are designed to be signed with ML-DSA-65 as well as EdDSA, and the load balancers are specified for hybrid post-quantum key exchange with clients that support it. This is not an end-to-end post-quantum claim. No timestamp authority issues post-quantum tokens today, so time is anchored by an RFC 3161 authority and a second, separately operated anchor; timestamps are renewed while they are still trustworthy, moving to post-quantum authorities as they appear.

02FIPS

What the certificate covers.

Signing keys are to live in AWS KMS hardware validated to FIPS 140-3 Level 3. That module’s current certificate lists neither ML-DSA nor EdDSA among its approved algorithms. We say so because you would find out.

03Verifier

“Valid as of”, never “valid now”.

The verifier reports “valid as of registry version N at checkpoint M”, because an offline verifier cannot know what was revoked after the pack was built. For each thing it reports, it names whose key, whose copy, whose observation or whose authority would have to fail for it to be wrong.

04Rule language

Small enough to check ours.

Policies are written in a small, closed, formally specified rule language, so anyone can write their own interpreter and check ours. A formally specified language is not a formally verified interpreter; that is why the verifier is a separate implementation with a reproducible build.

05Approvers

No recovery path, so every role has two.

Approvers sign with credentials they hold themselves. There is no recovery path, not through us and not through a help desk. Enforcement cannot start without at least two people enrolled for every approving role; a later period in which a role falls to one is flagged in that period’s evidence pack.

06AI models

No model takes part in a verdict.

Models help draft and classify for Regulatory watch and run Custogent’s own agents. None of them sees your data until you enable it by a signed approval, and every model call is recorded before it is sent.

Where your own gate controls release, the kill switch stops new authorizations where applicable and asks your gate to stop the specified new releases; delivery and effect depend on your gate and are reported separately, an acknowledgement is not independent proof that releases stopped, and nothing already committed is recalled. A checkpoint commits every tenant’s chain head in its cell: the number of entries reveals how many tenants the cell serves, and the published format will state what else checkpoints can reveal.

Who it’s for

Can you show your sponsor bank — or your examiner — every recorded instruction your AI agents submitted last quarter, the authority each acted under, the policy in force at the time, who approved each exception, and show that the record has not been altered since it was committed?

If assembling that answer would take longer than a day, or would rest on “we prompt the model carefully”, that is the conversation. Fintechs and agent builders deploying money-moving agents feel it first, because a sponsor bank is required to obtain evidence from its fintech partners, and asks. Banks feel it next, across their own agents and their partners’.

There is nothing to buy. Thirty minutes on how that question is landing at your institution is worth more to both of us than a demonstration would be, and it is the only thing being asked for.

The functions this usually sits with

  • 01Compliance and risk at a fintech deploying agents
  • 02Payments or platform engineering — the team that must not be slowed down
  • 03Third-party risk and BSA at a sponsor bank
  • 04Model risk and AI governance at a bank

Stage

Pre-launch, and saying so.

Custogent is being built now, and is looking for a small number of design partners: regulated institutions willing to argue the control set out against their own examinations and their own sponsor-bank reviews rather than inherit someone else’s.

There is no product to sell you yet. That is the reason to talk early rather than a reason to wait — design partners shape which controls come first, within fixed security boundaries, and the first evidence pack a sponsor bank reviews should be one of theirs.

Before a bank switches to enforcement, it shows us six things: a release point that checks our token, its own continuously replicated copy of the record, a named contact, at least two approvers for every approving role, a rehearsed incident notice, and a verifier it has run on its own pack.

Design partnersA small number of regulated institutions, each expected to argue with the defaults rather than inherit them. Shadow mode first; enforcement once the readiness conditions are met and they sign for it.
DeploymentDesigned as multi-tenant on AWS, US regions, with private connectivity and a replicated, retention-locked copy of the record in your own account; dedicated single-tenant cells for institutions that require them. Built to extend outside the US without a fork.
Out of scopeCustogent never holds funds, card numbers or your agents’ private keys; never screens; and never substitutes its own judgment for yours. It records what your systems submitted, decided and reported, and under which rules.
DataRuntime and tenant data stay in AWS, US regions. The evidence store holds pseudonymous references and hashes, never direct identifiers of people or accounts. Every other dependency is listed in a subprocessor register with what it receives; AI model access to your data is off until you enable it.
DependencyIn enforcement, a connected release waits for a verdict, and if the gateway cannot decide, it holds. Recovery targets, degraded modes, incident contacts and export of your record are set per deployment and written into the agreement.
AssuranceNo independent assessment exists yet. SOC 2 (Security) and ISO/IEC 42001 are planned for the first year; timing is published to design partners. Custogent’s own AI agents are to run under Custogent’s own control plane; the evidence system is also the evidence.
This siteRuns no JavaScript, sets no cookies and loads no analytics script; the host keeps ordinary access logs. A security team can check the browser side from outside in a few minutes.

Founder

Sheo Jha

Founder, Custogent. Formerly Risk Officer, U.S. Securities and Exchange Commission, Enforcement Division.

CISSP · CISM · CRISC
BS EE, IIT Kanpur · MBA, The George Washington University

Sheo spent twelve years as a Risk Officer in the U.S. Securities and Exchange Commission’s Enforcement Division, where he built and led its Governance, Risk and Compliance program, leaving in March 2026. He is Chief Innovation Officer at Ankore Consulting, a risk and technology advisory firm he co-founded in 2010.

Custogent exists because the examiner’s questions — who authorized this agent, what could it do, what rule was in force, who approved the exception, and can you prove the record is intact — have no answer yet for an agent that can move money on its own. The answer has to be built into the path the money takes, and it has to be checkable by someone who does not trust the vendor.

Contact

Request access, or just start the conversation.

Access is by request and by conversation — there is no self-service signup, no trial and no login on this site. Tell us who you are and what you are looking at; a person replies.

Request access Opens your mail app with an outline filled in.

No contact form by design: nothing is collected on this page, and a form processor would be a subprocessor to disclose on your questionnaire. Requests arrive as ordinary email.