The platform
Discover. Authorize. Prove.
One evidence graph behind every agent action: who is acting, whether the action is justified, and a receipt for what happened.
Who is acting, and with what?
Discover
Give every agent an identity
Register the agents, tools and credentials in your stack, and see what each one can reach before it takes its first action.
- An identity and an owner on every agent
- Every tool and credential mapped to the agent that holds it
- A reasoning trace for every run
Authorize
Verify before AI acts
Each proposed action is checked against current evidence, permissions and company policy. The answer is ALLOW, HOLD or ESCALATE.
- Evidence freshness and bindings verified
- Prompt injection filtered before a tool runs
- Tools fail closed without a valid grant
Prove
Leave a receipt for every decision
Approved actions carry an expiring signed grant, and every decision lands in a tamper-evident audit trail you can replay.
- HMAC-SHA256 signed action grants
- Tamper-evident audit log of allow, hold and escalate
- Human sign-off on high-risk steps
See it move
The whole platform in one short loop.
The wheel, the authorize gate, the decision engine and the rotating headline, recorded from the sections on this page.
Illustrative walkthrough with sample data. No audio.
Beyond people
You secured your people. What about your agents?
Three questions every team running AI agents ends up asking, usually after something has already happened.
Which agents exist, and what can they touch?
Agents show up faster than anyone registers them. Qbrin gives each one an identity and an owner, and maps the tools and credentials it can reach.
What do they inherit from whoever launched them?
An agent that borrows a person’s login inherits everything that login can do. Qbrin scopes what an agent may do to the action in front of it.
- Claim
- refund_payment
- Evidence
- invoice total
- Verdict
- HOLD claim not supported
Was the action actually justified?
Logs tell you what happened after the fact. Qbrin checks the claim against current evidence before the tool runs, and holds what the evidence does not support.
Inside the platform
Three moves between an agent and your tools.
01 · Discover
Every agent gets an identity. Nothing runs anonymously.
Register the agents, tools and credentials in your stack and see what each one is allowed to reach, before it takes its first action.
- An identity and an owner on every agent
- Every tool and credential mapped to the agent that holds it
- A reasoning trace for every run
Agent inventory · Illustrative
| Agent | Owner | Tools | Status |
|---|---|---|---|
| refund-agent | finance-ops | refund_payment | Governed |
| support-triage | support | tag_ticket | Governed |
| data-sync-bot | platform | export_rows | Held |
| research-agent | growth | web_search | Governed |
| onboarding-agent | people-ops | create_account | New |
02 · Authorize
Verify before AI acts.
Every proposed action is checked against current evidence, permissions and company policy. Decisions come back in low milliseconds as ALLOW, HOLD or ESCALATE.
- Evidence freshness and bindings verified
- Prompt injection filtered before a tool runs
- An expiring signed grant; tools fail closed without it
The AI wants to
refund_payment
- Order found in billing system
- Amount within what was paid
- Inside the refund policy
grant · qg_9f2c…e71a · expires in 60s03 · Prove
Every decision leaves a receipt.
Approved actions carry a signed grant. Every decision, allowed, held or escalated, lands in a tamper-evident audit trail you can replay.
- Tamper-evident audit log of every decision
- Human sign-off on high-risk steps
- Replay any run from its trace
10:41:07refund_payment ₹4,200ALLOW#a91f…3c2e10:41:33refund_payment ₹95,000HOLD#c40b…77d110:42:10delete_customer_recordsESCALATE#5e08…0aa910:42:58send_email → customerALLOW#2b7d…91f4
The control plane
Everything between an agent and your tools, in one place.
Agent identity & inventory
An identity, an owner and a scoped credential for every agent, with each tool it can reach mapped in one place.
Agent governanceAuthorizeEvidence-backed authorization
POST /v1/authorize checks each action against current evidence, permissions and policy, then answers ALLOW, HOLD or ESCALATE.
Authorization APIEnforceTool boundary policy
Policy is applied before a tool runs. Downstream tools and executors fail closed unless a valid grant is presented.
Read the docsContainSandbox containment
Agents work inside a sandbox they cannot escape, so a wrong decision stays small.
How containment worksProveTamper-evident audit
Every decision lands in an audit trail you can replay, with human sign-off on high-risk steps.
Security modelPlatform tour
Follow one action from registration to receipt.
A four-step walk-through of what happens when an agent tries to refund a customer.
- 01Register the agent
Give it an identity, an owner and only the tools it needs.
- 02It proposes an action
The agent reasons about the task and submits the action before any tool runs.
- 03The gate decides
Evidence, authority and policy are checked. The answer is ALLOW, HOLD or ESCALATE.
- 04A person signs off, and it is logged
High-risk steps route to an owner. Every outcome lands in the audit trail.
- Agent
- refund-agent Governed
- Owner
- finance-ops
- Credential
scoped key ••••8f2a- Tools
orders.lookuprefund_payment- Sandbox
- on
- Trace
- every run recorded
Register the agent with an identity, an owner and only the tools it needs. When it proposes an action, the gate checks evidence, authority and policy; high-risk steps route to an owner, and every outcome lands in the audit trail.
See it on your own agentsThe decision engine
Four checks, one verdict, no guessing.
Before a tool runs, the gate asks four questions. An action only gets a grant when every ring is full. Anything short of that is held or sent to a person.
Illustrative. Fill shows how much of each requirement the action meets.
refund_payment ₹4,200The trust layer, in motion
One verification layer for every domain.
Your agent asks. qbrin pulls the evidence from your live systems and knowledge, verifies every claim against it, and only then lets the answer through — the same way whether it’s a security alert, an outage, a mission decision, or a payment. Verified decisions, or an honest “not enough evidence”, never a confident guess.
- Cybersecurity
- IT operations
- Defence
- Space & aerospace
- Finance
- Healthcare
- Legal
- Manufacturing
0/500
fabrications on nonexistent-entity traps
LlamaIndex: 11 · naive RAG: 155+
93.7%
precision when answering
LlamaIndex: 84.7% · naive RAG: 80.5%
88%
recall@20 on the retrieval bench
bge-m3 dense
74.9%
answer coverage
It abstains on roughly 1 in 4 answerable questions rather than guess.
Held-out HotpotQA benchmark, N = 1,350 per system, measured 2026-07-18/19. qbrin is not zero-wrong: 33 wrong of 524 answered. See the full benchmarks.
One gate at the tool boundary. Evidence, permission and policy, checked before anything runs.
Qbrin Labs
Measured, not claimed.
Every number here comes from a committed benchmark, with its sample size and its caveats. Where we do not lead, the write-ups say so.
0
Made-up answers
Across 120 trap questions on four corpora, Qbrin declined, or corrected the false premise with the cited real fact.
86%
Citations you can trust
of the sources Qbrin cites genuinely back the answer, with its double-checking on. Plain keyword search manages 6%.
100%
Always the current fact
Right after a fact changes, Qbrin gives the new value. A popular open-source memory tool gave the old one 3 times in 4.
88%
Finds the right source
of the time Qbrin finds the right source document before it answers.
Engineering notes
A safety gate that blocks 100% of attacks and 100% of real work looks perfect on the scoreboardWhy substring grounding checks reject valid operator commands.The most dangerous prompt injection is stopped by retrieval, not by detectionCredential-scoped boundaries at the retrieval plane.A 400-token cap on our verifier was silently dropping correct answersHow a fixed limit turned parser errors into silent refusals.See it answer
See it answer your hardest question.
Bring one real question your team keeps re-asking. We’ll connect a source, read-only, and show you the answer, sourced, in seconds, in a 20-minute walkthrough. Nothing changes in your tools.
- One source connected, read-only
- Your real question answered, with sources
- Nothing changes in your tools
or email hello@qbrin.com