AI agents that operate your real software the way your team does: on screen, through APIs and tools, under guardrails you set.
Supervised until proven. Autonomous once trusted.
52-second preview · watch the full 6-minute demo
Everything on this page is real: live software, real runs, synthetic data. Payment and purchase decisions always remain with your people, in every mode.
Built for regulated back offices: insurance, healthcare, financial services, and any team that cannot ship its data to an AI vendor.
The browser is the universal interface, and it is not the only one. Agents take the best door each system offers, and every door passes through the same guardrails: one allow-list, one approval gate, one audit chain.
The interface every system has. If a person can work it on screen, an AI agent can too. No integration project required.
Where a system exposes an API, the agent calls it directly: faster, structured, exact. Every call is fenced to approved endpoints, and writes park for approval just like a click.
Agents query your databases with fenced, read-only access, and produce the documents and spreadsheets your workflows need. Everything stays inside your boundary.
Agents connect to Model Context Protocol servers, bringing enterprise tools inside your fence. Each MCP tool is allow-listed per use case, and consequential calls park for approval like everything else.
Eight steps from a plain-language description to a measured, audited AI workforce.
You create a use case the way you would brief a new teammate: a few sentences about the goal, the systems, and the rules. The copilot drafts the full working specification. No code, and no integration project.
Every use case carries its own governance: an approval checkpoint before anything posts, an explicit allow-list of actions, and a domain fence the agent cannot leave. Guardrails are enforced deterministically, not suggested to the model.
The agent signs in with vaulted credentials it never sees, reads the vendor invoice in Box, and drafts the bill in Wave field by field, matching the total to the penny. It works the same screens your team uses today, and where a system offers an API or a tool, it takes that door under the same governance.
Before anything consequential, the run parks and asks. A reviewer sees exactly what was prepared and approves it; only that approved action continues. And in every mode, payment and purchase decisions remain with your people.
Supervised is where a use case starts, not where it ends. When one has earned trust, you promote it: it runs end to end with zero human touches, still inside its fence, still on the audit chain. That is the trust dial.
Every run keeps its outcome, the structured record, and step-by-step visual evidence of what the agent actually did. Every action lands in a tamper-evident audit chain, attributed to a named human or agent identity, verified on demand.
Acting on web pages is only one doorway. The agent connects to your APIs, your data, and any system that speaks MCP, under the same fence and allow-list. Two claims, one run: one auto-filed, one routed to review, decided by a policy document your team writes.
Nobody clicks Run. The use case watches the intake feed and sweeps on a schedule. One run, eighteen governed calls across the warehouse, the API, MCP, and a legacy screen, every one fenced, audited, and on the chain.
The 6-minute product video: a use case created by description, governed, run live, approved by a named human, promoted to autonomous, connected to APIs, data, and MCP, and proven at scale on the audit chain. Filmed on Box, Wave, and a synthetic claims stack (payer API, claims warehouse, MCP service), standing in for the document, accounting, and claims systems your team already uses.
Sovereignty is not a deployment option; it is the default. The four answers your security team will ask for first:
Inside your trust boundary: your VPC or your own hardware, deployed on your Kubernetes. The agents, the model, the browser, the tools, the data, and the evidence all live there.
A self-hosted open model, served on your GPUs. No calls to a model vendor, no per-seat fees, and no closed-source runtime in the stack.
Nothing. Screens, documents, credentials, and model traffic stay inside. Egress is off by default and only ever opened per use case, by you, with the change on the audit chain.
You do: your identity provider, enforced role-based access, authenticated approvals, and a tamper-evident audit chain you can verify and export.
Each of these follows the pattern behind most back-office work: take a document, work the system of record, prove the result. Every flow starts supervised, earns its autonomy, and is measured: completions, exceptions, and ROI per use case.
Reads a vendor invoice and drafts the bill, line by line. Parks for approval before anything posts.
Prepares a customer invoice from a statement of work. Parks before sending.
Turns a W-9 into a finished vendor record with zero human touches. Promoted after proving itself supervised.
Verifies a claim against the payer API and a versioned policy document. Auto-files what qualifies and routes what does not to review.
One governed run, eighteen governed calls: queries the warehouse, verifies members over the API, flags via MCP, works a legacy screen, and delivers the report.
Your back office runs on an ERP, HR, claims, or policy admin system instead? If a person can operate it on screen, or it exposes an API, an agent can be taught to.
Autonomy is only useful if you can adopt it, prove it, and answer for it.
Everything needed to run an agent runs inside your trust boundary: your VPC or your metal, a self-hosted open model, your data never leaving. No model traffic crosses the boundary unless you explicitly permit it per use case.
Logins live in an encrypted vault and are injected as masked placeholders at run time. Credential values never reach the model context, the logs, or the artifacts.
Console access is delegated to your own IdP with enforced role-based access. Approvals are authenticated, so the platform can prove who approved what.
The approval gate, the action allow-list, the domain fence, and the payment hard stop are enforced in code, outside the model. A clever prompt cannot talk its way past them, whether the agent is clicking a screen or calling an API.
SOC 2 and HIPAA control sets are built into the platform. The formal attestation program is underway.
No closed-source runtime dependencies and no per-seat fees. The stack deploys on your Kubernetes, on the clouds you already run.
We are onboarding a small number of design partners: operations teams in insurance, healthcare, financial services, and other regulated back offices. The exchange is simple:
One high-volume, rules-driven workflow your team runs on screen today, and the software it runs on.
Hands-on deployment inside your boundary and your first use cases built with you, supervised from day one, measured from the first run.
Direct influence on the roadmap and founding-customer terms that stay with you as the platform grows.
The first step is a short note: the workflow, the software it runs on, and roughly how many times a month your team does it. That is enough for a first conversation.