The Second Signature
Before Money Moves.

SecondSign is the independent authorization and evidence layer for AI agents executing high-consequence transactions — a deterministic boundary on the execution path, in front of every irreversible action. Agent wallets are the first rail, not the product boundary.

Request access

The decision path

A deterministic checkpoint
for agent money.

Every action an agent takes to move money passes through one path, fail-closed, monotonic, and re-verified at the exact moment of execution.

Intent01

Immutable intent

Each action becomes a digest-bound intent. Raw account data never crosses the trust boundary.

intent_01H8QK… 
Decision02

Allow · Review · Deny

One monotonic verdict. Uncertainty always resolves to the strictest available path.

Allow Review Deny
Receipt03

Hash-chained audit

Every decision leaves a redacted, hash-chained receipt. No raw financial data, ever.

Hold high-value payments for a human

Actions above a policy threshold route to a one-shot, TTL-bound maker-checker before they can execute. Nothing moves until it is signed off.

Block anything that exceeds policy

Rules and providers evaluate every intent. Combining their judgements can only tighten the outcome, never widen what an agent is allowed to do.

Re-verify the amount at execution

The decided value is bound to an intent digest and re-checked the instant before the gateway executes. Decided value equals executed value.

Keep rail credentials out of reach

The agent holds no rail credential and has no network route to the rail. Stop SecondSign and it simply cannot move money.

Prove every decision after the fact

A hash-chained, redacted receipt records what was decided and why, without ever storing raw financial or customer data.

Guardrails

Control at the moment
money moves.

SecondSign decides, deterministically, whether an agent's action is allowed, and re-checks it the instant before any money actually leaves.

Where it fits

For every agent
that touches money.

Wherever an agent can move funds, SecondSign sits in front of it, the same deterministic checkpoint, whatever the rail or the workflow.

AP automation01

Invoice & payout agents

Agents that pay vendors and settle invoices, held the moment an amount crosses a policy threshold.

pay · vendor_4471 
Procurement02

Purchasing agents

Buying agents bound to approved vendors and spend limits - anything off the allowlist stops.

On allowlist Off - deny
Treasury03

Transfer & sweep agents

Movement between accounts and rails, with a human required the instant a move gets large.

Held for a human

What your team gets

Audit-ready by default

Every decision leaves a hash-chained, redacted receipt - prove what happened without ever storing raw financial data.

No credential exposure

Agents never hold a rail credential or a route to the rail. Stop SecondSign and money simply cannot move.

A human on the hook

High-value actions wait for a real, TTL-bound signature before anything executes. Agents act; people stay accountable.

Agents execute.
Humans decide.

Agents reach the rails only through SecondSign. Humans own the policies and the approvals, through the API, the CLI, or the console.

PaymentOrderTransfer
intentpay · vendor_4471
amount$ 42,500.00
policyover threshold
decisionReview
approvalSigned · TTL 5m

Put a second signature on
every agent that moves money.

Request access