Your claims agent has been ready for months. It is still sitting in staging because nobody will sign their name to it.
Arc Intelligence breaks your agent in a sandbox, shows you exactly what it can be made to do, then installs the control layer that stops it. Findings in 14 days. Production in six weeks. Your risk officer gets an audit trail they will actually sign.
The call is free· Sandbox only, never touches production· Three unauthorized actions or you pay nothing
The 20-minute call costs nothing. The Breach Test that follows it is $6,000, fixed.
Attack library
30 documented attack paths against claims agent workflows
Turnaround
Findings delivered in 14 days
Regulatory
EU AI Act Article 14 oversight evidence pack included
The agent is not the risk. The signature is.
The agent was built. It passed testing. It has been in staging for four months. Every week it sits there, the backlog grows and the board asks why the automation they approved has not shipped.
The board is pushing automation. Risk is blocking it. Security wants an answer nobody has given them. And the reason nobody will release it is not technical. It is that the moment it goes live, one person owns every decision the agent makes.
One wrongly auto-approved claim at a carrier this size costs $10,000 to $50,000. Under the EU AI Act, a breach is capped at €35 million or 7% of global turnover. Nobody wants their name on that release note.
Arc does not ask you to trust the agent. We prove what it can be made to do, close every path we found, and put a hard boundary and a named human in front of it. The accountability for the guardrails moves off your desk.
What everyone else sells
- A tool
- Model-level safety
- A dashboard
- Guidance
- And someone else operates it
What Arc sells
- Proof of the gap before the fix
- A gateway that freezes rather than proceeds
- A named analyst on the other end of every frozen case
- An audit trail the regulator will accept
A $6,000 Breach Test that tells you exactly how far your agent can be pushed.
01
We never touch production.
Sandbox access only, using your real claim document types. Your security team gets a scope document before anything starts.
02
We attack it the way an actual claimant would.
Indirect prompt injection through uploaded PDFs, payout and approval boundary tests, and attempted data exfiltration, run from a written library of 30 documented attack paths rather than improvised.
03
You get video of your own agent doing something it should not.
Not a report describing a risk. A recording of the action, with the input that caused it.
04
A findings report you can hand to your board without translating it.
Written for the people who sign, not for engineers.
05
A control policy file you can implement yourself.
If you want to fix it in-house, the file is yours. We will retest it for $4,500 when you are done.
06
An EU AI Act Article 14 oversight evidence pack.
Human oversight documentation your compliance officer can file, prepared alongside the findings.
07
A live walkthrough, not a PDF drop.
We take you and your risk officer through every finding on a call.
08
Findings in 14 days.
From sandbox access to a report on your desk.
If we cannot induce at least three unauthorized agent actions, you pay nothing.
How it works
01
Tell us what your agent is allowed to do.
A free 20-minute call. If the fit is wrong we will say so on that call, before you have spent anything.
02
We get sandbox access, and your security team gets the scope in writing.
No production systems, no live claims data required.
03
We spend 14 days trying to break it.
The Breach Test is $6,000, invoiced after the call, fixed. You get the video, the findings report, the control policy file and the Article 14 pack.
04
You decide what to do with what we found.
Implement it yourself, or have us install the containment layer and run it.
What happens after
Aegis MCP, the containment build.
A gateway installed between your document storage and the model. Cryptographic identity tokens for every authorized agent. Documents sanitized so hidden instructions are stripped before the model reads them. PHI and PII scrubbed on outbound calls. Hard boundary rules written against your actual claim types. When the agent hits one, it freezes instead of proceeding.
Escalations land where your people already work, and the logging is built to be read by an auditor. It ends with a written retest proving the attacks from your audit now fail. Multiple instances run behind health checks with automatic failover, on a 99.9% uptime commitment backed by service credits. Live in six weeks.
The Agent Operations Center, the human layer.
A named analyst reviews every frozen case, reads the telemetry and prompt history, and approves, rejects or escalates it. Four business hour response, guaranteed.
A monthly report your risk officer can forward without editing. Boundary rules tuned every month so the same exception stops recurring. Quarterly recertification against your live configuration, with a dated certificate.
Aegis stops the damage. The AOC clears the queue. Pricing depends on your stack and we quote it after the findings, not before.
The questions you were going to ask anyway
Our security team will never allow this.
They should not have to. The Breach Test is sandbox only and never touches production. Your security lead gets the scope in writing before access is granted, and they can revoke it at any point.
Our vendor already handles this. We have guardrails in Copilot Studio.
Your vendor secures the model. Nobody in that chain is accountable for the workflow, and the payout decision happens in the workflow. One question worth asking internally: when the agent does something wrong, who signs the incident report?
What if your gateway breaks and claims stop flowing?
Claims do not stop and nothing gets lost. Documents keep landing in your storage exactly as they do today. What pauses is the agent processing them, so work queues up and drains in order once service resumes. Claims intake runs on a days-long service level, not a seconds-long one, so an outage costs you a delay, not a claim.
You also get a documented break-glass path. You trigger it, not us, and it routes documents straight to your existing manual process, the same one you ran before you had an agent. Every bypass is logged and time-limited so it cannot quietly become permanent. We are never a single point of failure in your claims flow. In the worst case you work the way you did last year.
On the infrastructure itself, the gateway runs multiple instances behind health checks with automatic failover, and we commit to 99.9% uptime backed by service credits.
One thing people often mix up: an agent freezing because it hit a boundary is not an outage. That is the product working. One claim stops for human review while everything else keeps moving.
What does the call cost?
Nothing. The 20-minute call is free and there is no proposal fee. If we both decide to go ahead, the Breach Test is $6,000, fixed, invoiced before the sandbox work starts. Nothing else is quoted until you have seen the findings.
What is your liability?
Capped at trailing twelve months of fees, the same as any managed service. I take operational responsibility for the guardrails inside that cap and I will not claim more than that.
You are based in South Africa.
Yes. Nothing in the delivery requires me in the room, and the timezone means the overnight queue is being watched while your team is asleep. Every finding, report and certificate is documented and verifiable.
You already know the agent works. The question is what it does when someone feeds it something you did not write.
Twenty minutes. If your deployment is not exposed, I will tell you on the call and we both save the money.
The call is free· Sandbox only, never touches production· Three unauthorized actions or you pay nothing
The call is free. The Breach Test that follows is $6,000, fixed. Three unauthorized actions or you pay nothing.