Legal
Terms of Service
Draft for the proof of concept. These terms describe how Sentinel is meant to work and who is responsible for what. They are not legal advice and must be reviewed by counsel before any commercial launch.
In short
- Sentinel is a decision-support layer. It strongly reduces the risk of fraudulent agent payments, but no filter can stop every fraud.
- A payment that Sentinel approves and that leaves on a blockchain is final: it cannot be reversed like a bank transfer.
- If a fraud gets through, we help you report it, stop it from spreading, trace the funds and prove exactly why Sentinel said yes.
- Unless a written agreement or insurance says otherwise, Sentinel does not reimburse losses. You remain in control of your agents, mandates and limits.
01The service
Sentinel ("we", "the Service") is a payment guard for AI agents. Your agent calls our MCP tool verify_payment before a payment leaves. Sentinel analyses the order and what the agent read, gives it a trust score, and returns one of three decisions: approve, needs a human or block. Each decision is recorded on Sentinel L1, our Avalanche L1 blockchain.
By creating an account or connecting an agent to Sentinel, you ("the Customer") accept these terms.
02What we don't guarantee
Sentinel evaluates each payment with the information available at the time of the check. It can be wrong in two ways:
- False positive: a legitimate payment is held or blocked. You can always approve it as a human.
- False negative: a fraudulent payment is approved. This is the case these terms are mostly about.
False negatives can happen in particular when:
- a known supplier's mailbox is compromised and a new payment address is sent from it (payment-detail change fraud): the beneficiary, the amount and the habits all look normal;
- a fraud is split into small, repeated amounts that each stay under the thresholds;
- a prompt injection is subtle enough to stay within the agent's mandate;
- an address is clean when it is checked and is only used for theft afterwards.
We do not promise that Sentinel detects 100% of frauds. Figures we publish (for example detection rates on our red-team bench) describe tests, not a guarantee.
03On-chain finality
When Sentinel approves a payment, a one-time visa is issued and the payment can leave. Once a payment is settled on a public blockchain (such as the Avalanche C-Chain), it is final: there is no chargeback or recall mechanism like a bank's. Funds that have left can only be recovered afterwards, if at all, through the steps in section 4.
04If a fraud gets through
When a payment approved by Sentinel turns out to be fraudulent, we commit to the following, on a best-effort basis:
Report it from your dashboard ("Report a fraud") or by email. Often the real supplier claims its payment, or your own customer notices. Tell us as soon as you know.
We revoke the agent's outstanding visas and can pause its protected payments. The thief's address is added to Sentinel's on-chain threat registry, so every other Sentinel customer refuses it immediately.
We follow the funds on-chain. If they reach an exchange, the exchange can be asked to freeze the account; some stablecoin issuers (for example Circle for USDC) can freeze an address, usually at the request of the authorities. This sometimes works. It is never guaranteed.
We provide the full decision record (section 5): exactly why Sentinel approved the payment, and when. You can use it for a police complaint, your insurer, and your regulatory incident report.
The case becomes a test scenario. We re-check similar pending payments and adjust signals and thresholds, for all customers.
05The decision record
For every payment it checks, Sentinel keeps a record of how the decision was made:
The decision and its short reason are written on Sentinel L1 and cannot be altered afterwards. The full record is available to you on request and through your dashboard.
06Regulatory reporting
If you are a financial entity under the EU Digital Operational Resilience Act (DORA), you remain responsible for classifying and reporting ICT-related incidents to your competent authority. For major incidents, DORA and its technical standards currently require an initial notification within a few hours of classification and no later than 24 hours after becoming aware of the incident, followed by intermediate and final reports. Check the applicable texts for the exact deadlines.
Sentinel supports you by making the decision record available without delay, in a format suited to incident reports, audits (DORA, MiCA) and AML investigations.
07Liability
Sentinel is a decision-support tool. Unless a separate written agreement, warranty or insurance policy says otherwise:
- we do not reimburse losses resulting from a payment approved by Sentinel, by you, or by a human reviewer;
- our total liability is limited to the fees you paid for the Service during the twelve months before the event;
- we are not liable for indirect losses, or for losses caused by your agents, your keys, your mandates or third-party services.
Nothing in these terms limits liability that cannot be limited by law, in particular for fraud or gross negligence on our side.
08Your responsibilities
- Define each agent's mandate: allowed actions, allowed recipients, per-payment and daily caps.
- Keep your keys and credentials secure. Sentinel never needs your private keys.
- Review payments held for a human in good time, and report suspected fraud as soon as you know.
- Do not rely on Sentinel as your only control for high-value payments.
09Recommended safeguards
Because on-chain payments are final, the best protection is to limit the worst case before it happens:
- Caps per payment and per day in each agent's mandate, so that a single mistake stays small.
- A human review for large amounts and first payments to new recipients.
- An alert when a known supplier's payment details change: this is exactly the signal of payment-detail change fraud.
- A hold period for large or first-time payments, during which a payment can still be cancelled. This is on our roadmap.
10Data
To check a payment, Sentinel processes the order (issuer, recipient, amount, action), the content the agent read, and context such as the merchant's domain. Records on Sentinel L1 are public and permanent: do not put personal data in fields that end up on-chain. The proof of concept uses fictitious data only.
11Changes & contact
We may update these terms; we will tell you before material changes take effect. Questions, or a fraud to report: contact@petroi.fr.
Sentinel