The firewall for agentic commerce.

AI agents can hold cards now. Layne checks every spend request against your policy before it reaches the payment rails.

Coming Soon
dashboard
Requests decided this month
1,284
Declined at the network
2
Routed under policy
$3,218
Status: Under budget
Sample data
ALLOWED(IN_POLICY)openai · api$96.00
DECLINED(AGENT_FROZEN)agent · scraper-bot$12.40
ALLOWED(IN_POLICY)vercel · deploy$40.00
DECLINED(OVER_MONTHLY_CAP)anthropic · api$210.00

How it works

01
Write the policy.
Budgets per vendor. Budgets and scope per agent. Warning thresholds that fire before limits bite. Plain rules your whole team can read.
02
Put Layne in the path.
Every vendor gets its own virtual card with a hard cap. Every agent gets its own key and budget. Nothing spends from a shared pool, so nothing can drain one.
03
Every request gets a decision.
In policy, approved in real time. Out of policy, declined at the card network with a reason code, and an email to you instead of a bill.

An agent with your card is an employee with no fear of being fired.

So don't give it your card. Give it a Layne key with its own budget and a kill switch. Start in shadow mode and watch what it would have spent. Flip to enforce when you trust it. If it goes off-script, the next call returns DECLINED (AGENT_FROZEN), not a line on next month's invoice. Every decision, allow or decline, lands in a stream you can read and export.

DECLINED(AGENT_FROZEN)

Your team spends under the same firewall.

Every SaaS, cloud, and AI vendor gets its own dedicated card with a hard limit you set. If a vendor charges more, the card declines and you get an email instead of a bill. A compromised vendor can only ever spend its own card's limit. A leaked card is a $96 problem, not a company problem.

Admins control everything. Members own their vendors. Viewers see it all.

Blast radius, contained.
One card per vendor means one vendor per card. Your account number never touches a billing page, and no single leak can reach past its own cap.
Every decision on the record.
Every allow and every decline is logged with its reason code. When someone asks what happened, you paste the line, not a guess.

Questions

What is an agentic commerce firewall?

A policy layer between software that spends and the payment rails. It checks every request to spend before authorization and returns an approval or a decline with a machine-readable reason. Dashboards report spend after it happens. A firewall decides whether it happens.

What happens at the cap?

The charge declines at the card network. You get an alert immediately, and one click raises the cap if the charge was legitimate.

Will a decline break production?

Only if you choose hard declines. You can set warning thresholds, approvals instead of declines per vendor, auto-approve rules for small overages, and shadow mode. Hard declines are a choice, not a default.

Where does my money sit?

In your Layne balance, a money management account. Cards spend from that balance and can never exceed it.

Security, plainly

Card credentials live in a PCI-DSS Level 1 environment and never touch our servers. Data is encrypted in transit and at rest. The security page says exactly what we have and what we don't.

Read the security page

The next request to spend is already queued. Put a firewall in front of it.

Coming Soon
Layne | The Firewall for Agentic Commerce