Fully authorised, maximum damage
Companies do not put payment agents into production because they are authorised but not bounded. A misdirected or manipulated agent executes every single payment with technically valid authorisation and still produces an unacceptable total loss within minutes.
What was missing was not access control. What was missing was an upper bound.
Knight Capital was a trading disaster, not an AI disaster. What is used here is the control principle, not a historical parallel.
Source: U.S. Securities and Exchange Commission, order of 16 October 2013 against Knight Capital Americas LLC (Release No. 34-70694), the first enforcement of the Market Access Rule. sec.gov
Correctness is not quantity.
Authorisation is not a limit.
Existing controls answer important sub-questions. Sectile fills a gap that in many payment architectures is not controlled end-to-end: how much may a fleet of agents move in this process in total before a human steps in?
| Control question | Who answers it today | Sectile |
|---|---|---|
| Does the IBAN belong to the supplier? | Trustpair, nsKnox, Eftsure, Verification of Payee | not the purpose |
| Is a change to a supplier master record legitimate? | SAP Dual Control, four-eyes principle | not the purpose |
| May this agent call the payment function? | IAM, Agent Identity, PAM | a precondition, no protection against quantity |
| Is this individual payment plausible? | Fraud Detection, Payment Screening | complements, replaces no quota |
| How much may a fleet of agents move in this process in total before a human steps in? | In many architectures not end-to-end, delegation-bound and auditable | Sectile |
Is this malicious?
Signature, anomaly, behaviour, voice. The answer depends on how the attack looks. Generative models have destroyed that assumption: the content is no longer distinguishable, and the tailored attack costs the same as the mass one.
How much may happen here at most?
Amount, count, payee, fleet total, delegation. The answer depends on the consequence, not on appearance. The cumulative damage possible via the controlled path is bounded by the quota, regardless of whether anyone recognises the trigger as malicious.
Three other disciplines made the same shift independently: Watt's centrifugal governor in 1788, the SEC's Market Access Rule of 2010 and fly-by-wire since 1988. None of them relies on detection.
Who enforces what
Sectile runs as customer-side control software over the existing banking relationship. It replaces no bank, no payment service and no signing authority.
The enforcement point runs in your environment; no external decision service is required for enforcement. Quota and delegation are signature-checked, classical and post-quantum, and Sectile verifies the signature itself.
A fully compromised Sectile cannot exceed the single-transaction limit held on the bank's side. Within the controlled submission path, Sectile decides on the cumulative delegation limit.
That limit sits in the contract between you and your bank, not in our software. So you do not have to trust the vendor without limit, and that answers the first objection of any supplier review.
Quotas on a payment process
A quota is a damage budget, not an account balance. It is reserved before execution and committed after confirmation. A reversal does not give it back, otherwise the limit could be recharged at will through payment and recall.
The last limit is the only one that even a human release cannot lift. In a group structure, a delegation to a subsidiary binds the parent's quota at the moment of issue, not at the first payment.
| Limit | Counts | When exceeded |
|---|---|---|
| Amount | per time window, per agent | Stop, release over a second channel |
| Number of payments | per time window | Stop, release over a second channel |
| Per payee | Count and sum to the same place | Stop, release over a second channel |
| Purpose class | Invoice, expenses, payroll, tax | set per class, up to refused |
| Duplicate document | the same invoice via two paths | Stop, release over a second channel |
| Fleet total | all agents of the process together | everything stops, reset by hand only |
| Delegation | what a higher authority has passed on | Stop, even after human release |
Submit a request
Starting point: 36'700 CHF of the daily quota of 57'000 CHF is used, the bank-side single limit is 25'000 CHF, each new payee is allowed 20'000 CHF, payroll is not delegated.
per-payee limit reached
No judgement about intent. What is counted is solely how much may still happen.
Measured, not estimated
Nobody knows in advance how much a normal accounts-payable agent moves in a day. Estimated limits are almost always too wide, because nobody wants to set them too tight. That is why a measurement without intervention comes first: Sectile runs along, refuses nothing, changes nothing and afterwards calculates what a limit would have cost.
And the test of it
A limit that is derived from the same figures and tested against the same figures is bound to look good. That is not a proof but a circular argument. The measurement period is therefore split: the limits come from the earlier part, and they are measured solely against the later part, which they have never seen.
The report shows both figures and states which one applies. The less favourable one is decisive, because only it was measured against transactions that did not feed into its derivation.
The impact-path map
Sectile provides no coverage ratio. For a defined payment process it provides a versioned inventory of the payment paths identified within the agreed scope of examination, and states the control status for each path.
Uncontrolled paths do not vanish into a ratio. They stand by name in the proof, with owner, compensating control and control status. A coverage ratio would need in its denominator every consequence that is at all possible, and in a grown landscape those are neither complete nor objectively determinable.
Every decision processed by Sectile is additionally held in a hash-chained record. An auditor gets a root and, for each single entry, a path to it. They can recompute that this exact entry was in this exact record, without seeing the other entries. Payees and invoice numbers appear in it only as a key-dependent hash.
What Sectile supports: Sectile produces technical evidence that can support control objectives in DORA, ISO 42001 and AI-governance programmes. What Sectile does not promise: Sectile makes no agent compliant, and no regulator today requires consequence quotas.
The centrifugal governor
In 1788 James Watt did not invent a method that detects whether a steam engine is about to run away.
He built a governor that makes the question unnecessary. Two balls turn with the shaft, rise with the speed and thereby close the valve. The engine cannot get faster because it gets faster. Nothing is detected in the process.
The same shift lies behind the Market Access Rule after 2010 and behind the flight envelope in fly-by-wire. Sectile carries the idea into the payments of autonomous software.
Who works with it
have a finished payment agent that must not go live, because nobody can answer the release board's question.
need a control whose effect does not depend on detecting an attack.
require auditable proof with scope, exceptions, responsibilities and residual risk, and not a percentage.
What is sold is not a feeling of security but the ability to obtain release: a blocked project with a budget already spent becomes movable.
A measurement pilot on one process
Four to six weeks on a clearly bounded payment process. Sectile changes nothing and refuses nothing. At the end you have your path inventory, your measured distribution and a reasoned proposal for the limits.
The scope stays narrow, and that is a rule: a measurement pilot covers one process, never the entire payment traffic of a group.
The product brochure and a short overview. No sales pitch.
Or directly: hello@sectile.ch · Crownhill Capital AG, Bahnhofstrasse 29, 6300 Zug
Join as a pilot customer
Two design partners, six weeks of measurement, your figures. We reply within two business days.
No cookies, no trackers, no sharing for advertising. Your details serve solely to answer this enquiry.