SECTILE
Consequence quotas for payment processes

An agent may request.
It may not execute.

An AI agent can prepare and submit payments in your process. Sectile limits, within the controlled submission path, how much it can trigger in total before a renewed human approval is required. Even technically valid individual payments cannot add up without limit in this path.

Limits from your measured payment data. Enforcement in your environment, with no cloud-based third-party service.

Suitable for clearly bounded accounts-payable, treasury and payment processes in which autonomous software prepares or triggers payments.

ENFORCEMENT POINT · LIVE QUOTA ACTIVE
QUOTA TODAY 36’700 / 57'000 CHF
reserved and committed Limit · above it a human decides
REQUESTS FROM THE PAYMENT AGENT
4’800 RE-2026-0901 let through
12’400 RE-2026-0902 let through
9’000 SAL-05 approval needed
7’200 RE-2026-0908 declined (bank)
Sample values. No real payment traffic.
A demonstration with generated figures. The limit is 57'000 CHF per day; when the running total reaches it, the process stops and waits for a human.
01 · THE PROBLEM

Fully authorised, maximum damage

Companies do not put payment agents into production because they are authorised but not bounded. A misdirected or manipulated agent executes every single payment with technically valid authorisation and still produces an unacceptable total loss within minutes.

440 m

US dollars that Knight Capital lost on 1 August 2012 through millions of individual orders. Every order authorised, every one authenticated, every one permitted.

45 min

is how long it took. A clerk pauses at the third unusual transfer; an agent takes as long over the two-thousandth as over the first.

0

No attackers were required. A faulty reconciliation, a wrongly learned rule or a double-imported batch of invoices is enough.

What was missing was not access control. What was missing was an upper bound.

Knight Capital was a trading disaster, not an AI disaster. What is used here is the control principle, not a historical parallel.

Source: U.S. Securities and Exchange Commission, order of 16 October 2013 against Knight Capital Americas LLC (Release No. 34-70694), the first enforcement of the Market Access Rule. sec.gov

02 · DISTINCTION

Correctness is not quantity.
Authorisation is not a limit.

Existing controls answer important sub-questions. Sectile fills a gap that in many payment architectures is not controlled end-to-end: how much may a fleet of agents move in this process in total before a human steps in?

Control questionWho answers it todaySectile
Does the IBAN belong to the supplier?Trustpair, nsKnox, Eftsure, Verification of Payeenot the purpose
Is a change to a supplier master record legitimate?SAP Dual Control, four-eyes principlenot the purpose
May this agent call the payment function?IAM, Agent Identity, PAMa precondition, no protection against quantity
Is this individual payment plausible?Fraud Detection, Payment Screeningcomplements, replaces no quota
How much may a fleet of agents move in this process in total before a human steps in? In many architectures not end-to-end, delegation-bound and auditable Sectile
UNTIL NOW

Is this malicious?

Signature, anomaly, behaviour, voice. The answer depends on how the attack looks. Generative models have destroyed that assumption: the content is no longer distinguishable, and the tailored attack costs the same as the mass one.

SECTILE

How much may happen here at most?

Amount, count, payee, fleet total, delegation. The answer depends on the consequence, not on appearance. The cumulative damage possible via the controlled path is bounded by the quota, regardless of whether anyone recognises the trigger as malicious.

Three other disciplines made the same shift independently: Watt's centrifugal governor in 1788, the SEC's Market Access Rule of 2010 and fly-by-wire since 1988. None of them relies on detection.

03 · THE ENFORCEMENT POINT

Who enforces what

Sectile runs as customer-side control software over the existing banking relationship. It replaces no bank, no payment service and no signing authority.

The enforcement point runs in your environment; no external decision service is required for enforcement. Quota and delegation are signature-checked, classical and post-quantum, and Sectile verifies the signature itself.

Payment agent request_payment execute_payment requests Sectile Delegation, quota Payee list, velocity Purpose class, fleet total Reservation and proof submits Your bank Single-transaction limit Collective release, execution WHO ENFORCES WHAT The cumulative limit, in the controlled submission path The outer single-payment limit, the collective release
Two limits, two authorities. The bank enforces the outer single-transaction limit and the collective release. Sectile enforces the cumulative delegation limit in the controlled submission path. Together they make the statement; on its own each half is misleading.
A fully compromised Sectile cannot exceed the single-transaction limit held on the bank's side. Within the controlled submission path, Sectile decides on the cumulative delegation limit.

That limit sits in the contract between you and your bank, not in our software. So you do not have to trust the vendor without limit, and that answers the first objection of any supplier review.

04 · THE FIRST STAGE

Quotas on a payment process

A quota is a damage budget, not an account balance. It is reserved before execution and committed after confirmation. A reversal does not give it back, otherwise the limit could be recharged at will through payment and recall.

The last limit is the only one that even a human release cannot lift. In a group structure, a delegation to a subsidiary binds the parent's quota at the moment of issue, not at the first payment.

LimitCountsWhen exceeded
Amountper time window, per agentStop, release over a second channel
Number of paymentsper time windowStop, release over a second channel
Per payeeCount and sum to the same placeStop, release over a second channel
Purpose classInvoice, expenses, payroll, taxset per class, up to refused
Duplicate documentthe same invoice via two pathsStop, release over a second channel
Fleet totalall agents of the process togethereverything stops, reset by hand only
Delegationwhat a higher authority has passed onStop, even after human release
015'00030'00045'000 Daily limit across all payees, 57'000 Sum to this single payee, 15'000 per-payee limit applies from here release by a human Ten payments of 5'000 each to the same payee, all within one hour · solid let through, dashed stops
Salami payments: inconspicuous individual transactions with cumulative risk. Each single payment is inconspicuous, the daily limit across all payees is never reached. A total limit sees nothing here. The per-payee limit does. What is counted is how much may go to one place before a human watches.
QUOTA SIMULATOR

Submit a request

Starting point: 36'700 CHF of the daily quota of 57'000 CHF is used, the bank-side single limit is 25'000 CHF, each new payee is allowed 20'000 CHF, payroll is not delegated.

PURPOSE CLASS
PAYEE
DECISION OF THE ENFORCEMENT POINT
approval needed

per-payee limit reached

36'700 usedlimit 57'000

No judgement about intent. What is counted is solely how much may still happen.

05 · THE LIMITS

Measured, not estimated

Nobody knows in advance how much a normal accounts-payable agent moves in a day. Estimated limits are almost always too wide, because nobody wants to set them too tight. That is why a measurement without intervention comes first: Sectile runs along, refuses nothing, changes nothing and afterwards calculates what a limit would have cost.

50.90.99th percentile Proposal 99th percentile plus a quarter of headroom Daily total of an accounts-payable process, measured state of the sliding window at each transaction
The only set value in the whole report is the quarter of headroom above the 99th percentile. It catches outliers that did not occur during the measurement period. Everything else comes from your figures.

And the test of it

A limit that is derived from the same figures and tested against the same figures is bound to look good. That is not a proof but a circular argument. The measurement period is therefore split: the limits come from the earlier part, and they are measured solely against the later part, which they have never seen.

The report shows both figures and states which one applies. The less favourable one is decisive, because only it was measured against transactions that did not feed into its derivation.

06 · THE OBJECT OF PROOF

The impact-path map

Sectile provides no coverage ratio. For a defined payment process it provides a versioned inventory of the payment paths identified within the agreed scope of examination, and states the control status for each path.

IMPACT-PATH MAP · ACCOUNTS-PAYABLE RUN · VERSION 4
ERP payment run via payment hub Enforced with a dependency hub enforces
Direct bank API, treasury Hard enforced quota applies
Batch order via file transfer Observed only Stage 2 planned
Bank portal, manual entry Out of scope no agent access
Corporate cards and travel-expense system Residual path owner named

Uncontrolled paths do not vanish into a ratio. They stand by name in the proof, with owner, compensating control and control status. A coverage ratio would need in its denominator every consequence that is at all possible, and in a grown landscape those are neither complete nor objectively determinable.

Every decision processed by Sectile is additionally held in a hash-chained record. An auditor gets a root and, for each single entry, a path to it. They can recompute that this exact entry was in this exact record, without seeing the other entries. Payees and invoice numbers appear in it only as a key-dependent hash.

What Sectile supports: Sectile produces technical evidence that can support control objectives in DORA, ISO 42001 and AI-governance programmes. What Sectile does not promise: Sectile makes no agent compliant, and no regulator today requires consequence quotas.

07 · ORIGIN

The centrifugal governor

In 1788 James Watt did not invent a method that detects whether a steam engine is about to run away.

He built a governor that makes the question unnecessary. Two balls turn with the shaft, rise with the speed and thereby close the valve. The engine cannot get faster because it gets faster. Nothing is detected in the process.

The same shift lies behind the Market Access Rule after 2010 and behind the flight envelope in fly-by-wire. Sectile carries the idea into the payments of autonomous software.

Faster means further out means less steam

Who works with it

Heads of treasury and payments

have a finished payment agent that must not go live, because nobody can answer the release board's question.

Security and risk officers

need a control whose effect does not depend on detecting an attack.

Internal audit and compliance

require auditable proof with scope, exceptions, responsibilities and residual risk, and not a percentage.

What is sold is not a feeling of security but the ability to obtain release: a blocked project with a budget already spent becomes movable.

THE NEXT STEP

A measurement pilot on one process

Four to six weeks on a clearly bounded payment process. Sectile changes nothing and refuses nothing. At the end you have your path inventory, your measured distribution and a reasoned proposal for the limits.

The scope stays narrow, and that is a rule: a measurement pilot covers one process, never the entire payment traffic of a group.

REQUEST INFORMATION

The product brochure and a short overview. No sales pitch.

Or directly: hello@sectile.ch · Crownhill Capital AG, Bahnhofstrasse 29, 6300 Zug

Join as a pilot customer

Two design partners, six weeks of measurement, your figures. We reply within two business days.

No cookies, no trackers, no sharing for advertising. Your details serve solely to answer this enquiry.

METHOD

How Sectile works

This page is written for technical review. It describes what is built and, at the end, names what is deliberately missing.

01

Delegation instead of standing authorisation

An agent receives no standing payment authorisation. It receives a signed Delegation: purpose, set of payees, amounts, time window, validity. For the single transaction a short-lived, single-use execution ticket is generated from it.

The quota inside this delegation is a damage budget, not an account balance. This distinction is decisive: if a quota is treated like an account balance, it can become available again unintentionally through recalls, retries or unclear bank responses.

02

Passing on binds immediately

A group distributes its quota to subsidiaries, and the subsidiaries pass it on. The question on which such hierarchies fail is: may the sum of what the subsidiaries are allowed be greater than what the group has?

Not here. A subsidiary delegation charges the parent's quota at the moment of issue, not at the first payment. Three subsidiaries with two hundred thousand each under a parent with four hundred thousand are individually permissible and together an overrun by half.

Group treasury · 400'000 CHF per 30 days
150'000 bound
200'000 bound
50'000 free
Subsidiary Industry
150'000 · issued, bound immediately
Subsidiary Trade
200'000 · issued, bound immediately
Subsidiary Services
100'000 requested · declined, only 50'000 free
Without immediate binding the overrun only shows when everyone draws at once, that is, at the worst moment.
03

Reserve, commit, settle

Released does not charge Open waits, charges Committed accepted, charges Done paid out, charges Disputed unclear, charges confirmed settled confirmed non-execution unclear or contradictory response only via human reconciliation
In case of unclear execution the reservation stays charged until non-execution is proven. A reservation without a response stays in place: as long as nobody has confirmed that nothing was paid, the opposite must be assumed.
EventEffect on the quota
Payment confirmedReservation is committed bindingly
Payment declinedReservation is released against confirmed non-execution
Timeout, asynchronous confirmationReservation stays until a confirmation arrives
Partially executed batch orderfull batch sum reserved, reduction only against confirmed non-execution of the remainder
Bank status unclear or contradictorydisputed, stays budget-effective, is never released automatically
Reversal or recalldoes not give the quota back. Otherwise the limit could be recharged at will through payment and recall
Resend after a technical errorruns against the same reservation, no second charge
04

What happens when the bank does not answer

The most expensive case is neither acceptance nor rejection, but the unclear reply. Nobody knows whether payment was made.

The transaction becomes disputed. It keeps charging the quota and is never released automatically. No lapse of time ends this state, and neither does a later bank message, otherwise the last reply to arrive would have the final word.

The way out requires a document and two different people. This is not a second payment release: payment may long since have happened. What is decided is a quota that has been blocked ever since.

Without this list a business would only see that the quota is shrinking, and would not know why.

Disputed transactions therefore stand in a work list with amount, age and reason. A vanished budget becomes a task with an owner.

05

Three rules that an amount limit cannot express

Purpose classes

An accounts-payable agent may pay invoices and never payroll, not even small ones, not even to known payees. Purpose limits count separately from one another: expenses use no invoice quota. A purpose that nobody has defined goes to a human.

Per-payee limits

A daily limit across all payees does not see ten payments of nine thousand each to the same place. Count and sum per payee and time window do see them. Nothing is judged as suspicious; what is counted is how much may go to one place.

Duplicate documents

The transaction key recognises the same payment attempt after a technical error. The document hash recognises the same invoice, which comes in as two different payments, once from the inbox and once from the ERP system. That is the more frequent case and the more expensive one.

The fleet switch

Every single agent can stay within its bounds and the sum still produce a catastrophe. If the sum exceeds the limit, everything stops, including the agent that did nothing wrong. The reset is deliberately not automatic: a switch that resets itself is a delay, not a limit.

06

The proof

Every decision is recorded as an entry in a hash-chained, hash-secured record: time, agent, class, object, result, reason, quota state, version of the underlying quota.

  • The entries are chained via their hashes. A later change becomes recognisable via the hash chain, provided the corresponding root or time anchor is present unchanged.
  • Over time segments, seals are formed with a Merkle root. An auditor gets the root and, for each entry, a path to it.
  • Payees and invoice numbers appear in it only as a tenant-key-dependent hash. Whoever wants to check the plaintext presents it and recomputes.
  • For a time segment an external, signed timestamp can be obtained. Sectile checks its signature itself. An unsigned or backdated stamp does not count as proven.
  • The verification is available as a standalone tool. It strictly separates what is proven from what is only plausible, and in case of doubt lets nothing count as proven.

Hardened and on your premises. Sectile runs in your environment, with no external service. The reference implementation was reviewed in several independent attack rounds. Findings were documented, fixed and secured by regression tests.

Prepared for post-quantum. The approach is hybrid: a classical signature (Ed25519) and a post-quantum signature (ML-DSA-65) must both hold. Both schemes are written in-house, with no additional dependency and no network. The post-quantum part is checked against the official NIST vectors.

07

What is deliberately missing

The first stage deliberately focuses on a clearly bounded payment process. These points are open and are not presented as present.

OpenWhy
The automated exception pathis offered only once the technical separation of submission paths with the bank or provider is demonstrated
The legal rolewhether Sectile itself holds bank credentials is not fixed before the Swiss legal memo
The further four consequence classesCode and deployment, identity and rights, messages to the outside, data outbound. Specified, but not part of the first stage
The delivery path of the payment streaman adapter for pain.001 (ISO 20022, versions .03 and .09) is available. The concrete delivery path (file, SFTP, EBICS, API) remains open
MEASUREMENT PILOT

First measure, then enforce

Four to six weeks on a clearly bounded payment process. Without intervention, with your figures on your premises.

01

Three stages

StageContentWho decides
1 · Measurement pilot
four to six weeks
Path inventory, impact-path map, measurement without intervention, quota proposal. Changes nothing.Platform or process owner
2 · Enforcement
per controlled process
Quotas, per-payee limits, purpose classes, fleet switch, record of actions.Head of security, risk officer
3 · Proof
annual module
Tamper-proof quota record, scope and residual-path register, audit report.Compliance, internal audit

The measurement pilot is a clearly bounded, chargeable engagement. It covers the process mapping, the measurement in your environment and a documented quota proposal. The price depends on the process scope and is set transparently after the first conversation.

02

What is on the table at the end

01
The impact-path map

A versioned inventory of the identified payment paths with control status per path. Residual paths carry owner, compensating control and control status.

02
The measured distribution

Amount, count and distinct payees per hour and day, each with 50th, 90th, 95th and 99th percentile.

03
The quota proposal

99th percentile plus a quarter of headroom. This headroom is the only set value in the whole report.

04
The counter-calculation

What these limits would have cost during the measurement period, broken down by reason.

05
The test on unseen data

The period is split: the limits come from the earlier part, they are measured against the later one. The report shows both figures and states which one applies.

03

The sequence

W 1W 2W 3W 4W 5 Process scoping, data contract Path inventory, conversations on site Measurement without intervention, you keep the data on your premises Report The measurement needs at least one month-end, so the report does not describe only quiet weeks.
The effort on your side lies in the first two weeks. After that the measurement runs without anyone having to do anything.
04

What can be measured depends on seven fields

The most common reason a measurement fails is not the technology. It is an export missing a field. That is why the data contract comes at the beginning and not at the end.

FieldContentFor what
timestampISO 8601carries the sliding windows
amountinteger, smallest currency unitfloating point has no place in a payment process
currencyISO 4217must be uniform per file
payeeIBAN or creditor numberdistinct payees per day, per-payee limits
processname of the payment processbounds what is measured
triggerwho triggered the transactionseparates machine from human
transactionunique keyrecognises repeats after technical errors

If a file does not match the contract, the checking program names every objection with line number, field and reason and evaluates nothing. No half report arises from half data. The program is standalone and depends on nothing beyond the operating system's base library.

05

What the measurement pilot is not

No security audit. The pilot measures one process and says nothing about the other ways money is moved in your house. Those ways belong in the impact-path map, with a status per way.

No proof of effect. A period of four to six weeks does not contain the year-end close, no special payment and no acquisition. Before live operation at least one month-end belongs in the measurement.

No promise of availability. The measuring connection is read-only, with no standby service. If it fails, that costs nothing but measurement time.

And the scope stays narrow. A measurement pilot covers a clearly bounded payment process, never the entire payment traffic of a group. Otherwise the map tips from an entry point into a list of defects.

THE FIRST STEP

A one-hour conversation

We bound the process, go through the data contract and tell you whether a measurement pilot would show anything in your case. If a measurement pilot is unlikely to yield a robust insight, we do not recommend it.

COMPANY

Who is behind it

A venture of Crownhill Capital AG, Zug.

01

The industry's answer and why we give a different one

The industry answers autonomous software with better detection: more signals, more models, more context. We hold that to be the wrong axis. A control whose effect depends on detection is powerless exactly when nobody detects an attack.

The cumulative damage possible via the controlled path stays bounded. That is a weaker promise than security, and one that can be kept.
02

Patent status

The invention was filed on 3 September 2026 at the Swiss Federal Institute of Intellectual Property as a direct Swiss application. The institute's confirmation of deposit is on hand.

Application numberCH001189/2026
Filing date3 September 2026
TitleConsequence-Bounded Authorization of Autonomous Software Agents Using Credential-Bound Residual Quotas and a Two-Phase Reservation Ledger
Claims31
Filing languageEnglish
Statusunpublished patent application
Maximum term of protection if granted and maintaineduntil 2 September 2046

The scope of the granted claims is not yet fixed. The product principle is publicly explainable; concrete implementation details we disclose to banks, providers and design partners under a non-disclosure agreement.

“Filed for patent” means filed, not granted.

03

What we are looking for

Two design partners with a payment process in which software triggers payments today or soon, and with the willingness to let us measure for six weeks. In return you get your figures, influence on the design and terms that will not exist later.

If you are unsure whether your case fits: the first conversation lasts an hour; if a measurement pilot is unlikely to yield a robust insight, we do not recommend it. That is cheaper for everyone than a pilot that shows nothing.

04

Legal notice

ResponsibleCrownhill Capital AG
AddressBahnhofstrasse 29, 6300 Zug, Switzerland
Commercial registerUID CHE-101.159.394
Contacthello@sectile.ch
TrademarkSectile is a product name of Crownhill Capital AG

The respective provider is responsible for the content of external links. All information on this page serves as information and constitutes neither an offer nor a warranty.

05

Privacy

This website uses no cookies for analytics or marketing purposes and embeds no external maps, videos or reach measurement. For hosting, DNS, email and the operation of the contact form we use technically necessary service providers that process connection or communication data to the extent required. The following sections set out the details.

Controller

The controller for data processing is Crownhill Capital AG, Bahnhofstrasse 29, 6300 Zug, Switzerland. For privacy matters you can reach us at hello@sectile.ch.

Server operation and log data

On access the web server processes technically necessary connection data such as IP address, time of the request and requested file. This processing is required for the secure operation of the website; it serves to deliver the pages and to prevent misuse. The data is not combined into personal profiles and is automatically deleted after 14 days at the latest.

Contact

If you enter your details via a form or write us an email, we process the details it contains, such as name, organisation, email address and your message, to answer your enquiry and for any follow-up questions. We keep these details as long as required to handle the enquiry and delete them afterwards, unless statutory retention obligations apply.

Service providers

To operate the site we rely on carefully selected providers that process data on our behalf and on our instructions: hosting and DNS with Hetzner Online GmbH (Germany) and email delivery with easyname GmbH (Austria). Both process the data within the European Economic Area; no transfer to countries outside the EEA takes place.

No cookies, tracking or profiling

We use no cookies for analytics or marketing purposes, no tracking and no automated decision-making or profiling.

Your rights

Within the legal framework you have the right to information, correction, deletion and restriction of processing, to object to processing and to data portability. Please contact the address given above. You may also lodge a complaint with the competent supervisory authority, in Switzerland the Federal Data Protection and Information Commissioner, and in the European Economic Area the data protection authority responsible for you.

Swiss data protection law applies. For enquiries from the European Economic Area, the data-subject rights of the General Data Protection Regulation apply in addition. Last updated: September 2026.