I make AI agents safe to run on customers’ data and money.

I built PANTHEON solo: AI assistants that take bookings, message guests and run a business's website, in production. Their limits aren't a system prompt: every action passes a layer the model can't change, which checks whose business it is, what it may spend and whether a person must approve. What is PANTHEON? →

Looking for: a founding or early role owning an AI agent's trust boundary. Cardiff, UK; open to relocate.

Try to break it → Work with me

↓ turn · plan · tool · verdict: the gates every request crosses, lit by the live feed.↓ A demonstration turn. After this, only real traffic moves it.For example, a guest asks to book dates: the assistant sends the request, and nothing is booked until the owner confirms. Bookings and payments always wait.

Live · not a recording

Don't take my word for it. Ask it.

This site's assistant runs on PANTHEON. Every message is checked before it answers, and the panel shows the checks for yours. Try to break it.

PANTHEON assistant
this site's assistant · live
the proof

One real defect, start to finish.

The bug. WhatsApp and Telegram history was stored under the guest's phone number alone, so a guest who messaged two businesses could have the first conversation loaded into the second business's assistant.

Caught by my own adversarial audit in July: not a customer, and not the test suite, which had passed. Fixed by keying the history to the business as well. Kept fixed by a test that fails if the old key comes back.

An outside check: I'm a credited reporter (one of seven) on CVE-2026-104850 ↗, a high-severity flaw in the MCP TypeScript SDK.

what holds, and what doesn't yet

What it guarantees, and what it doesn't.

Each business's data is walled off by the database. Each request is bound to its business by a signed key, and a query for another business's rows returns nothing. Three sign-in and payment tables are guarded in code instead.
Help comes before billing. A person in crisis gets help free, ahead of every cap and charge.
Money moves atomically. Each charge and refund is keyed, so a retry can't repeat it. Internal credits only so far: no real charges between businesses yet.

Not solved: prompt injection (limited by scoping, an audit judge and human approval; nobody has solved it), and scale past one production instance (designed for, unproven). The full list → The architecture →

Built solo. Running in production. Open to the right team.

If your AI agent is about to touch real customers' data or money, that's the job I want. Let's talk.

Read my one-page CV →