About VaultOS

Autonomous finance, with boundaries

VaultOS is a spending limit for an AI that can move your money. The AI can analyse whatever it likes; it cannot move the line you drew.

The problem

Autonomous agents can reason and act. Giving one unrestricted authority creates a different problem: what happens when the agent proposes something outside the owner’s limits?

The usual answer is to put the limit in the prompt. But a limit a model is asked to respect is not a limit — it is a request, and it competes with every other instruction in the context. The failure case is not a model that reasons badly. It is a model that reasons persuasively toward something you never agreed to.

The approach

VaultOS separates reasoning from authorization, and keeps them in different code with no path between them.

SERVSuggestion
Says how risky a move looks and how much it would put in. It reasons freely because it cannot reach your rules or approve anything — which is what makes it safe to give a reasoning model a real wallet. If its answer is unreadable, it is thrown away rather than guessed at.
Policy engineDecides
Checks the move against the limits you set. Same question, same answer, every time — and if a rule can't be checked, the answer is no. It never sees what the AI said.
AgentKitExecution
Sends the transaction. Only what was approved, and only reported as done once a block confirms it.
Audit trailRecord
What was asked, what was allowed, what was refused, and which rule decided.

The rule underneath all of it: an AI never gets to decide whether a hard money limit has been met.

The current demo

VaultOS runs this workflow on Base Sepolia using synthetic opportunities and real testnet transactions. The wallet, the balances, the transfers and the confirmations are genuine and verifiable on a block explorer.

The six opportunities are invented examples, each written to exercise a different rule — three pass, three are refused. Testnet funds have no monetary value and cannot be exchanged for anything.

Use it from your own agent

VaultOS isn’t only a screen. The rules check is an HTTP endpoint, so any agent — in any language, on any stack — can ask “am I allowed to do this?” before it acts.

curl -X POST https://vaultos-rust.vercel.app/api/evaluate \
  -H 'Content-Type: application/json' \
  -d '{"opportunityId":"opp-volatile-strategy","amount":"0.01"}'

Comes back with the decision, the rule that produced it, and every rule that was checked:

{
  "ok": true,
  "decision": "REJECTED",
  "verdict": {
    "decision": "REJECTED",
    "violations": [
      {
        "code": "RISK_ABOVE_MAX",
        "message": "Opportunity risk HIGH exceeds the policy maximum of MEDIUM."
      }
    ],
    "evaluated": ["chain", "amount", "maxAllocationPercent", "maxRisk", "..."]
  }
}

That single call is the product, and it is the billable unit: you pay per decision, not per transaction. Refusals count — a refused action is the one that cost nothing and saved everything. The audit trail already meters every one of them.

What VaultOS is not

  • Not a way to make money. Nothing here earns anything.
  • Not a real investment service. Test network only — there is no real-money path in the code.
  • Not a trading bot let loose. Nothing runs that your rules did not allow.
  • Not financial advice. What the AI says is an opinion, shown as one.