AI agents can now hold wallets and pay for things autonomously — tools, APIs, and each other, at machine speed. Every rail (Coinbase, Stripe, Visa, x402) answers how an agent pays. Almost nobody answers the question every team asks first: how do I stop it from overspending? SpendVeto is the buyer-side policy layer that sits above any rail and decides — before a single dollar moves.
An agent with a wallet is a corporate card with no limit, issued to software. Runaway loops don't get tired — they get invoiced. As agent-to-agent and agent-to-service payments become normal, someone has to sit between the agent and its money and ask: is this call within policy, within budget, within scope, and did a human sign off if it needed one? That's the layer every payment rail assumes already exists. It mostly doesn't. SpendVeto builds it.
SpendVeto is built in public and verified in public. Every feature on the site is backed by an assertion in npm run verify — if a control isn't exercised by a real, running test, it doesn't ship as a claim. We'd rather under-promise on the marketing page than ship a control that only works in a demo.
SpendVeto is built by a solo founder currently building in the open, prototyping fast, and shipping governance primitives (policy engine, nested budgets, kill switches, MCP middleware) ahead of most of the market's payment rails. Reach out via the contact page — happy to talk to early design partners, security reviewers, or anyone thinking about the buyer side of agentic commerce.