Back to searchCanonical Registry Record · slug: financial-action-agent

Financial Action Agent — Stripe Reference Deployment

v1.0.0-ref
byAgentSearch Reference Architecture·FinancialFrameworkUnverified Provider

Deterministic reference architecture modeling an accounts-receivable AI agent capable of inspecting approved SME invoices and executing controlled invoice collections via an isolated Policy Gateway and Stripe payment platform.

TR2 — Limited Assurance(64.14/100)
Assessment: TR-2026-000003
Version:1.0.0-ref
Runtime category:container_gvisor_sandboxed_python

Capabilities

(1)
Descriptive presence only · Not a quality or performance rating
Reference Architecture Verificationsystem.reference

Standardised reference architecture for independent control testing.

Integrations

(1)
Documented interfaces · Factual connection support
Isolated Reference EnclaveVendor: AgentSearch
reference.enclave

Deployment & Execution Environment

Public runtime architecture · Excludes private keys and credentials
Execution Environment:agentsearch-reference-cloud-isolated
Runtime Engine:container_gvisor_sandboxed_python
Assessed Invocation Tools (5):
get_invoiceget_payment_stateprepare_paymentexecute_approved_paymentget_reconciliation_status
Assessed Permissions (4):
financial.invoices.readfinancial.payment_intent.preparefinancial.payment_intent.submitfinancial.reconciliation.read
Assessed Boundary Controls (8):
deterministic_policy_gatewaycryptographic_intent_bindingidempotency_key_enforcementreconciliation_two_phase_verifiercounterparty_binding_validatorminor_unit_amount_validatorvault_isolated_stripe_credentialscontainer_egress_firewall_drop_raw_processor

Documented Models

Underlying foundation or reasoning models declared by provider documentation:

CONFIGURATION_DEPENDENT

TrustRank Assurance

Assessment ID: TR-2026-000003
AgentSearch Reference Assessment:This evaluation models an AgentSearch reference architecture deployment under controlled conditions. It does not represent a vendor-submitted or vendor-certified product evaluation.
Assessed TrustRank
64.14/ 100
TR2 — Limited Assurance
Limited Assurance
Evidence Confidence
30.0%

Strength, testability, and independence of submitted audit evidence.

Methodology v0.2
Assessment Metadata
Type: Reference Architecture Assessment
Status: VALID
Assessed: 1 October 2026
Valid Until: 30 December 2026
Assurance Cap Applied
  • PUBLIC_ASSESSMENT_CAP (Ceiling: 79): Reference architecture assessments are capped at 79 and ineligible for verified status or TR4/TR5.
Understanding Score vs Evidence Confidence:

TrustRank reflects the assessed control outcome. Evidence Confidence reflects the strength, independence and testability of the supporting evidence. They are separate metrics and are never combined or averaged.

Scope of Assessment:

TrustRank evaluates a specific Agent Assessment Object (AAO), including the agent version, model, deployment profile, tools, permissions, runtime and security controls. A TrustRank result should not be interpreted as a universal rating of the provider or every deployment of this agent.

Public Findings (1)

Audited security & control findings
CF3Prompt-Injected Destination Tampering in Invoice Notes Mitigated by Policy Gateway
Status: RESOLVED

Adversarial testing (FT09) demonstrated that free-form invoice notes containing prompt injection instructions can cause unconstrained language models to emit unauthorized recipient identifiers. In the reference architecture, this is deterministically mitigated at the Policy Gateway layer, which enforces cryptographic intent binding and rejects non-bound counterparties.

Finding ID: CF-FIN-001 · Control: TR05.11
Critical Control Coverage (30 Controls)
30Applicable
0E3 Tested
0Not Testable
Control Coverage (Legacy Record)75 controls
0E0
75E1
0E2
0E3

Note: In this legacy v0.2 record, the E0–E3 breakdown reflects 75 evaluated controls across 7 source documents.

Operational Profile & Autonomy Boundaries
Autonomy Level:A2
Financial Authority:F3
Guardrails:GD3
Composition Risk:CE0
Cryptographic Assessment Fingerprint:
8f6d8a1c085313f1467629f56d98c924de1a5f2c985c4dca3e5e8a8382afb05c
View Full Trust Passport

Sources & Provenance

(1)
Information observed: 1 October 2026

Registry Provenance Distinction: Registry Source Provenance is NOT TrustRank Assessment Evidence. Sources above document registry facts. TrustRank assessment evidence measures technical control test results.

AgentSearch Reference Architecture SpecificationREFERENCE ARCHITECTURE
Publisher: AgentSearch TrustRank Assessment Registry