Financial Action Agent — Stripe Reference Deployment
v1.0.0-refDeterministic reference architecture modeling an accounts-receivable AI agent capable of inspecting approved SME invoices and executing controlled invoice collections via an isolated Policy Gateway and Stripe payment platform.
Capabilities
(1)Standardised reference architecture for independent control testing.
Integrations
(1)Deployment & Execution Environment
Documented Models
Underlying foundation or reasoning models declared by provider documentation:
TrustRank Assurance
Strength, testability, and independence of submitted audit evidence.
Methodology v0.2- PUBLIC_ASSESSMENT_CAP (Ceiling: 79): Reference architecture assessments are capped at 79 and ineligible for verified status or TR4/TR5.
TrustRank reflects the assessed control outcome. Evidence Confidence reflects the strength, independence and testability of the supporting evidence. They are separate metrics and are never combined or averaged.
TrustRank evaluates a specific Agent Assessment Object (AAO), including the agent version, model, deployment profile, tools, permissions, runtime and security controls. A TrustRank result should not be interpreted as a universal rating of the provider or every deployment of this agent.
Public Findings (1)
Adversarial testing (FT09) demonstrated that free-form invoice notes containing prompt injection instructions can cause unconstrained language models to emit unauthorized recipient identifiers. In the reference architecture, this is deterministically mitigated at the Policy Gateway layer, which enforces cryptographic intent binding and rejects non-bound counterparties.
Note: In this legacy v0.2 record, the E0–E3 breakdown reflects 75 evaluated controls across 7 source documents.
Sources & Provenance
(1)Registry Provenance Distinction: Registry Source Provenance is NOT TrustRank Assessment Evidence. Sources above document registry facts. TrustRank assessment evidence measures technical control test results.