Your AI agents,
under control.
You build AI agents in Zapier, n8n, Make or your own code. VINCHY - MAAM manages all of them from one place — whatever tool each one runs in: it sees every action, holds risky ones for your approval, and records all of it on a tamper-evident audit trail you can show a regulator.
Everyone helps you build agents. Far fewer help you control them after deploy.
An AI agent can send an email, move money, export customer data, or delete records — on its own, in seconds. Most teams have no gate in front of those actions and no provable record after them.
Under the EU AI Act, the deployer — whoever runs the agent — is accountable for what it does. One wrong action without oversight or records is a real legal and financial risk. That gap is exactly what VINCHY closes.
The same gap has a commercial side. Teams tend to hold agents back from the work that would actually pay off, simply because nobody can see what the agent did. In our experience visibility usually comes before trust — and how much you trust an agent decides how much you let it do. In August, the UK's AI Security Institute published what happened when it ran agents with the models' built-in safety filters deliberately switched off: the agent invented identities, talked a real project maintainer into accepting its code — and then edited its own earlier activity to look harmless. A record the agent can rewrite is not evidence.
One manager for all your agents — whatever tool they run in
VINCHY is a registry of every agent you run, an approval checkpoint in front of their risky actions, and a tamper-evident audit trail behind them. Each agent gets a named owner and a trust level you set; risky actions check in before they run; every action — approved, blocked, or executed — is signed and chained so it can be proven later. It is not another agent builder. It is the one place from which the agents you already have are governed.
No black box. No silent actions.
No black box. Every agent action is recorded, signed and explainable — to you, your team, or a regulator.
No silent actions. Anything risky waits for a human. Always. Trust can tighten the gate — never loosen it.
No blind trust. Verify the audit chain yourself, against a public copy we cannot rewrite. Trust the math, not us.
No lock-in. Your agents stay in your tools. VINCHY - MAAM is the layer above them, not another builder.
Control is not a feature we added. It's the reason VINCHY exists.
Three steps to control
Connect
Point your agents — Zapier, n8n, Make or custom code — at VINCHY with one API key. However many, in however many tools: they all land in one registry. Each agent gets a named, accountable human owner. An agent with no owner can't act.
Govern
Click-to-enable policy templates and your own IF→THEN rules hold risky actions — payments, bulk email, deletes, data exports — for explicit human approval before they run. You decide where the line sits, so routine work keeps moving and only what you marked as risky stops: a purchasing agent can run on its own below your limit and escalate above it.
Prove
You get a full chain of custody — which agent, which action, which human approved it, when. Every action is written to an append-only, hash-chained, Ed25519-signed audit trail. Any later edit is mathematically detectable by anyone with the public key — including a regulator.
Tamper-evidence, demonstrated
Verify the audit chain in your own account, then simulate an edit and watch verification fail from that record onward — proof you can't fake the trail.
Manage a fleet, not just one agent
Fleet overview
One coordinator view of every agent — status, pending approvals, trust level and last action — so oversight scales across your whole fleet.
Registry & anomaly alerts
A searchable agent registry with risk filtering and anomaly detection — the car-alarm principle: it flags unusual behaviour, it doesn't silently stop it.
Live map
A live picture of your fleet — agents → your approval gate → tamper-evident log — so you see what's flowing and what's waiting, at a glance.
Trust levels per agent
Decide how much each agent does on its own — Watch, Approve-critical, or Full trust. Trust only tightens the gate, never loosens it; irreversible actions always need a human (Art. 14).
Governance metrics
Live dashboard KPIs — including your overturn rate (how often you reject what agents propose) — so you can see oversight actually happening, not just claimed.
Named Owner rule
Every agent maps to an accountable human. No owner — no action. The first governance question is always: who is responsible if this goes wrong?
Human-in-the-loop approvals
High-risk actions wait in your inbox with the full picture — what, justification, blast radius and the agent's confidence — before they execute.
Tamper-evident audit
Append-only, hash-chained, Ed25519-signed. One click re-verifies the whole chain; a safe simulation shows how a single edit breaks it.
Policy engine
Approved systems per agent, five built-in templates (financial authority, external comms, data export, off-hours, named owner) and your own custom rules.
Reversibility tags
Every action is classed Reversible, Conditional or Irreversible. The irreversible ones — send, pay, delete — always wait for a person. Risk management by design (Art. 9).
Guardrail layers
Four defence layers — input, context, tool and output — screen every agent action, with prompt-injection detection that flags manipulation attempts in the audit trail. Guardrails only tighten the gate, never loosen it.
Ask VINCHY
A built-in assistant plus team chat (@VINCHY) that explains your governance posture in plain language and answers questions about your agents and audit.
Compliance reports
One-click EU AI Act gap report, an auditor-grade Trust Report, and a human-readable audit timeline — all exportable as PDF, ready to hand over.
ISO 42001 readiness
A readiness panel mapping your setup to AI-management-system clauses — preparation for an audit, not a certification.
Model transparency
The model each agent runs on (Mistral, Claude, GPT-4o, Gemini, Llama, GLM…) is recorded per action — EU AI Act Art. 13 — so you can prove which model, and where it runs.
One-click tool actions
Connect a tool like GitHub with a token VINCHY encrypts. The agent's writes — open an issue, comment — wait for your approval; then VINCHY performs the action and records the result in the audit chain.
Public audit anchoring
The audit chain is periodically anchored to a public GitHub repository — so records can be verified against a copy VINCHY itself cannot rewrite. Trust the math, not us.
Running agents with VINCHY - MAAM — and without
Same agents, same tools. The difference is what you can see, stop and prove when it matters.
Without VINCHY
- Agents act on their own; you find out afterwards — if at all.
- Logs are scattered across tools, editable and easy to lose.
- "Who approved this?" has no provable answer.
- An audit or customer question means manual reconstruction across systems.
- API keys with broad access and no per-agent limits.
With VINCHY
- Risky actions wait at your approval gate before they run.
- One append-only, Ed25519-signed audit trail — any edit is detectable.
- Every agent has a named owner; every approval records who and when.
- Gap report, Trust report and audit timeline — exported in one click.
- Scoped keys and rate limits per agent — plus guardrails on every action.
Home or Business
Home
- Control and audit your own agents — your household, your rules.
- Exempt from EU AI Act deployer obligations (Art. 2(10)) — voluntary control posture.
- Free to start. Connect an agent and see the audit trail today.
Business
- Team accounts with owner / admin / member roles and per-agent accountability.
- EU AI Act Art. 26 framing, content moderation pre-screen, gap + Trust reports.
- Documentation and records designed to support an audit or enterprise review.
Agents you can put under control
Don't know where to start? Pick a ready-made agent for Home or Business — or describe your own. VINCHY - MAAM gates the risky actions either way.
Bill & Subscription Monitor Home
Watches bills and subscriptions, flags new or rising charges. Every payment or cancellation waits for your OK.
Invoice Approver Business
Matches purchase orders to invoices and proposes payment. Releasing a payment waits for an approver.
Grocery & Meal Planner Home
Plans meals and builds your shopping list. Checkout waits for your approval.
Lead Qualifier Business
Scores and routes inbound leads. Messaging a new prospect waits for you.
Travel Booker Home
Finds flights and hotels to your taste. Booking with payment waits for you.
Support Resolver Business
Drafts answers and resolves tickets. A refund or policy exception is held for review.
Health Scheduler Home
Manages appointments and reminders. Confirming a booking waits for your OK.
Contract Reviewer Business
Reviews and redlines agreements. Sending a document to an outside party waits for approval.
Home Maintenance Tracker Home
Tracks repairs and upkeep. Hiring a handyman waits for your approval.
Onboarding Agent Business
Runs new-hire setup tasks. Granting system access waits for a human.
Deal & Price Hunter Home
Tracks prices and hunts deals. Ordering in your name waits for you.
Social Publisher Business
Drafts and schedules content. Publishing to your company channels waits for approval.
Every template ships with a safe default trust level and the right gates — you tune it, then it runs.
Five working agents. One click. Every action gated.
"Install the team" sets up five ready-made business agents in your workspace. They draft — you approve. Try them on demo data first, then connect your real leads via CSV import or the included n8n recipes.
Lead Reactivation Business
Drafts SMS to leads that went quiet — with built-in triage that skips opted-out contacts. Nothing sends without your approval.
Review & Referral Business
Asks happy customers for reviews and referrals. Every message waits for your OK before it goes out.
Lead Nurture Business
Keeps new prospects warm with relevant follow-ups. Sending always waits for you.
Receptionist Business
Proposes appointment slots and prepares bookings (e.g. Google Calendar). Nothing is confirmed until you approve.
Sales Trainer Business
Read-only agent: analyses your lead and response data and surfaces coaching insights. It never sends anything.
Each agent ships with eval-tested triage, guardrail layers and an n8n recipe to connect your own tools (e.g. Twilio, Google Calendar, Slack).
Where VINCHY - MAAM is today — and what's next
- Named-owner rule + policy engine
- Human-in-the-loop approvals
- Tamper-evident audit (Ed25519)
- EU AI Act gap, Trust + audit-timeline reports (PDF)
- ISO 42001 readiness + model transparency
- Agent registry + Ask VINCHY + team chat
- Connect Zapier / n8n / Make / custom
- German & English — auto-selected by region
- Trust levels + reversibility tags (Art. 9 & 14)
- Fleet overview + governance KPIs (overturn rate)
- Connect GitHub — agents act on your repo, gated by your approval
- Live map of your agents (visualisation)
- Install as an app (PWA) + in-app updates
- Starter Pack — five ready-made business agents, installed in one click
- Guardrail layers + prompt-injection detection
- Public audit anchoring (GitHub) — verify against a copy we can't rewrite
- Scoped API keys + rate limiting
- Help Center + in-app support
- Voice — talk to VINCHY in chat
- Developer SDK & MCP firewall — docs & downloads →
- TÜV & ISO/IEC 42001 certification — in preparation
- SDK on PyPI / npm + framework adapters (LangChain, CrewAI)
- Desktop app (Windows & macOS)
- Mobile push notifications — approvals on the go
- More one-click integrations (Google, Microsoft 365, Granola)
- IAM / Zero-Trust — who acts on whose behalf
- More EU languages
Designed around deployer duties
VINCHY - MAAM maps directly to the obligations that fall on whoever runs an AI agent — helping you meet them, not certifying that you have:
Questions
Do I need to rebuild my agents?
No. Keep building in Zapier, n8n, Make or your own code. You just point their risky actions at VINCHY - MAAM's endpoint with one API key — VINCHY sits in front, it doesn't replace your tools.
Is this EU AI Act compliance?
VINCHY gives you the oversight and tamper-evident records that the deployer duties call for, plus gap and Trust reports. It supports your documentation — it is not a certification, and it is not legal advice.
Where is my data?
Hosted in the EU. The audit trail stores action metadata and cryptographic hashes — not raw payloads where avoidable. You can export a signed CSV/JSON envelope and verify it offline.
What's the difference between Home and Business?
Home is for personal agents (Art. 2(10) exempt) and is free to start. Business is for companies acting as a deployer — team roles, Art. 26 framing, moderation, and compliance reports.
How is VINCHY different from orchestration tools like Trigger.dev or Temporal?
Orchestration tools like Trigger.dev or Temporal help engineers build and run agents in code. VINCHY sits one layer up: it governs the agents you've already deployed — human approval gates, a tamper-evident audit trail, and EU AI Act Art. 26 oversight — no code required, built for the people accountable for the agents, not the ones writing them.
Isn't this just another dashboard?
A dashboard tells you what already happened. VINCHY sits in the path of the action instead: risky steps stop and wait for a decision, and the decision you make is written into a record you can hand over later. The numbers on screen are a by-product — the point is being able to step in before an action runs, not read about it afterwards.
See, approve, and prove every agent action
Start free with a Home account, or request a Business pilot for your team.