
NullRun
AI Agent Governance
Hey Indie Hackers
For the past 7 months I've been building NullRun - a runtime authorization layer that sits between your AI agents and the outside world.
The problem I'm solving:
Companies are shipping AI agents everywhere (LangChain, CrewAI, MCP-based), but most have zero control over what those agents actually do at runtime: an agent can blow through budget, trigger an unsafe tool call, or delete something in production - and nobody finds out until it's too late.
What NullRun does:
1 - statefull caps spend at the agent level
2 - blocks unsafe tool calls before they execute
3 - requires human approval for critical actions
4- logs and audits every decision the agent makes
It's a drop-in layer in front of any agent framework (LangGraph, CrewAI, OpenAI/Anthropic/Gemini agents) - no need to rewrite agent logic.
Status:
The product is production-ready, but revenue is still $0
I'm looking for my first pilot customers to validate whether teams already running agents in production are ready to pay for this kind of governance layer now, or if the market just isn't there yet.
Question for you:
If you're deploying AI agents to production right now - how are you handling budget control and unsafe actions? Duct-tape scripts, custom middleware, or nothing at all?
Would really appreciate any feedback, especially from anyone who's already gotten burned on agent spend or safety.
About
Build something the market genuinely needs, then earn from it. Not a side experiment. Not a passion project. A real B2B SaaS in a real category. Seven months of full-time work later, it's production-ready.

1 Comment
The $0 revenue is less interesting than the urgency question. Have you found teams already running agents that consider spend limits or unsafe tool calls painful enough to pay for now, or are most treating governance as a future problem?