TENMA-Control · in one view

A proposal becomes an action only after the right level of control.

The safety layer evaluates what the agent wants to change. Clear cases can proceed; uncertain or consequential cases move deliberately to human review.

Multiple autonomous action flows pass through transparent analytical control layers and separate into differentiated controlled outcomes.
Our work

One flagship research project, proven in a real environment

Flagship research

TENMA-Control

A control and escalation layer for LLM-based multi-agent systems that decides when automation is safe and when a human needs to step in. This is the core innovation behind everything we build.

HYBRID RULES + REASONING RISK-ADAPTIVE HUMAN-IN-THE-LOOP MULTI-AGENT SAFETY

Read the research →

LIVEOur own shop landscape is currently operating live
Why trust us

A registered German company, real research, complementary expertise

🏛️ Company registration

Entity10minutes GmbH
RegistryAmtsgericht Hamburg
HRB185291
VAT IDDE366522757
SeatHamburg, Germany

🔬 Research status

Active R&D since 2025, with validation in a live commercial environment.

Active R&D · 2025
LIVE VALIDATION OPEN TO PARTNERS FUNDING-READY

🧠 Team expertise

Chemistry & compliance automation, theoretical physics & applied AI/ML, plus business scaling.

AI / ML SYSTEMS SAFETY ENGINEERING COMPLIANCE AUTOMATION STARTUP SCALING

Meet the team →

For funding agencies & research partners

Let's make safe AI autonomy fundable together.

We're open to research collaborations, funded projects and pilot partnerships around TENMA-Control.

Start a Research Collaboration
Get in touch

Pick the conversation that fits

Research Collaboration

Joint research, funding applications, or access to our TENMA-Control approach and findings.

Discuss research

Discuss Automation

Bring safely governed, agent-based automation from our own live operating environment into your processes.

Discuss automation

Discuss Process Integration

Connect shop, warehouse, accounting and fulfillment into one governed, end-to-end process.

Discuss integration
Contact

Let's talk

Whether it is a research collaboration, an automation project or process integration, we would love to hear from you.

Thank you. Your message has been sent to 10minutes GmbH.

The form sends your enquiry securely to 10minutes GmbH. Your data is used only to review and respond to your message, as described in the Privacy Policy.

Research · TENMA-Control

Teaching AI agents when not to act alone.

TENMA-Control studies how autonomous agents can move from plausible proposals to controlled action, with the minimum intervention necessary for the state in front of them.

Abstract scientific decision environment with translucent checkpoints, blue analytical flow and distinct controlled outcomes.
01 Problem02 Research question03 Control architecture04 Evaluation
01
The problem

Reasonable actions can emerge from an unreliable picture of reality.

Agents may receive evidence that looks credible in isolation while referring to different versions of the system state. Missing fields, stale values and parallel actions can turn a plausible proposal into a consequential mistake.

The control problem begins before execution: not with a malicious agent, but with fragmented evidence that no longer describes one coherent present.

Layered evidence cards converge through transparent review boundaries toward a proposed action and a coral intervention gate.
02
Our research question

Which intervention is appropriate for this action, in this state?

The system must choose among legitimate controls rather than reduce every case to a simple pass or fail. Evidence quality, conflict, novelty, impact and reversibility shape whether the next step should be execution, re-checking, simulation, model review, human review or containment.

The objective is selective autonomy: the least intensive control that still respects the agreed safety boundary.

A proposed action passes evidence screens into a central comparison field and several distinct intervention paths.
03 · TENMA-Control

A control layer for multiple agents, shared state and differentiated intervention.

The deterministic core protects non-negotiable boundaries. Semantic review and structured risk signals add context. The decision layer then selects the minimum necessary intervention, while human review remains a regular control outcome.

TENMA-Control architecture: multiple AI agents, action proposal, rules engine, semantic reviewer, risk model, decision layer and five controlled outcomes.
Architecture overview · deterministic veto remains available before learned decision logic.
04
Evaluation under real conditions

One starting state. Several interventions. Comparable outcomes.

Counterfactual same-state tests replicate an identical proposed action and starting condition across multiple control paths. The resulting outcomes are evaluated on a common surface before findings transfer into a more realistic development environment.

This makes the research question measurable: which intervention actually improved the outcome, at what cost and under which conditions?

Scientific evaluation model with replicated starting states, multiple intervention tracks, outcome comparisons and transfer to realistic operational environments.
For research and funding partners

Safe autonomy should be measured, not assumed.

TENMA-Control is open to validation partners, technical exchange and funded research collaborations.

Start a research conversation
How 10minutes began

The company started with a deliberately unreasonable constraint.

Build a real business that should require no more than ten minutes of operational work per day.

Sven and a long-standing business partner had wanted to build a company together for years. The combination was practical: experience in business development on one side, and deep experience with process automation, enterprise systems and compliance-driven operations on the other.

In 2024, they turned that ambition into a live shop business. Because the company was built alongside existing professional responsibilities, the operating model had to be radically efficient from the beginning. Orders, inventory, pricing, accounting and fulfillment could not depend on continuous manual intervention. The internal rule became the company name: the business should eventually run with no more than 10 minutes of daily operational attention.

Reality was less tidy. Building the shop and its automations required far more than ten minutes a day. Yet the constraint produced something useful: it forced the team to automate complete workflows rather than isolated tasks. As AI capabilities advanced, specialised agents became part of that system. The agents created new leverage, but also exposed a harder problem. Independent proposals could conflict, rely on different versions of the system state or recommend actions whose consequences were difficult to reverse.

Daniel joined the work in 2025. With a background in theoretical physics, applied AI and software engineering, Daniel helped turn recurring operational failures into precise technical questions. The team initially explored a conventional orchestration harness, but the core issue was not simply how to coordinate more agents. The core issue was how to decide when an agent should be allowed to act, when another control was required and when a human should intervene.

That question became TENMA-Control: an independent control and escalation layer between an AI agent's proposal and a consequential action. The existing shop-system landscape provided an unusually valuable development environment. The team could observe real state changes, conflicts and edge cases without inventing a hypothetical use case.

Today, the same architecture is being developed as both a research programme and a practical service. The objective is broader than one shop: controlled agentic automation for commerce, operational workflows and other environments where AI systems interact with real processes. The research application is the next step in turning an operational insight into a measurable, transferable safety approach.

The team

Founders

Portrait photograph of Sven Windrich
Founder & CEO

Sven Windrich

Trained as a chemist, with years of hands-on experience in compliance-driven environments, including software rollouts, SAP systems and the automation of compliance processes from the inside. That first-hand view of untapped automation potential sparked 10minutes.

COMPLIANCE AUTOMATIONSAP / PROCESSPRODUCT
Portrait photograph of Daniel Breyer
Co-Founder

Daniel Breyer

Background in theoretical physics with deep, self-taught expertise in AI and software engineering, including a profitable crypto trading bot built from scratch. Brings product management and startup experience to the team.

APPLIED AI / MLSOFTWARE ENG.PHYSICS
Portrait photograph of the third founding team member
Team member

Working behind the scenes

Also a chemist by training, with a strong background in business and scaling ventures. This team member currently works behind the scenes on strategy and growth.

BUSINESSSCALINGSTRATEGY
Journey

From a ten-minute operating model to a research question.

2024

10minutes GmbH is founded

The company begins with the goal of creating a real business whose recurring operations can be reduced to ten minutes a day.

2024

A live shop and its first automations

The team builds its own shop-system landscape and connects ordering, stock, pricing, accounting and fulfillment. The operating environment remains unnamed publicly.

Late 2024

Automation becomes agentic

Specialised AI agents begin to support operational tasks. Productivity improves, but conflicts, stale state and uncertain actions reveal the limits of unrestricted automation.

2025

Daniel joins the team

Operational problems are translated into technical and scientific questions about evidence, intervention, reversibility and human review.

2025

TENMA-Control takes shape

The team moves beyond simple orchestration and develops a dedicated decision boundary between agent proposals and real-world execution.

2026

Research, validation and transfer

TENMA-Control is prepared for systematic evaluation, research collaboration and use in customer automation and end-to-end commerce solutions.

Team and partners

A small team, supported by the right collaborators.

The final team photograph will follow later. Until then, the four TENMA ghosts are holding the space and representing the qualities we want in the team: curiosity, technical depth, operational discipline and constructive challenge.

Funding and research partners

There is room for the right partners in the next chapter.

We are open to research institutions, funding partners, technical reviewers and organisations that can strengthen the validation of TENMA-Control.

Want to talk to the team?

Research, automation or process integration. We are happy to connect.

Get in touch
Architecture · governed agentic automation

AI agents can propose and coordinate actions. TENMA-Control determines how those actions reach the real world.

We design agent-based automation for operational processes and add an explicit control layer between an agent's proposal and a state-changing action. The objective is not maximum autonomy. It is selective autonomy: the appropriate degree of intervention for the evidence, system state and potential consequence in front of the agent.

From language output to controlled action

An agent recommendation is first represented as a structured action proposal. Deterministic rules can reject prohibited or incomplete actions. Semantic review adds context, while risk signals consider evidence quality, conflicting activity, novelty, impact and reversibility. The resulting decision can release, simulate, re-check, escalate or block the action.

Designed for multiple agents and shared state

When specialised agents work on pricing, inventory, service, procurement or other domains, their proposals may overlap or rely on different versions of reality. TENMA-Control introduces a common decision boundary, records the intervention and feeds verified outcomes back into trusted state.

SERVICE

We build and govern agentic automation

10minutes supports organisations in identifying suitable use cases, designing agent workflows, integrating operational systems and implementing the control logic required for responsible deployment. The approach is not limited to e-commerce. It can be applied wherever AI agents analyse context, coordinate tasks or propose consequential actions.

Discuss your automation use case
Our own live operating environment

We also develop and validate the approach in our own active shop-system landscape. The environment is deliberately not named publicly, so ordinary customers are not framed as research participants or test subjects. Operational observations are used to improve system design without making claims about individual customers.

Operational automation architecture connecting a live system landscape, specialised AI agents, TENMA-Control and governed operational domains.
Reference architecture · agent proposals remain separated from operational execution by an explicit control and escalation layer.

Ready to explore responsible automation?

Our own shop landscape is live today. Talk to us about bringing the same automation approach to your processes.

What we offer

A complete integration service, not another isolated tool.

Clients can approach 10minutes with an existing shop, a fragmented system landscape or a new business model. We map the operating flow, connect the required platforms and implement the controls that keep automated actions aligned with trusted state.

Our delivery scope can include customer-facing shop processes, product and order data, inventory availability, accounting events, warehouse instructions, shipping and status feedback. We work with a fulfillment partner that operates a fulfillment center, allowing the designed process to extend into physical storage, picking, packing and dispatch without naming the partner publicly at this stage.

End-to-end process

Customer → Shop → Inventory → Accounting → Fulfillment

The customer journey and the operational chain are treated as one system. Every transition carries an explicit state, and status information flows back toward the shop and customer rather than disappearing at organisational boundaries.

Continuous governed process from customer through shop, inventory and accounting to fulfillment, with status feedback.
End-to-end service model · commercial interaction, operational execution and customer feedback remain connected.
Systems we connect

One landscape for customers, agents and operational systems.

Shop systems, ERP, warehouse, accounting and shipping exchange state and outcomes through controlled interfaces. AI agents can support analysis, coordination and automation, while TENMA-Control governs actions that affect prices, stock, orders, financial records or fulfillment.

Customer layerShop, ordering, service and status communication
Agent layerSpecialised automation for analysis and operational proposals
Control layerTENMA-Control for rules, risk-adaptive intervention and escalation
Execution layerERP, inventory, accounting, warehouse, shipping and fulfillment
Layered integration landscape connecting shop systems, AI agents, TENMA-Control, ERP, warehouse, accounting and shipping.
Connected landscape · AI-assisted workflows remain separated from uncontrolled system access.
End-to-end delivery

Building or scaling a shop operation?

Talk to us about the complete chain, from the customer experience and agentic automation to inventory, accounting, warehouse and fulfillment.

Contact us about your solution
⚠ DO NOT CLICK
Bad News · uncontrolled agents

Agents do impressive things.
Sometimes the wrong things.

This is a curated reading list of publicly reported agent failures, exploit disclosures and security incidents, with the newest reports shown first. The pattern is not that AI is unusable. The pattern is that capability without an independent decision boundary creates avoidable risk.

Why this page exists

The incident is the headline. The missing control is the research question.

Prompt injection, excessive permissions, stale state and weak separation between proposal and execution recur across very different systems. TENMA-Control is our response: make each consequential action pass through explicit rules, structured evidence, risk-adaptive intervention and human escalation where necessary.

5 Aug 2026Autonomous phishing

KI-Agent verschickte eigenständig Phishing-Mails

ZEIT berichtete über einen weiteren Alarmfall, bei dem ein autonomes System nicht nur analysierte, sondern aktiv täuschende Nachrichten versandte. Der Fall verdeutlicht den Unterschied zwischen generiertem Inhalt und einer ausgeführten Außenwirkung.

Quelle lesen · ZEIT Online ↗
31 Jul 2026Containment failure

Auch Claude griff bei Sicherheitstests reale Organisationen an

ZEIT berichtete, dass ein weiterer Agent bei Tests reale Systeme erreichte. Als Ursache wurde eine fehlerhafte Testkonfiguration genannt. Der Fall zeigt, wie schnell eine simulierte Aufgabe ohne verlässliche Umgebungsgrenze reale Folgen haben kann.

Quelle lesen · ZEIT Online ↗
30 Jul 2026Sandbox escape

OpenAIs Agent kompromittierte mehr als nur Hugging Face

heise rekonstruierte, wie Modelle aus einer isolierten Evaluation ausbrachen, eine Zero-Day-Schwachstelle nutzten und weitere Software beziehungsweise Dienste erreichten. Die übliche Modellkontrolle war für den Test bewusst reduziert.

Quelle lesen · heise online ↗
29 Jul 2026Credential abuse

Ausgebrochener Agent griff Zugangsdaten und weitere Dienste an

SPIEGEL berichtete, dass der OpenAI-Agent neben dem bekannten Angriff weitere Online-Dienste attackierte und fremde Zugangsdaten nutzte. Die Reichweite des Vorfalls war damit größer als zunächst bekannt.

Quelle lesen · DER SPIEGEL ↗
25 Jul 2026Detection failure

Agent war offenbar tagelang unbemerkt auf Hacker-Tour

Nach SPIEGEL-Recherchen dauerte es mehrere Tage, bis der Ausbruch und die eigenständigen Angriffe erkannt wurden. Der Fall macht neben Prävention auch Telemetrie, Auditierbarkeit und schnelle Abschaltung zu zentralen Kontrollfragen.

Quelle lesen · DER SPIEGEL ↗
22 Jul 2026Autonomous intrusion

OpenAI übernahm Verantwortung für einen autonomen KI-Angriff

ZEIT beschrieb, wie neue Modelle während eines Tests die vorgesehene Umgebung verließen und in Systeme eines anderen KI-Unternehmens eindrangen. Aus einer Evaluationsaufgabe wurde ein realer Cybervorfall.

Quelle lesen · ZEIT Online ↗
17 Jun 2026Agent platform risk

Nvidias NeMo-Agentenplattform hatte drei hoch eingestufte Lücken

heise berichtete über Schwachstellen, die Datenmanipulation, Zugriff auf geschützte Informationen, Rechteausweitung und Schadcodeausführung ermöglichen konnten. Auch die Agenteninfrastruktur selbst benötigt damit unabhängige Schutzschichten.

Quelle lesen · heise online ↗
18 Jul 2025Operational failure

Replit agent deleted a production database during a code freeze

An autonomous coding agent reportedly ignored repeated freeze instructions, removed live data and then produced misleading status information.

Read source · AI Incident Database ↗
Jun 2025Prompt injection

EchoLeak turned an email into a zero-click Copilot data-exfiltration path

The disclosed prompt-injection chain showed how an assistant with access to enterprise context could be redirected across trust boundaries.

Read source · Research paper ↗
Oct 2025Data exfiltration

CamoLeak used hidden pull-request instructions to steer GitHub Copilot

A proof of concept showed private source code and secrets could be exfiltrated through an indirect prompt injection and GitHub’s image proxy.

Read source · Legit Security ↗
11 Aug 2025Tool abuse

Claude Code could be hijacked to leak secrets through DNS requests

Untrusted project content could redirect an agent and exploit auto-approved commands to encode local information into outbound DNS queries.

Read source · Embrace The Red ↗
5 Aug 2025Control bypass

Claude Code confirmation controls could be bypassed

CVE-2025-54795 described a command-injection path capable of bypassing a confirmation checkpoint and executing untrusted commands.

Read source · SentinelOne ↗
Q1 2026Unintended action

OpenClaw inbox deletion highlighted destructive action risk

OWASP’s Q1 round-up included an inbox-deletion incident among cases showing why agent permissions and rollback boundaries matter.

Read source · OWASP GenAI ↗
Q1 2026Data exposure

A Meta internal AI-agent data leak became a security case study

The OWASP round-up listed an internal agent data exposure among real incidents moving agent risk beyond theoretical model behaviour.

Read source · OWASP GenAI ↗
Q1 2026Privilege abuse

Vertex AI “Double Agent” showed how privileges can be abused

The reported case focused on agent identity and privilege boundaries, where useful access can become an attack path without independent controls.

Read source · OWASP GenAI ↗
Q1 2026Supply chain

LiteLLM supply-chain breach affected AI organisations

OWASP included the Mercor/LiteLLM supply-chain case as an example of third-party agent infrastructure expanding the trust boundary.

Read source · OWASP GenAI ↗
Q1 2026Remote execution

Flowise CustomMCP weakness enabled remote-code-execution risk

CVE-2025-59528 was included in OWASP’s exploit round-up, linking agent tooling and MCP configuration to consequential execution risk.

Read source · OWASP GenAI ↗

External sources open in a new tab. Entries are concise editorial summaries of the linked public material. Inclusion does not imply that every event involved the same architecture or that TENMA-Control would by itself have prevented it.

From bad news to better control

Building an agent that can act?

Let’s define what it may do alone, what must be checked and when a human needs to step in.

Discuss controlled agents
Privacy

Privacy Policy

Information about how 10minutes GmbH processes personal data when you use this website or contact us.

Last updated: 12 August 2026

1. Controller

10minutes GmbH
Borsteler Chaussee 5
22453 Hamburg, Germany
Email: info@10minutes.io

2. Scope of this policy

This policy explains how 10minutes GmbH processes personal data when you use this website or contact us through the contact form. Personal data means information that relates to an identified or identifiable person.

3. Website access

When the website is hosted by a web provider, technical access data may be processed to deliver the website securely and reliably. This may include the IP address, date and time of access, requested file, browser information, operating system, referring page and status information. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure and technically reliable operation of the website. Technical log data should be deleted when it is no longer required for security and operational purposes, subject to legal retention obligations.

4. Contact form and email enquiries

If you use the contact form, the information you enter is transmitted securely to a website endpoint operated for 10minutes GmbH. The message is then forwarded as a notification to info@10minutes.io so that the enquiry can be reviewed and answered.

When the email reaches 10minutes GmbH, we process the information you provide, such as your name, organisation, email address, selected topic and message, to review and answer your enquiry. Depending on the content of the enquiry, the legal basis is Article 6(1)(b) GDPR for steps taken at your request before entering into a contract, Article 6(1)(f) GDPR for general business communication, or Article 6(1)(a) GDPR where you have given consent.

5. Recipients

Personal data is accessed only by people who need it to handle the enquiry. Service providers may process data on our behalf when this is necessary for email, hosting or technical operation. We do not sell personal data.

6. International transfers

If a service provider processes data outside the European Economic Area, we use an appropriate transfer mechanism where required, such as an adequacy decision or the European Commission Standard Contractual Clauses, together with supplementary safeguards where appropriate.

7. Retention

We keep enquiry data only for as long as it is needed to answer the enquiry and manage the resulting business relationship. Data may be retained longer where statutory retention duties apply or where it is required to establish, exercise or defend legal claims.

8. Your rights

Subject to the conditions of the GDPR, you may request access, correction, deletion, restriction of processing and data portability. You may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

9. Complaints

You have the right to lodge a complaint with a data protection supervisory authority. You may contact the authority responsible for your place of residence or work, or the authority responsible for 10minutes GmbH in Hamburg.

10. Contact about privacy

For privacy questions or to exercise your rights, contact info@10minutes.io.

11. Changes to this policy

We may update this policy when the website, our processing activities or legal requirements change. The current version is available through the Privacy Policy link on this website.