Verifiable identity, guarded access, and proof of every action — for the agents doing real work in your company. Built on open standards. No blockchain.
Agents borrow human passwords and share API keys. Impersonating one is trivial — and nobody can prove which agent did what.
Access is all-or-nothing. An agent allowed to read can often also write, delete, and spend. Delegation hands over far too much.
No tamper-evident record exists — nothing that would satisfy your security team, let alone a regulator asking questions.
An autonomous agent ran an end-to-end intrusion of Hugging Face's production infrastructure — 17,000+ recorded actions. It defeated no identity architecture; it found static secrets and a network to cross.
Hugging Face disclosure, Jul 2026 ↗An AI coding tool with operator-level permissions reportedly deleted and recreated part of a production environment at Amazon — a thirteen-hour outage, and no approval workflow in its way.
AI Incident Database #1442 ↗Attackers stole the OAuth tokens of one AI chat integration and reached 700+ corporate Salesforce tenants. No password cracked, no MFA bypassed: the trusted integration itself was the credential.
Mandiant · UNC6395 ↗// none of these was a model failure — each one is an identity and authorisation failure
Every agent gets a verifiable, forgery-proof identity anchored in your own domain — who built it, who runs it, what it's trusted to do. Think KYC, for agents.
A doorman in front of the systems you already run. Your rules, enforced on every call: least privilege, spending limits, human sign-off where it matters. And delegation only narrows — helpers an agent sponsors get a smaller slice of its authority, and suspending the parent cuts off every child in minutes.
A tamper-evident record of every action — who, on whose authority, under which rule. Each entry fingerprints the one before it, so the past can't be rewritten quietly. One click turns it into an evidence pack for an auditor.
Want the whole argument? ▶ Watch the full concept film · 6:17
Three questions every company fails today. Meet Aria, an AI agent that buys parts for Acme. Today she has no ID — like every agent, she borrows keys and passwords. Nobody can prove who she is.
Identity → Enforcement → Proof. A doorman in front of what you already have — installed in 15 minutes.
Pick an agent and send its request through the gateway. Watch the doorman work.
One container, in front of the systems your agents already use.
One command per agent, anchored in your own domain.
Observe mode: nothing blocked, everything visible. Zero risk.
Flip the rules live when you're ready. Your CTO can finally say yes.
Enter through the open-source gateway and govern your own agents first. The verdict stream — every admission and refusal, attributed — is yours from day one.
Pilot observe-only on a single rail: nothing blocked, everything visible. The same verdict stream those gateways already produce is the supervisory signal.
// setup is a container and one command per agent — no SDK, no code changes on your side
The same identity rails the EU digital wallet runs on — applied to agents. Anchored in DNS and cryptography, the trust roots the internet already accepts. EU data residency from day one.
Two obligations in the EU AI Act name what this layer produces. Article 12 requires systems to technically allow the automatic recording of events over their lifetime. Article 14(4)(e) requires human oversight that can interrupt a system through a stop button or equivalent — which is what revoking a passport does. Under the 2026 amendments, Article 50 transparency obligations apply from 2 December 2026, and the high-risk logging and oversight obligations from 2 December 2027 — the window to get evidence-ready.
We're onboarding a small group of design partners — agent platforms and EU enterprises piloting agents.