Cryptographic identity for AI agents

Your agent has production access. Prove it deserves it.

Agentic Trust & Protection Platform issues every AI agent a signed, SPIFFE-based identity, then broadcasts a signed trust-state event for every action it takes. The badge on your status page isn't a claim about what your agent is allowed to do. It's a cryptographic record of what it just did.

NO CARD · NO SALES CALL · 10 AGENTS FREE FOREVER
Trust manifestLive
agentbilling-reconciler-03
identityspiffe://acme.dev/ops/billing
scoperead:ledger · write:draft
last actionreconciled 214 invoices
signature7f3a…e01c
stateverified

agentsupport-copilot-11
last actionrequested crm:export:all
staterevoked
What breaks without it

Four questions you can't answer about your agents right now

None of these are hypothetical. They're the questions that arrive in an incident channel at 11pm, or in an enterprise security questionnaire on a Tuesday — and today the honest answer to all four is a shrug.

No record
"What did it actually do?"
Your agent made forty thousand tool calls last month. The only record is whatever application logging the engineer who built it happened to write — unsigned, editable, and scattered across three services. There is no ledger of agent actions because nobody built one.
No enforcement
"What is it still allowed to do?"
The credential you issued in March is the credential it holds today. Scope was a decision made once, in a config file, and never checked again at runtime. An agent scoped to read invoices can attempt anything that credential permits — and nothing stops it or even notices.
No artifact
"How do you control your AI's access to our data?"
This is question 14 on every enterprise security review now. Today you answer it with a paragraph of prose in a document. Your buyer's security team has no way to verify a word of it, so they discount all of it — and the deal slows down.
No kill switch
"How fast can you stop it?"
Revoking a misbehaving agent means finding which credential it uses, rotating it, and hoping nothing else in production depended on that same key. Minutes at best. In the window between "something's wrong" and "it's stopped," the agent keeps working.
65%
of organizations had at least one AI-agent-caused security incident in the past year
97%
of orgs reporting an AI breach had no proper access controls on the agent involved
10–50×
how far machine and agent identities now outnumber human ones inside a typical company
$47B
Gartner's 2026 estimate for enterprise AI-agent spend, up from under $5B in 2023
Step Finance — DeFi trading platform $27–30M lost
"The agent did exactly what it was designed to do."

Attackers compromised executive devices, then didn't need to breach anything else. The platform's own trading agent already held unbounded permissions, and moved 261,000+ SOL tokens on command. The model didn't fail. The prompt didn't fail. There was simply no enforceable, verifiable limit on what that agent was permitted to do — and no signed record of it doing it.

The difference

Same agent. Same permissions. One of them can prove itself.

Agentic Trust & Protection Platform doesn't slow your agents down or route their traffic through us. It changes what exists after they act — and for teams who want more than a record, ATPP Enforce adds an inline checkpoint, opt-in and gated (see below).

today Unverified agent
  • Identity is a long-lived API keyStored in an environment variable, shared between services, rotated when someone remembers.
  • Scope is a hopeWritten into a config once. Never enforced at the moment of action.
  • Actions are unlogged or self-loggedWhatever the agent's author chose to write down, in a format nobody agreed on.
  • Trust is a sentence in a PDF"We limit our AI agent's permissions." Unverifiable, so discounted.
  • Revocation takes minutes to hoursFind the key, rotate it, redeploy, hope.
with atf Verified agent
  • Identity is a short-lived signed certificateA unique spiffe:// identity per agent that rotates automatically and can't be replayed.
  • Scope is checked at every actionGranted scope is evaluated when the agent reaches for a tool, not when it was deployed.
  • Every action is signed and streamedA tamper-evident event log you didn't have to ask an engineer to build.
  • Trust is a signed record anyone can checkGreen while it stays in scope, red when it doesn't. The badge is only a pointer; the signed document behind it verifies offline against your public key.
  • Revocation is immediate and automaticAn out-of-scope action suspends the identity itself — the next call fails.
How it works

Four steps from "we think it's fine" to "here's the proof"

No framework rewrite, no gateway to route traffic through. Agentic Trust & Protection Platform sits beside the agents you already run.

  1. Register the agent
    Point Agentic Trust & Protection Platform at a LangGraph, CrewAI, AutoGen, or custom agent process. Container, Lambda, or laptop — it doesn't matter where it runs.
  2. Issue an identity
    Each agent gets a unique spiffe:// identity and a short-lived signed certificate. Not a key in an env var — an identity that rotates and can't be replayed.
  3. Broadcast signed state
    Every tool call, scope request, and data access is signed and streamed as a trust-state event. This is the audit trail nobody had time to build.
  4. The badge goes live
    green while the agent operates inside its granted scope. red the moment it doesn't — an escalation attempt, an out-of-scope read, or a tool it was never issued.
The badge

One mark. Binary meaning. Anyone can check it.

Every other product in this category gives you a console your security team logs into. This gives you something you can hand to a customer.

Agentic Trust & Protection Platform — verified

Every action this agent has taken since its last identity rotation stayed inside its granted scope. Verified against the signed event log, not asserted by its owner.

Agentic Trust & Protection Platform — revoked

This agent attempted an action outside its granted scope. Its identity was suspended automatically, the call failed, and the attempt is in the log with a timestamp.

<img src="https://trust.redthreadsec.com/badge/acme/billing-reconciler.svg" alt="Agentic Trust & Protection Platform">
[![Agentic Trust & Protection Platform](https://trust.redthreadsec.com/badge/acme/billing-reconciler.svg)](https://trust.redthreadsec.com/v/acme/billing-reconciler)

Every badge links to a verify page. The document behind it is Ed25519-signed with the workspace key, published at a stable URL — anyone can check the signature offline without calling us. Unknown or expired renders grey. Red only on a proven exploit or a signed out-of-scope action.

The charter

Seven rules that make the badge worth checking

Badges are easy to launch and hard to make anyone check. These are the rules the product enforces — each one is verifiable by a skeptical engineer, and none of them can be bought.

1 · One claim per mark
The badge names the level and the date.
The verify page names the exact checks, the version hash or identity, and the raw result. “Verified” never means “safe.”
2 · Offline-verifiable
Every result is Ed25519-signed.
The public key is at a stable URL. A one-line script proves the document without calling us.
3 · Unasked and unbuyable
Scores are computed whether or not you want them.
No plan changes a score or a colour. Paying changes retention, limits and alerts — never the mark.
4 · Time-bounded
Every level carries an expiry.
Scans expire in 7 days; runtime states with their event TTL. Expired renders grey, never a stale green.
5 · Red only on proof
Revoked means a proven exploit or a signed out-of-scope action.
Inferred or potential findings render “degraded”, never red.
6 · Method published, versioned
The check list and thresholds are public.
A score always names the rules version it was computed with.
7 · Disputes are public and logged
A publisher can contest a finding.
The outcome and the correction are appended to the ledger with a timestamp — corrections are as visible as the original score.
New · Preview

The badge went from a record to a checkpoint.

Everything above happens after an agent acts. ATPP Enforce puts a decision point in front of the request — a gateway your agent's traffic runs through, checked against a grant you write, before anything reaches its destination.

recording What you have today
  • The request already leftBy the time an action is logged as out of scope, it already happened.
  • Scope is a tool nameAn allowed tool can still carry a malicious argument.
  • The agent reports on itselfNothing stops it from simply not reporting the one call that matters.
enforce With the gateway in the path
  • Checked before it leavesHost, method, path and body size against a grant — a denied request never reaches its destination.
  • Catches the workaround, not just the askRefused, then reached through a different route — the same signal, whatever the mechanism.
  • A stranger can verify itEvery forwarded request carries a signed receipt. The site on the other end can check it with no account and no relationship to you.
The safety rail

You cannot switch on blocking by accident.

Every new grant starts in shadow — it decides and records, and forwards everything, exactly like the recording layer above. There is no setting that puts a fresh identity straight into blocking traffic.

1 · Watch first
The gateway has to see real work.
At least 100 real decisions over at least an hour, under the exact grant you wrote — never a synthetic test.
2 · Review every block
Nothing enforces on your say-so alone.
Every request the gateway would have refused sits in a queue. You mark each one agree or disagree.
3 · One disagreement holds it
You get to be wrong about the grant.
Disagree once, and enforce stays refused until you fix the grant — which restarts the review, on purpose.
4 · No override
Not even the workspace owner can skip it.
The switch to enforce is refused by the API itself until the review is clean. Not a checkbox — a gate.

This is a preview: the whole point of a checkpoint is that it has to earn the traffic it blocks, so we are not shipping one that hasn't. Ask about early access →

Pricing

Land it in an afternoon, not a procurement cycle

You shouldn't need a signed MSA to find out whether your agent is behaving. Talk to us when you need SSO, long retention, or a few hundred agents — not before.

Free
$0
  • Up to 10 agent identities
  • Live green/red badge, embeddable anywhere
  • Signed trust-state event log, 30-day retention
  • Automatic revocation on out-of-scope action
  • Community support
Team
$149 /mo
  • Up to 50 agent identities
  • 1-year retention, exportable log
  • Slack & PagerDuty alerts on revocation
  • Webhook stream for your own SIEM
  • Email support, next business day
Business
$499 /mo
  • Up to 250 agent identities
  • Unlimited retention, audit-ready export
  • SSO/SCIM and role-based access
  • Custom trust-page domain for your badges
  • Priority support
Running more than a few hundred agents, or want the identities you register here mapped onto a full inventory of your cloud accounts, shadow-AI usage, and pentested applications? Agentic Trust & Protection Platform is one of seven capabilities inside Redthread — every agent you verify here is already a node in that graph, visible the moment you want to see it. Nothing to migrate.
The category

Everyone sells control. Nobody sells proof.

Agent and non-human identity is a real, funded category — three of its fastest-growing names were acquired into larger platforms during 2026. Here's how the independents present themselves, and where we think the gap is.

VendorHow they leadCategory wordStart without sales?
Agentic Trust & Protection Platform "Your agent has production access. Prove it deserves it." Agent trust & proof Free forever, self-serve
Aembit"IAM for Agentic AI" — secretless workload accessSecretless accessFree tier, published pricing
Natoma"Let your AI know everything your company knows."Managed MCPFree tier, published pricing
P0 Security"Authentication gets agents in. Authorization controls what happens next."AuthZ control planePricing page, no figures
Token Security"Identity-First AI Agent Security"Identity-firstDemo required
Clutch Security"Every Identity. Every Agent. Every Secret."Non-human identityDemo required
Britive"Zero standing privileges by design"PAM transformationQualification form
Andromeda"Identity Security for the Agentic Era"Identity posture (ISPM)Demo required

Public marketing copy as published September 2026. Vendors iterate quickly and several of these are excellent products — if you're running a large enterprise identity program, some of them are a better fit than we are. Verify current details directly before you decide.

What's crowded

Most of the category leads with some arrangement of discover, secure, govern. "Non-human identity," "runtime authorization," and "zero standing privilege" are all spoken for. We don't compete on those words.

What's missing

Every product in this category produces control, and control lives inside a console your security team logs into. None of them produce an artifact you can show someone else. That's the whole gap.

Who we're for

Not the identity program. The platform engineer who granted an agent production access this week and wants proof before anyone asks. That person can't get past a qualification form at 11pm.

Start free

Know what your agents can do. Prove it to everyone else.

Register your first agent, get its identity issued, and put a live badge somewhere in about five minutes.