Cryptographic identity for AI agents

Your agent has production access. Prove it deserves it.

Agent Trust Fabric issues every AI agent a signed, SPIFFE-based identity, then broadcasts a signed trust-state event for every action it takes. The badge on your status page isn't a claim about what your agent is allowed to do. It's a cryptographic record of what it just did.

NO CARD · NO SALES CALL · 10 AGENTS FREE FOREVER
Trust manifestLive
agentbilling-reconciler-03
identityspiffe://acme.dev/ops/billing
scoperead:ledger · write:draft
last actionreconciled 214 invoices
signature7f3a…e01c
stateverified

agentsupport-copilot-11
last actionrequested crm:export:all
staterevoked
What breaks without it

Four questions you can't answer about your agents right now

None of these are hypothetical. They're the questions that arrive in an incident channel at 11pm, or in an enterprise security questionnaire on a Tuesday — and today the honest answer to all four is a shrug.

No record
"What did it actually do?"
Your agent made forty thousand tool calls last month. The only record is whatever application logging the engineer who built it happened to write — unsigned, editable, and scattered across three services. There is no ledger of agent actions because nobody built one.
No enforcement
"What is it still allowed to do?"
The credential you issued in March is the credential it holds today. Scope was a decision made once, in a config file, and never checked again at runtime. An agent scoped to read invoices can attempt anything that credential permits — and nothing stops it or even notices.
No artifact
"How do you control your AI's access to our data?"
This is question 14 on every enterprise security review now. Today you answer it with a paragraph of prose in a document. Your buyer's security team has no way to verify a word of it, so they discount all of it — and the deal slows down.
No kill switch
"How fast can you stop it?"
Revoking a misbehaving agent means finding which credential it uses, rotating it, and hoping nothing else in production depended on that same key. Minutes at best. In the window between "something's wrong" and "it's stopped," the agent keeps working.
65%
of organizations had at least one AI-agent-caused security incident in the past year
97%
of orgs reporting an AI breach had no proper access controls on the agent involved
10–50×
how far machine and agent identities now outnumber human ones inside a typical company
$47B
Gartner's 2026 estimate for enterprise AI-agent spend, up from under $5B in 2023
Step Finance — DeFi trading platform $27–30M lost
"The agent did exactly what it was designed to do."

Attackers compromised executive devices, then didn't need to breach anything else. The platform's own trading agent already held unbounded permissions, and moved 261,000+ SOL tokens on command. The model didn't fail. The prompt didn't fail. There was simply no enforceable, verifiable limit on what that agent was permitted to do — and no signed record of it doing it.

The difference

Same agent. Same permissions. One of them can prove itself.

Agent Trust Fabric doesn't slow your agents down or route their traffic through us. It changes what exists after they act.

today Unverified agent
  • Identity is a long-lived API keyStored in an environment variable, shared between services, rotated when someone remembers.
  • Scope is a hopeWritten into a config once. Never enforced at the moment of action.
  • Actions are unlogged or self-loggedWhatever the agent's author chose to write down, in a format nobody agreed on.
  • Trust is a sentence in a PDF"We limit our AI agent's permissions." Unverifiable, so discounted.
  • Revocation takes minutes to hoursFind the key, rotate it, redeploy, hope.
with atf Verified agent
  • Identity is a short-lived signed certificateA unique spiffe:// identity per agent that rotates automatically and can't be replayed.
  • Scope is checked at every actionGranted scope is evaluated when the agent reaches for a tool, not when it was deployed.
  • Every action is signed and streamedA tamper-evident event log you didn't have to ask an engineer to build.
  • Trust is a live badge anyone can queryGreen while it stays in scope. Red the instant it doesn't. Embeddable in a trust page or README.
  • Revocation is immediate and automaticAn out-of-scope action suspends the identity itself — the next call fails.
How it works

Four steps from "we think it's fine" to "here's the proof"

No framework rewrite, no gateway to route traffic through. Agent Trust Fabric sits beside the agents you already run.

  1. Register the agent
    Point Agent Trust Fabric at a LangGraph, CrewAI, AutoGen, or custom agent process. Container, Lambda, or laptop — it doesn't matter where it runs.
  2. Issue an identity
    Each agent gets a unique spiffe:// identity and a short-lived signed certificate. Not a key in an env var — an identity that rotates and can't be replayed.
  3. Broadcast signed state
    Every tool call, scope request, and data access is signed and streamed as a trust-state event. This is the audit trail nobody had time to build.
  4. The badge goes live
    green while the agent operates inside its granted scope. red the moment it doesn't — an escalation attempt, an out-of-scope read, or a tool it was never issued.
The badge

One mark. Binary meaning. Anyone can check it.

Every other product in this category gives you a console your security team logs into. This gives you something you can hand to a customer.

Agent Trust Fabric — verified

Every action this agent has taken since its last identity rotation stayed inside its granted scope. Verified against the signed event log, not asserted by its owner.

Agent Trust Fabric — revoked

This agent attempted an action outside its granted scope. Its identity was suspended automatically, the call failed, and the attempt is in the log with a timestamp.

<iframe src="https://millenniums.ai/badge/billing-reconciler-03" width="240" height="48"></iframe>
Pricing

Land it in an afternoon, not a procurement cycle

You shouldn't need a signed MSA to find out whether your agent is behaving. Talk to us when you need SSO, long retention, or a few hundred agents — not before.

Free
$0
  • Up to 10 agent identities
  • Live green/red badge, embeddable anywhere
  • Signed trust-state event log, 30-day retention
  • Automatic revocation on out-of-scope action
  • Community support
Team
$149 /mo
  • Up to 50 agent identities
  • 1-year retention, exportable log
  • Slack & PagerDuty alerts on revocation
  • Webhook stream for your own SIEM
  • Email support, next business day
Business
$499 /mo
  • Up to 250 agent identities
  • Unlimited retention, audit-ready export
  • SSO/SCIM and role-based access
  • Custom trust-page domain for your badges
  • Priority support
Running more than a few hundred agents, or want the identities you register here mapped onto a full inventory of your cloud accounts, shadow-AI usage, and pentested applications? Agent Trust Fabric is one of seven capabilities inside Redthread — every agent you verify here is already a node in that graph, visible the moment you want to see it. Nothing to migrate.
The category

Everyone sells control. Nobody sells proof.

Agent and non-human identity is a real, funded category — three of its fastest-growing names were acquired into larger platforms during 2026. Here's how the independents present themselves, and where we think the gap is.

VendorHow they leadCategory wordStart without sales?
Agent Trust Fabric "Your agent has production access. Prove it deserves it." Agent trust & proof Free forever, self-serve
Aembit"IAM for Agentic AI" — secretless workload accessSecretless accessFree tier, published pricing
Natoma"Let your AI know everything your company knows."Managed MCPFree tier, published pricing
P0 Security"Authentication gets agents in. Authorization controls what happens next."AuthZ control planePricing page, no figures
Token Security"Identity-First AI Agent Security"Identity-firstDemo required
Clutch Security"Every Identity. Every Agent. Every Secret."Non-human identityDemo required
Britive"Zero standing privileges by design"PAM transformationQualification form
Andromeda"Identity Security for the Agentic Era"Identity posture (ISPM)Demo required

Public marketing copy as published September 2026. Vendors iterate quickly and several of these are excellent products — if you're running a large enterprise identity program, some of them are a better fit than we are. Verify current details directly before you decide.

What's crowded

Most of the category leads with some arrangement of discover, secure, govern. "Non-human identity," "runtime authorization," and "zero standing privilege" are all spoken for. We don't compete on those words.

What's missing

Every product in this category produces control, and control lives inside a console your security team logs into. None of them produce an artifact you can show someone else. That's the whole gap.

Who we're for

Not the identity program. The platform engineer who granted an agent production access this week and wants proof before anyone asks. That person can't get past a qualification form at 11pm.

Start free

Know what your agents can do. Prove it to everyone else.

Register your first agent, get its identity issued, and put a live badge somewhere in about five minutes.