01
Who is accountable for this agent?
A named operator, bound to a verified domain or a verified legal entity — not an anonymous key.
Enterprise AI security
Evoliv Core is an enterprise AI security company. We build the identity, assurance and accountability layer that autonomous agents need before a business can trust them with real work.
The problem
An API key says someone has a copy of it. A user-agent string says whatever its author typed. Before an agent is trusted with an action, three questions need answers a machine can check.
01
A named operator, bound to a verified domain or a verified legal entity — not an anonymous key.
02
Graded assurance levels for the operator, the agent's key and any delegation — each backed by evidence, not by claims.
03
A signed credential and a signature on every request, checked offline against keys the site already holds.
What we build
Product
The zero-trust identity layer for AI agents. A registry that verifies who stands behind each agent and issues short-lived credentials; a desktop gateway that keeps the agent's key on its own device and signs every request; a console to register, verify and revoke.
Standard · Draft 0.1
The Agent Identity Assurance Framework: a proposed standard for the identity, assurance and accountability of autonomous software agents. It names no vendor, lets any registry issue identifiers, and is published for review with the intention of handing it to a neutral standards body.
How we build
A registry must never generate, receive or store an agent's private key. One that did could impersonate every agent it serves.
Credentials last at most fifteen minutes, so a stolen one has a bounded life even if revocation fails entirely.
Which model an agent runs, how it will behave, whether it has been prompt-injected: none of these is verifiable over the wire, and we never present them as verified.
Any registry may issue identifiers under AIAF, and relying parties choose which to trust. A framework that assumes one registry is a monopoly proposal, not a standard.
Verify agents offline with our SDKs, and decide per action what assurance you require.
ResourcesGive each one an identity you can revoke, backed by your verified organisation.
Go to Console