Skip to content
Evoliv Core

Enterprise AI security

Foundational infrastructure for zero-trust AI agents

Evoliv Core is an enterprise AI security company. We build the identity, assurance and accountability layer that autonomous agents need before a business can trust them with real work.

The problem

Agents act on the web and inside enterprises. Nothing tells them apart.

An API key says someone has a copy of it. A user-agent string says whatever its author typed. Before an agent is trusted with an action, three questions need answers a machine can check.

01

Who is accountable for this agent?

A named operator, bound to a verified domain or a verified legal entity — not an anonymous key.

02

How strongly is that evidenced?

Graded assurance levels for the operator, the agent's key and any delegation — each backed by evidence, not by claims.

03

What can a website verify?

A signed credential and a signature on every request, checked offline against keys the site already holds.

What we build

A product, and the open standard it implements

Product

Project AIDR

The zero-trust identity layer for AI agents. A registry that verifies who stands behind each agent and issues short-lived credentials; a desktop gateway that keeps the agent's key on its own device and signs every request; a console to register, verify and revoke.

  • ✓Ed25519 keys generated on the device, never sent anywhere
  • ✓RFC 9421 signatures on every request
  • ✓Revocation that reaches relying parties within a minute
Explore Project AIDR

Standard · Draft 0.1

AIAF

The Agent Identity Assurance Framework: a proposed standard for the identity, assurance and accountability of autonomous software agents. It names no vendor, lets any registry issue identifiers, and is published for review with the intention of handing it to a neutral standards body.

  • ✓Three independent axes: operator, key and delegation assurance
  • ✓Conformance requirements for registries, relying parties and operators
  • ✓Explicit about what identity can and cannot prove
Read about AIAF
Verifier SDKs for Node.js, Python and Go — check an agent's identity on your own site, offline. Downloads →

How we build

Security you can check, claims you can hold us to

The key never leaves the operator

A registry must never generate, receive or store an agent's private key. One that did could impersonate every agent it serves.

Short-lived by design

Credentials last at most fifteen minutes, so a stolen one has a bounded life even if revocation fails entirely.

We say what cannot be proven

Which model an agent runs, how it will behave, whether it has been prompt-injected: none of these is verifiable over the wire, and we never present them as verified.

No single registry

Any registry may issue identifiers under AIAF, and relying parties choose which to trust. A framework that assumes one registry is a monopoly proposal, not a standard.

Running a website or an API?

Verify agents offline with our SDKs, and decide per action what assurance you require.

Resources

Operating AI agents?

Give each one an identity you can revoke, backed by your verified organisation.

Go to Console