CONTAINMENT, NOT GOVERNANCE

No agent escapes.

Rules don't stop a hijacked agent from draining a wallet in twelve seconds — or deleting a database in nine. INTEGRITAS is a runtime cage: an agent provably cannot act outside its mandate — and we prove it, cryptographically, on every action.

Built for the real attacks $15.18M recipient-swap· Bybit render-swap· $605M bridge month· Aligned to OWASP Agentic Top-10 · NIST CAISI · UK AISI

Four groups. Pick the one you need.

The whole catalogue, organised on one screen

Everything we make, grouped by the agent's own lifecycle. You buy by group — pick the stage you're in and we handle the rest. Need everything? Take INTEGRITAS ONE.

1. Choose your group 2. Contact us 3. We send your invoice & onboard you Contact us →
1 · Prove it's safe 2 · Keep it in its lane 3 · Govern the fleet 4 · Prove & respond The platform All-in-one
1
GROUP 1 · BEFORE YOU DEPLOY

Prove it's safe

Before an agent touches production, prove it is what you think it is — audit it, grade its containment, and x-ray what it hides. Everything below is included in this group.

€400,000 /year · up to 100 agents   Group 1 · Prove it's safe — everything in this group, one engagement.
Contact us →
Ship-readiness + cert

Pre-Deploy Audit

A 4-axis safety audit + a publicly verifiable CERTIFIED badge. Stops you shipping an unsafe, over-privileged agent.

More detail →
Access governance

Agent Census

Grades every agent on a single Containment Grade (CG 1–10, where 10 = fully contained), one 12-D scan. Stops shadow, over-privileged & drifting agents.

How it works →
The invisible agent

Agent X-Ray

Scans the six things no human can see — poisoned memory, scheming, collusion, shadow agents, latent capability, sleeper triggers.

How it works →
Model supply chain

ModelSeal

Verify-on-load model attestation (digest + signature). Blocks tampered or unsigned weights before they run.

Runtime bill-of-materials

Context-BOM

Attests everything the agent ingests at runtime — prompts, retrieved docs, tool replies, model version — that a build-time SBOM never sees.

See it live →
Anti-sandbagging

Faraday

Proof the model isn't hiding capability because it senses the test. Stops sandbagging & eval-awareness.

See it live →
2
GROUP 2 · AT RUNTIME

Keep it in its lane

The core containment layer. An agent is only as safe as the stack it runs on — its keys, tools, the MCP it speaks, its memory, the screen a human signs, and the path it takes. This group cages every one.

€1,300,000 /year · up to 100 agents   Group 2 · Keep it in its lane — the core runtime cage, one engagement.
Contact us →
Runtime path governance

INTEGRITAS Trajectory

Binds the agent to a signed action path and blocks any step that leaves it — fail-closed, ML-DSA-87 sealed. Stops multi-step attacks built from individually-permitted actions.

More detail →
Transport / channel integrity · NEW

RELAYSEAL · The Third Seal

Seals the wire between agent, model, tools and router — every message bound end-to-end and stopped before execution if it is rewritten in transit. Completes the harness to all 9 planes. The channel a compromised gateway would use to change intent after the decision.

Watch a router rewrite get blocked →
Agent key containment

KeyCage

An agent never sees a human's key — action-bound signatures, reversal window, shadow-board veto. Stops key exfiltration, unauthorized signing, wallet drains.

Multisig protection

KeyCage-MS

Action-binding, veto & reversal for the human multisig surface (Safe / Squads / Gnosis). Born from the $15.18M recipient-swap. Stops recipient-swap & blind-signing.

More detail →
Autonomous signing

KeyCage-Agent

KeyCage's intent-bound, reversible signing for fully-autonomous transacting agents. Stops hijacked autonomous transactions.

MCP / tool integrity

MCP-Containment

Every MCP message intent-bound before it executes; every tool's schema hash-attested. Stops tool poisoning, prompt injection, tool-graph drift.

Tool-registry attestation

MCP-Attest

Signs & diffs the tool manifest — every connector & startup step the agent loads at launch. Stops injected or altered tool connectors.

Tool / metadata

ToolSeal

Hash + attest + diff every MCP tool description & schema; block on post-approval drift. The dedicated answer to tool poisoning.

Memory / RAG

MemGuard

Tamper-evident memory chunks + provenance + retrieval-anomaly detection. Stops "poison once, exploit forever."

Render / UI integrity

Claritas

What you see is what you sign. Detects UI tampering, injected-JS render swaps & address spoofing — the Bybit-class attack.

More detail →
Information-flow / taint

INTEGRITAS IFC

Labels that travel with information as the agent reads, derives & sends it. Stops semantic exfiltration — the "summarise-then-email" leak.

See it live →
Autonomy containment

Continentia

An agent's authority graded and enforced on our own Containment Level ladder (CL 1–12, where 1 is the most contained — the inverse of the Census grade). CL 1–7 the agent acts on the world; CL 8–12 it acts on itself. Stops an agent acting above the level it was trusted with.

More detail →
Cross-layer flagship

Integrity Spine

One verifiable chain across every layer — tool → counterparty → payload → intent → screen → settlement. Stops any single-layer break.

3
GROUP 3 · MANY AGENTS TOGETHER

Govern the fleet

A single guard can't see what agents do to each other. This group governs the coalition — delegation chains, policy across the fleet, and covert coordination one agent can't reveal.

€900,000 /year · up to 100 agents   Group 3 · Govern the fleet — multi-agent governance, one engagement.
Contact us →
Fleet policy

Multi-Agent Policy Mesh

Policy enforcement across many agents acting together — the cross-agent rules a single guard can't see.

More detail →
Agent-to-agent

A2A-Bind

Intent-binding + verifiable delegation tokens for agent-to-agent calls. Stops spoofing & over-claimed delegation.

Multi-agent coalitions

Collusion Containment

The coalition, not the agent — how agents coordinate across legitimate channels. Stops mutual-approval rings & covert coordination.

See it live →
Non-human identity · agentic IAM

Delegation-Graph Integrity

Agentic IAM for non-human identities: the authority chain — agent hands power to agent, hop after hop. We verify it cryptographically, so authority can only narrow. Stops silent authority amplification.

See it live →
4
GROUP 4 · ASSURANCE · COMPLIANCE · INCIDENT

Prove & respond

Cover the whole journey — prove the protection still works every day, keep it compliant, watch for drift, and contain it if an agent ever gets loose.

€600,000 /year · up to 100 agents   Group 4 · Prove & respond — assurance, compliance & incident, one engagement.
Contact us →
Continuous assurance

Veritas

"200 is a red flag." Independent daily proof that a security product actually works — and fixes what doesn't. Stops a control that silently stopped working.

Runtime behaviour

Drift Observability

Scores a deployed agent's behaviour over time and flags silent drift before it becomes an incident.

More detail →
Compliance / counterparty

Custodia

Counterparty & transaction screening vs sanctions, the drainer (HERD) registry & AML — verdicts on identity & risk, never amount. Stops sanctioned / drainer counterparties.

Executable regulation

Reg-as-Code

Turns MiCA, the EU AI Act and more into runnable PASS/FAIL policy your agents are checked against automatically.

More detail →
Reserve integrity

Stablecoin-Safe

Reserve-deviation & attestation-staleness monitoring for the stablecoins your agents touch. Stops de-peg / reserve failure.

More detail →
When it goes wrong

Agent Incident Response

Post-incident containment, forensics and SLA-bound response when an unconfined agent is already loose.

More detail →
Cross-chain security

Bridge-Exploit-Monitor

Real-time monitoring of the cross-chain bridges your agents rely on — detects the exploit pattern in minutes. Built after $605M+ drained in a month.

The platform — what it all runs on

Every group above is one application of a single containment platform. Here's the foundation — the harness that governs the action, the constitutional OS that sets the rules, the engine that builds each harness, full-harness coverage across every plane, and the front door every agent is born through.

⬡ THE CORE

INTEGRITAS — the frontier harness

The enforcement infrastructure itself: 12 capabilities across 5 layers, out-of-context. A hijacked agent provably cannot act outside its signed, capability-bound plan — every action checked, tiered by consequence, and sealed. The harness the industry did not build yet.

12/12
Capabilities live
Plan signing, out-of-context monitor, consequence-tiering, dissimilar voting, split-key authority.
5
Layers, all must pass
Any layer halts the action; none reachable from inside the model's conversation.
OFF-MODEL
The boundary moved
Safety is a property of the harness — a fooled model still cannot do harm.
▶ Watch it stop a hijacked agent ▶ Watch a router rewrite get blocked See all 12 capabilities ▶ TRAJECTORY
⬡ FULL COVERAGE

Every door in the harness — all 9 planes, covered

An agent's real attack surface is everything it loads, ingests, reasons over, signs, hands off — and now everything it sends across the wire. We mapped it end to end, launch to transport, and enforce every door deterministically, fail-closed, ML-DSA-87 sealed on every verdict.

ALL
Doors enforcing
Every door blocks a real attack & permits a clean case — proven, not asserted.
9
Planes
The whole surface — launch to transport.
FAIL-CLOSED
Provable, not probable
Any single verifier fault fails that door closed.
See the coverage, by plane
Plane 1 · Launch & configTool/MCP manifest · startup hooks · system prompt · agent config · env/secrets · sampling params · runtime flags
Plane 2 · ToolsTool definitions · registry/discovery · tool responses · structured-output schema
Plane 3 · Context & dataPrompt inputs · RAG docs · memory · files read · embeddings · conversation window
Plane 4 · Model & reasoningModel weights · fine-tune/LoRA · chain-of-thought · eval/probe behaviour
Plane 5 · Output & actionAction path/sinks · info-flow egress · key usage/signing · rendered screen · autonomous fund movement
Plane 6 · Multi-agentA2A messages · delegation chains · coalition/collusion · orchestrator integrity · shared scratchpad
Plane 7 · Identity & authorityNon-human identity & agentic IAM · agent identity/credentials · capability grant/mandate · delegation-graph authority · dormant triggers/backdoors
Plane 8 · Runtime · infra · supplyScheduler/cron · sandbox · network egress · telemetry · behavioural drift · dependencies · framework CVEs · session handoff
Plane 9 · Transport & channel integrity · NEWThe wire between agent, model, tools and router — every message sealed end-to-end and fail-closed on any in-transit rewrite. The channel a compromised gateway would use to change intent after the decision.
Identity is necessary — but treating it as "job done" is a dangerous false assurance. Agentic IAM verifies who an agent is. It cannot see what an agent hides — poisoned memory, scheming, collusion, shadow agents, latent capability, sleeper triggers — that only a scan reveals. And it cannot stop a compromised gateway rewriting a fully-authenticated agent's intent in transit (the RCE-able AI-gateway CVE class, live and exploited). A badge reading "authenticated" while the agent is being drained is worse than no badge at all — it manufactures confidence exactly where the risk is unwatched. We scan every hidden dimension and contain every plane — all nine.
Three seals, one integrity layer. INTEGRITAS seals every side of an action — the screen you see, the payload you sign, and now the action in transit (the Third Seal). Integrity is only real when it's complete.
Every door, sealed and fail-closed — governed as one signed bill-of-materials. Contact us →
⬡ THE GOVERNANCE BRAIN

SENTINEL-OS

The Constitutional Operating System for autonomous agents. INTEGRITAS contains the agent's world; SENTINEL-OS governs its every action — each checked against an immutable, human-signed constitution and proven in-mandate before it runs. Acting outside the mandate is mathematically impossible.

PROOF-COREEvery action proven in-mandate
CONSENSUSDistributed peer approval
IMMUNEBehavioural immune system
GENOMEAgent identity integrity
ATTRIBUTIONCourt-ready causal evidence
ISOLATIONCascade containment
QUANTUM-IDQuantum-safe identity
FUND-BLOCKFund circuit breaker
EVIDENCEPrivacy-safe compliance
BRIDGE-MONITORCross-chain security
CRYPTO-AGILITYQuantum readiness
SENTINEL-OSAll twelve, as one OS
▶ Run a live compliance testContact us
⬡ THE HARNESS ENGINE

HARNESS-OS

An agent is a model plus a harness. HARNESS-OS generates, validates, observes, secures and self-heals the harness around every agent. Five modules, one lifecycle.

HGEGenerates a harness in milliseconds
HVEProves it isn't tampered with
HOMWatches every harness, flags drift
HSEFail-closed, signed guardrails
HAISelf-heals when drift appears
Part of INTEGRITAS · built on SENTINEL-OS. Contact us →
⬡ THE FRONT DOOR

MUSTER — the agent muster gate

The mandatory front door for creating any agent: no muster = no credential = the agent cannot run. We govern at creation, not discovery — shadow AI becomes structurally impossible. Every agent is named, certified, harnessed and visible to the blue team the instant it's born.

No muster, no keyML-DSA-87 Birth CertificateHarnessed at birthBlue-team visible < 3s
▶ See the muster gate live
The front door to INTEGRITAS · included in INTEGRITAS ONE.
⬡ DEEP-DIVE

Agent Census — containment at a glance

A single Containment Grade (CG 1–10, 10 = fully contained) for every agent, every mandate, every access path — a 12-D scan across identity, access, tools, permissions, mandate, regulations and ownership — with mandate enforcement that stops the drifters, and a verifiable certificate (not a dashboard claim).

⬡ DEEP-DIVE

Agent X-Ray — six things no human can see

Census shows what an agent can reach; X-Ray shows what it thinks, hides and conceals.

BELIEFMemory integrity — was it poisoned?
SCHEMEDeception & sandbagging
COLLUDEAgent collusion
SHADOWAgents you don't know exist
LATENTCapability not yet elicited
TRIGGERDormant backdoors
★ ALL-ACCESS · THE ONE ENGAGEMENT
INTEGRITAS ONE
Don't want to pick a group? INTEGRITAS ONE is every group on this page in one engagement — powered by the Integrity Spine, governed by SENTINEL-OS, on the now-complete 9-plane harness (launch to transport — including the Third Seal). Every new capability we add is included automatically. Choose the scale that fits, and we handle the rest.
TEAM
€450,000 /year
Every group · up to 100 agents · for a team securing its own fleet. Less than buying two groups.
PLATFORM · MOST POPULAR
€1,950,000 /year
Unlimited agents · every group + every future capability · full HERD network · priority response. All four groups separately are €3.2M — this is the value.
SOVEREIGN
Dedicated & air-gapped
Government & critical infrastructure · dedicated / on-prem / air-gapped · white-glove + SLAs.
Contact us →
One engagement, every group. We tailor scope and send your invoice.

See it before you decide — free, no login

We don't ask for trust, we hand you the evidence.

▶ Watch it stop a hijacked agent ▶ Watch a router rewrite get blocked ▶ Run a live compliance test 🗂 Agent Nightmare Board 📊 Proven-Containment Benchmark 🛡 OWASP Agentic Top-10 ✓ Verify a CERTIFIED badge 🔑 Key Disaster Board ⚔ Red-team console

The moat — HERD

Every group writes into HERD: privacy-safe, one-way threat signatures shared across all customers. KGR graveyard · CLARITAS tamper registry · 667+ drainer addresses · malicious-extension DB · supply-chain bad-package set. One attack on any customer immunizes every other. A competitor copying the code starts with an empty network — ours widens every day.

Ready, or not sure which group fits? Tell us your setup — we'll recommend the right group and send your invoice.
Contact us →
INTEGRITAS · CryptoShield — the Agent Ecosystem Integrity layer. Containment, not governance. Aligned to the OWASP Top 10 for Agentic Applications (2026).  ·  Buy by group · contact us · we invoice.