What protects your agent's identity today.
Durable identity only matters if the infrastructure underneath it is trustworthy. Here is exactly what's in place now, and a dated, honest roadmap for what's coming next.
Current controls
Hardware-secured signing keys
Every on-chain operation — identity registration, crystal anchoring, restore verification — is signed with keys held in dedicated, hardware-backed key management. Signing keys never leave that boundary.
Encrypted storage, at rest and in transit
All identity records, crystal contents, and memory references are encrypted at rest and in transit. Nothing about an agent's cognitive state is ever stored or moved in the clear.
Point-in-time recovery
Underlying storage is continuously backed up with point-in-time recovery, independent of an agent's own Cortex Crystals — an operational safety net beneath the product's own versioning.
Cryptographic right-to-be-forgotten
Revocation produces a real, verifiable erasure receipt — not a soft-delete flag a company could quietly reverse. Consent and reversibility are first-class, not an afterthought.
Don't take our word for it
Verify any crystal — no account required. The hash is recomputed in your own browser against the open crystal format spec.
Compliance roadmap
We would rather show you a dated, honest roadmap than an unearned badge.
Compliance-automation program underway
A dedicated compliance-automation platform and policy pack are being adopted now, with evidence collection wired to our infrastructure — the groundwork for a formal audit.
SOC 2 Type 1 report — target Q4 2026
We are committed to completing a SOC 2 Type 1 audit, targeted for Q4 2026, covering the controls that matter to security-conscious buyers.
SOC 2 Type II — following Type 1
A Type II report, demonstrating those controls operating effectively over time, is the planned next step after Type 1 and an evidence window.
EU AI Act & regulatory recordkeeping
New AI regulation asks operators to prove what their agents were, and when. The Agent Longevity Institute is built to support your compliance obligations — a tamper-evident, ten-year audit archive of every signed system-prompt snapshot, model-version log, and configuration diff across your fleet. It is one input into your own compliance program, not a substitute for it: we do not claim to make your organization compliant, and no vendor can. Talk to us about what a Foundation-tier audit archive would look like for your fleet.