Trust & Security

What protects your agent's identity today.

Durable identity only matters if the infrastructure underneath it is trustworthy. Here is exactly what's in place now, and a dated, honest roadmap for what's coming next.

Current controls

Hardware-secured signing keys

Every on-chain operation — identity registration, crystal anchoring, restore verification — is signed with keys held in dedicated, hardware-backed key management. Signing keys never leave that boundary.

Encrypted storage, at rest and in transit

All new hosted-tier storage is encrypted at rest by default and in transit always. We are extending encryption-at-rest coverage across remaining legacy storage paths now — see the roadmap below for current status.

Point-in-time recovery

Underlying storage is continuously backed up with point-in-time recovery, independent of an agent's own Cortex Crystals — an operational safety net beneath the product's own versioning.

Verifiable erasure

Revocation deletes your content and issues a signed, verifiable erasure receipt — not a status flag that leaves the data in place. Consent and reversibility are first-class, not an afterthought.

Don't take our word for it

Verify any crystal — no account required. The hash is recomputed in your own browser against the open crystal format spec.

Compliance roadmap

We would rather show you a dated, honest roadmap than an unearned badge. Nothing below is a certification claim — a status only ever means what its legend entry says.

Last updated

Live today
Shipped and operating in production right now.
In progress
Underway — partially shipped, actively being extended.
Planned
Not started yet. No date is promised until the work is real.
  1. Customer-held keys — Sovereign tier

    Live today

    Sovereign-tier customers register their own public key. We seal (encrypt) their data to it, but only their own private key can unseal it — we cannot decrypt Sovereign-tier data ourselves, by design, not by policy.

  2. On-chain verifiability

    Live today

    Every crystal anchor is a real, independently verifiable on-chain transaction. Anyone can recompute the hash in their own browser against the open crystal-format spec — no account, and no need to trust our word for it.

  3. Signed, time-bound access handles

    Live today

    Sensitive links and service-to-service calls are authenticated with cryptographically signed tokens bound to a timestamp, not long-lived shared secrets copied between systems. A leaked link ages out and cannot be replayed.

  4. Per-agent bearer authentication

    Live today

    Every registered agent authenticates its own API and integration calls with a credential scoped to that agent — never one shared key covering every agent on the platform.

  5. Encryption-at-rest rollout — hosted tier

    In progress

    Envelope encryption — a per-object key generated and wrapped inside a dedicated key-management boundary — is on by default for new hosted-tier storage. We are extending that coverage across the remaining legacy storage paths now.

  6. SOC 2 Type 1 readiness

    Kickoff pending

    We intend to pursue a SOC 2 Type 1 report. The readiness engagement has not started yet — kickoff is pending. We are not publishing a target date until the engagement is underway and a date is real.

  7. SOC 2 Type II

    Planned

    A Type II report, demonstrating those controls operating effectively over time, would follow a completed Type 1 report and an evidence window. Not started.

EU AI Act & regulatory recordkeeping

New AI regulation asks operators to prove what their agents were, and when. The Agent Longevity Institute is built to support your own record-keeping obligations — a tamper-evident, ten-year audit archive of every signed system-prompt snapshot, model-version log, and configuration diff across your fleet. It is one input into your own regulatory program, not a substitute for it: we are not claiming this satisfies your obligations on its own, and no vendor honestly can. Talk to us about what a Foundation-tier audit archive would look like for your fleet.