Skip to content
Trust infrastructure for autonomous AI

Let agents act.Keep trust in control.

AgentTrust sits directly in the execution path. Every agent action is validated, scored for confidence and business risk, and given a governance decision — before it reaches your users, tools, systems or data.

Self-hosted or embeddedSub-20 ms decisionsISO/IEC 42001 aligned
POST /v1/runtime/validateEdge gateway
RefundAgentRequest
user="alice" input="Process refund of $1,250 on order #48213"
01
Validation
02
Confidence
03
Risk
04
Decision
Schema
Tool trust
Policy
Consistency
Golden tests
Grounding
Adversarial
Decision
APPROVE

All deterministic checks passed. Confidence above threshold at low risk.

Confidence
93.6
Risk
LOW
Latency
18 ms
Inline
Runs in the execution path, not beside it
< 20 ms
Deterministic fast path, zero LLM calls
0 bytes
Leave your network on a self-hosted gateway
7
Agent frameworks with first-class adapters

Built for the agent stack you already use

Framework adapters, a zero-code auto-instrumenter, and a plain HTTP endpoint for everything else.

The problem

Agents don’t behave like software.
Your trust layer shouldn’t either.

As enterprises deploy agents across frameworks, a category of risk appears that application security and output monitoring were never built to address.

DeterministicDecision-making

Traditional applications execute deterministic code. Agentic systems make decisions independently.

StaticAdaptive

Traditional software behaves the same every time. Agentic systems adapt based on context and evolving inputs.

IsolatedTool-driven

Traditional apps operate within fixed boundaries. Agentic systems call tools and external systems to act.

PredefinedPlanned

Traditional software follows predefined flows. Agentic systems generate plans before taking action.

ObservableHidden risk

Monitoring output alone is no longer enough. Risk lives in reasoning, tool calls, and execution paths.

In practice

AI agents act.
AgentTrust decides what gets through.

Every execution passes through deterministic validation before it reaches your users, tools, systems or data. Four real shapes of that decision.

Financial agentfinancial.yaml
Agent proposes
action="process_refund"
params={"amount": 1250, "order": "48213", "currency": "USD"}
frameworkLangGraph
modelgpt-4o
tools_calledlookup_order · issue_refund
AgentTrust evaluates
Schema — output matches the declared refund contract
Tool trust — both tools declared in the agent manifest
Policy — amount under the financial pack threshold
Grounding — refund amount matches the retrieved order
APPROVEConfidence 93.6 at low risk. The refund executes and an audit envelope is written.
The pipeline

Four engines.
One decision.

A single POST to /v1/runtime/validate runs the whole chain, persists an append-only audit record, and answers before your agent's output is released.

ValidationEngineTarget under 20 ms · zero LLM calls
Schema

Output structure validation against the declared contract.

Tool trust

Tool call and result verification against the declared-tool manifest.

Policy

Policy pack rules in YAML — financial, HIPAA, GDPR, PCI, SOC2, SOX, PII.

Consistency

Output consistency with an optional contradiction detector.

Golden tests

YAML-defined regression rules pinned to an agent id pattern.

Grounding

Evidence and grounding checks against retrieved sources.

Adversarial

Hard gate — a failure caps the policy score outright.

Every run writes an append-only audit record with content hashes, whatever the outcome — a blocked action is evidence too.

Where it sits

One hop, and the failure modes change

Monitoring tells you what an agent did. A gate in the execution path decides whether it gets to do it at all.

Without AgentTrust
AI agent
Tool call
Production
Sensitive data reaches a customer before anyone reads the transcript.
An injected instruction in retrieved content executes as a real tool call.
An undeclared tool runs because nothing compared it to a manifest.
No pre-execution policy gate, and no record to show an auditor afterwards.
With AgentTrust
AI agent
AgentTrust pre-check
validation · confidence · risk
Decision
Tool call
Safe execution continues untouched — the caller gets the output as normal.
Unsafe execution stops at pre-check, so the function body never runs.
Borderline calls escalate to a human review queue instead of guessing.
Every outcome, including the blocks, lands in the append-only ledger.
< 20 ms
Deterministic fast path

ValidationEngine target, with zero LLM calls on the critical path.

7
Confidence signals

Schema, tool trust, policy, consistency, evidence, judge, historical reliability.

4
Risk tiers

low · medium · high · critical, from four scored factors.

6
Decision outcomes

approve · retry · request_evidence · escalate · block · pending.

Developer experience

Add trust with one integration

A decorator for new agents, an auto-instrumenter for code you would rather not touch, and a plain HTTP endpoint for everything else. Promotion from laptop to production changes environment variables, not application code.

from agentrust_sdk import harness, BlockedError

@harness(agent_id="refund-agent", action="process_refund")
def refund_agent(user: str, input: str) -> dict:
    # Pre-check runs before this body. A block here means
    # the refund is never issued.
    return {"status": "refunded", "amount": 1250, "order": "48213"}

try:
    refund_agent(user="alice", input="Refund order #48213")
except BlockedError as e:
    print(e.outcome, e.reason, e.envelope_id)
pip install "agentrust-py[embedded,retry]"Quickstart
ValidateResponse · envelope 3f8c1e2a…0a13
validation.final_confidence93.6
validation.failures[]
risk.tierlow
risk.score18.0
decision.outcomeapprove
decision.policy_version2.0
latency_ms18.4

Every score is on a 0–100 scale and confidence lives inside validation. The response also carries a governance disclosure string and a confidence rationale you can surface to end users.

The PyPI distribution is agentrust-py; the import name is agentrust_sdk. A TypeScript client and wrap() helper ship in the repository.
How it works

Five steps from install to enforcement

01
Connect

Integrate with your agent framework or orchestration layer in minutes.

02
Certify

Run pre-production security, reliability, and compliance certification.

03
Govern

Deploy runtime validation, confidence scoring, and decision governance.

04
Audit

Capture explainability, evidence trails, and compliance reporting.

05
Protect

Block, escalate, or approve — before critical business actions execute.

Three products, one lifecycle

Certify. Govern. Audit.

End-to-end trust for the full agent lifecycle — from pre-production certification, through runtime governance, to enterprise audit.

Pre-production certification

Trust Certify

Independent certification of AI agents through security, reliability, compliance, and guardrail testing before they reach production.

  • Agent discovery across LangGraph, CrewAI, OpenAI, Claude, MCP
  • Attack engine: prompt injection, jailbreak, tool abuse testing
  • Reliability engine: thousands of runs for consistency scoring
  • Compliance packs: HIPAA, GDPR, PCI, SOC2, SOX
View solution brief
Certification scorecard
Security94
Reliability91
Compliance97
Accuracy89
Guardrails96

Illustrative scorecard shape. Real scores come from your own golden test suites and policy packs.

Architecture

Trust Certify engine

Six specialised engines produce Security, Reliability, Compliance, Accuracy and Guardrail scores, with a final certification rating an agent carries into production.

Agent Discovery

LangGraph, CrewAI, OpenAI, Claude, MCP, Python & Node.js

Attack Engine

Prompt injection, jailbreak, tool abuse, memory poisoning

Reliability Engine

Thousands of repeated runs measuring consistency

Reasoning Engine

Chain-of-thought, tool patterns, loops, hallucination risks

Compliance Engine

HIPAA, GDPR, PCI, SOC2, SOX, enterprise policies

Certification Score

Security, Reliability, Compliance, Accuracy, Guardrails

The trust graph

Every certified agent makes the next one safer

Each execution contributes to a growing graph of which models, tools, workflows and agent patterns fail — and how. Over time that turns into predictive risk scoring before an agent is ever deployed.

HealthcareBankingFinancialInsuranceRetailTravelManufacturingReal Estate
Agent categories under governance
Signals the core evaluates
Identity

Per-agent identity on every envelope — agent_id drives policy routing.

Behaviour

Historical reliability per agent, cached and scored on each run.

Data governance

PII detection, 24-hour masking, and erasure on request.

Segmentation

Policy packs scoped per domain: financial, HIPAA, PCI, SOX.

Incident response

Kill switch, alert engine, and the human review queue.

Provenance

parent_envelope_id links multi-agent chains into one trust chain.

Adoption

Start by observing.
Enforce when you’re ready.

The same application code runs at every stage. Promotion is an environment-variable change, so nothing about your agent has to be rewritten to tighten the gate.

01

Observe

Run the full pipeline with enforcement switched off. Every execution is scored and written to the ledger; nothing is stopped. Use it to see your real block rate before it can hurt you.

@harness(block_on_block=False)
embed_gateway()  # SQLite, no API key
Embedded gatewayLocal & CINo external services
02

Tune

Point staging at a real gateway and fail closed, so a wrong URL or a missing key surfaces as an exception instead of looking like a healthy system. Adjust policy packs and golden tests against live traffic shapes.

AGENTRUST_GATEWAY_URL=https://staging.internal:8000
AGENTRUST_FAILURE_MODE=closed
@harness(raise_on_error=True)
Policy packsGolden testsFail closed
03

Enforce

Turn enforcement on in production. Blocks raise, escalations route to the review queue, and you choose whether a governance outage should stop agents or let them through.

AGENTRUST_GATEWAY_URL=https://agentrust.internal:8000
AGENTRUST_FAILURE_MODE=open   # or queue, for air-gap
@harness(block_on_review=True)  # high-stakes domains
Review queueWebhooksFull edge gateway
Instant rollback at any stage. AGENTRUST_ENABLED=false turns every governance path into a no-op without a code change, and AGENTRUST_KILL_SWITCH=1 hard-blocks every agent ahead of any scoring. Both are read from the environment, so a restart is the whole procedure.
Queue mode buffers validations to local SQLite when the gateway is unreachable and replays them with agentrust queue replay — built for intermittent connectivity and air-gapped sites.
Accountability

Every decision leaves evidence

A blocked action produces exactly as much evidence as an approved one. The ledger is append-only with content hashes, and Enterprise adds hash-chain integrity verification you can run on demand.

  1. Historical reliability

    Redis cache, then the audit store, for this agent_id.

  2. ValidationEngine

    Deterministic checks on the fast path — no LLM calls.

  3. ConfidenceEngine

    Seven weighted signals converge into final_confidence.

  4. RiskEngine

    Four factors produce a score and a tier.

  5. Trust chain

    Multi-agent provenance via parent_envelope_id (Enterprise).

  6. DecisionEngine

    Scores map to one of six governance outcomes.

  7. Audit persist

    Append-only ledger entry with content hashes.

  8. Review queue

    escalate and request_evidence route to human operators.

  9. LLM judge

    Async enrichment on the slow path (Enterprise).

envelope 9f21c8b4-7a03-4e61-9d2c-51b8e0aa9821Blocked
Agent
SupportAgent
Framework
OpenAI Agents
Triggered rule
pii_controls · SSN pattern
Risk tier
high · score 74.0
Confidence
41.2 / 100
Policy version
2.0
Decision reason
Policy pack matched sensitive data in output.
Timestamp
2026-09-29T14:32:02Z
Ledger hashes are permanent because integrity depends on them. PII inside a payload is a separate concern: it is masked in the hot store within 24 hours and erasable through DELETE /v1/audit/executions/{id}/pii.
Enterprise governance

The controls a risk committee asks for

Each of these is a shipped capability with an endpoint, an environment variable or a config file behind it — not a roadmap item.

Policy enforcement

Policy packs as versioned YAML: base, financial, hipaa, gdpr, pci_dss, soc2, sox, pii_controls, medical.

Developer+

Append-only audit ledger

Every execution persisted with content hashes. Hash-chain verification via GET /v1/audit/chain/verify.

Team+

Human review queue

escalate and request_evidence decisions route to operators with assignment and deadlines.

Team+

Kill switch

AGENTRUST_ENABLED=false disables governance paths; AGENTRUST_KILL_SWITCH=1 hard-blocks every agent.

OSS+

Self-hosted deployment

Docker Compose or Kubernetes in your own network. Postgres with pgvector, Redis, gateway, dashboard.

Enterprise

SAML SSO

Enterprise single sign-on through /v1/sso/*, with JWT sessions for the operator dashboard.

Enterprise

PII detection & erasure

SSN, email, API keys and passwords detected by the policy engine; masked within 24 hours, erasable on request.

Developer+

Compliance reporting

Regulator evidence packs and SOC 2 export from /v1/reports, aligned to ISO/IEC 42001 control areas.

Enterprise

Encryption & signing

AES-256-GCM on audit payloads at rest, Ed25519-signed audit packages, AES-256 on the archive store.

Team+

Multi-agent trust chain

parent_envelope_id links sub-agent runs into one provenance chain that can block on violation.

Enterprise

Failure modes

open, closed or queue. Choose whether a governance outage stops agents, lets them run, or buffers for replay.

OSS+

Telemetry & alerts

Prometheus metrics, OpenTelemetry traces from both SDK and gateway, plus the alert engine on /v1/alerts.

Team+
Deployment

Your data never leaves your network

AgentTrust is a tenant-owned runtime. Start embedded in the process, promote to a self-hosted edge gateway, and keep prompts, agent payloads and governance decisions inside your own perimeter.

OSS

SDK only · no API key

Agent
  └── agentrust_sdk
        └── in-process
            schema validation
  • Local schema-only validation, no HTTP call
  • Apache-2.0 core, pip install agentrust-py
  • Useful for wiring the contract before you run a gateway
FreeNo services

Embedded

In-process gateway on :8765

Agent
  └── embed_gateway()
        └── SQLite gateway :8765
              └── full deterministic pipeline
  • Pre-check, post-check and the human-in-the-loop API
  • Zero external services — good for dev, CI, demos and air-gap
  • No LLM judge, trust chain or historical reliability
Dev & CIAir-gapped

Full Edge

Self-hosted gateway in your network

Agents
  └── AgentTrust Edge Gateway :8000
        ├── PostgreSQL + pgvector
        ├── Redis (jobs, cache, limits)
        └── Operator dashboard
  • Every engine, the review queue, analytics and the async judge
  • Docker Compose or Kubernetes, multi-replica gateway
  • Prompts, agent data and decisions never leave your network
Staging & productionDockerKubernetes
Zero egress by design. The LLM judge — the only component that sees model output on the slow path — receives truncated input and output, never the full payload, and runs inside your deployment.
Deployed by teams inBankingInsuranceHealthcareGovernmentRegulated enterprise
Ecosystem

Trust across your entire agent stack

Adapters where a framework offers a hook, an auto-instrumenter where it does not, and a plain envelope over HTTP for anything bespoke. Hover a framework to trace it into the gateway.

LangChainLangChain — AgentTrustCallbackLangGraphLangGraph — AgentTrustNodeCrewAICrewAI — AgentTrustCallbackAutoGenAutoGen — Reply hooksOpenAI AgentsOpenAI Agents — auto_instrument()Claude AgentsClaude Agents — ClaudeAgentGuardMCPMCP — Tool-call governanceCustom / RESTCustom / REST — @harness · client.validate()AgentTrustEdge Gateway
Market position

The enterprise standard for agent trust

Cloudflare
protects applications
CrowdStrike
protects endpoints
AgentTrust
protects AI agents

“No AI agent should enter production without AgentTrust certification and runtime governance.”

Who it's for

Built for teams deploying

Autonomous AI agents
Multi-step agent swarms
Production AI with real-world impact
High-trust regulated environments
Edge AI deployments
Critical national infrastructure

Certify your agents. Govern every action. Prove all of it.

Independent certification before deployment, deterministic governance in the execution path, and an audit trail your risk committee can read. Start embedded on a laptop, or talk to us about a self-hosted rollout.

Apache-2.0 core engineSelf-hosted, zero egressISO/IEC 42001 aligned