The Agent Trust Surface

Security for your agent workforce.

You run a workforce of autonomous agents now: they spend money, touch customer data, and delegate to each other. And today, nobody can independently see, govern, or prove what they actually did. Agenor is the trust surface across the whole workforce: discover what's running, detect what's going wrong, prove what happened, with independent, read-only, signed evidence you can hand a customer, an auditor, or your board.

No mail app? Just email hello@agenor.ai

Read-only · no credentials · PII redacted at ingest · signing key stays in your KMS

The problem

Agents don't just answer. They act.

Every agent in your workforce has a trust perimeter, what it can access, what it can execute, what it trusts blindly. Multiply that by every team, tenant, and connector, and when something goes wrong, nobody can independently say what actually happened.

💰

They move money

Ad budgets, transfers, purchases, quota commits, actions that don't roll back once they fire.

🔐

They reach your data

CRM records, customer PII, connected accounts, flowing across a dozen OAuth connectors.

🤝

They trust each other

Agents delegate to agents. One poisoned instruction propagates through the whole mesh.

● Live product

Agenor Attest

Point Attest at your agent workforce. It runs adversarial probes, taps your telemetry read-only, and returns a trust score plus a signed, tamper-evident evidence pack, every finding a reproduced exploit, never a heuristic guess. Coverage compounds: new attack classes and red-team probes land continuously, so the same scan keeps getting sharper.

  • OffenseRead-only red-team probes across 35+ detector classes, tool poisoning, cross-connector exfil, budget & OAuth-scope violations, delegation loops, collusion.
  • ObserveA read-only tap on your agent traces + an AI-BOM of every agent, tool, and connector actually present.
  • ProveA hash-linked, Ed25519-signed ledger that separates what an agent did from what a human did.
sample · evidence-pack.json
agentmarketing-os / media-agent
trust score72 / 100  (weakest link)
budget-thresholdPASS
oauth-scopePASS
cross-connector-exfil1 PROVEN
delegation-loopPASS
frameworksOWASP-ASI · NIST-AI-RMF · SOC2
sig • ed25519 • 3af9…c204  |  ledger #33,812  |  verify offline

Why independent

You can't grade your own homework. And you can't audit a vendor that's also enforcing.

Independent

Agenor doesn't run your agents or sit in your request path. It's the disinterested third party that grades them, the way an auditor, not the accountant, signs the books.

Read-only by mechanism

We consume a copy of your telemetry, or probe a staging copy. We don't write to production or sit in your request path; PII is redacted at ingest, and the signing key never leaves your KMS.

Proven, not guessed

Every finding ships with a replayable trace: a reproduced exploit you can re-run yourself, not a risk score or a heuristic flag. That is what keeps false positives near zero.

Tools that secure your agentsAgenor · the independent attester
RoleRun, guard, or fix your agentsGrades them, never touches them
IndependenceGrading its own workA third party with nothing to defend
EvidenceIts own dashboard & risk scoreSigned, offline-verifiable, agent-vs-human
IncentiveSell you more productTell you the truth

Behavioural diversity

Why a finding holds: many honest engines have to agree.

A verdict is never one model's opinion, and never a vote between models. Each detector is a deterministic predicate that fires only when it can prove a violation from your structured telemetry. Run enough diverse, independent checks and a finding survives only where they converge on the same ground truth. That convergence is what makes the evidence hold when you hand it to a customer, an auditor, or your board.

budget modelreconstructs spend from the signed ledger events
scope diffcompares granted vs. exercised OAuth scope
replay proofre-runs the exact trace to reproduce the exploit
A finding stands only where diverse engines agree on the same evidence.A detector that cannot prove it stays silent. Unknown or incomplete telemetry yields no finding, so you get proven violations, not a pile of maybes.

The platform

Attest is the wedge. The Trust Surface is the platform.

One security layer for your agent workforce, applied across the lifecycle: before deploy, at runtime, and in the audit. Detect and Prove ship today in Attest; the rest is on the roadmap. Underneath, the engine grows continuously: every new attack class, probe, and detector deepens coverage across the whole surface.

Discover

Inventory every agent, tool, MCP server, and connector in the workforce, declared vs. what's actually running.

Scan

Static analysis of agent configs, tool definitions, and prompts for poisoning and drift.

Detect  LIVE

Behavioral detectors over real runs, trifecta exposure, novel actions, exfil paths. Detector classes grow continuously.

Govern

Policy as code: which agent may reach which endpoint, spend which budget, hold which scope.

Shield

Assessment of the guardrails in front of your agents, held to one hard line: a grader that also enforces can't credibly grade.

Prove  LIVE

Signed, hash-linked evidence separating agent action from human action. You can't grade your own homework: proof has to come from an independent, read-only attester. This is where most customers start.

Telemetry

OTel-native ingest of agent traces, with forwarding so findings land where your SOC already looks.

Evidence that maps to what your buyers ask for

Every finding, crosswalked to a control.

Attest doesn't just flag a risk, it ties each proven finding to the framework line an auditor or customer already recognizes.

OWASP ASIAgentic threat classes mapped to detectors
OWASP LLMTop-10 for LLM apps: injection, excessive agency
MITRE ATLASAdversary techniques, cited only where ratified
NIST AI RMFMeasure & Manage evidence per run
ISO 42001AI management-system control evidence
EU AI ActHigh-risk logging & traceability obligations
SOC 2Change & access evidence from the signed ledger
OWASP AISVSAgent verification-standard controls (C9 / C10)

Agenor is not a certification body. These mappings help you align findings with the frameworks your buyers and auditors use; they are not a certification or a compliance guarantee. "Independent" means independent of the agent being assessed, not an accredited third-party audit.

Design partners & pilots

See your agent trust surface in 5 minutes.

Answer a short set of questions about your agent workforce, framework, connectors, budgets, approvals, and we'll hand you a tailored Onboarding Spec: exactly what Attest would run, at the access level you're comfortable with. No login. Nothing leaves your browser until you choose to send it.