-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathindex.html
More file actions
430 lines (405 loc) · 21.8 KB
/
Copy pathindex.html
File metadata and controls
430 lines (405 loc) · 21.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>AgenTrust: Open Specifications for Verifiable AI</title>
<meta name="description" content="Prove what your AI ran and what it did: open specifications and verifiers that bind model weights, agent identity and tool calls to hardware attestation.">
<link rel="canonical" href="https://agentrust-io.com/">
<meta name="robots" content="index, follow">
<!-- Icons -->
<link rel="icon" href="/favicon.ico" sizes="any">
<link rel="icon" type="image/png" sizes="32x32" href="/favicon-32x32.png">
<link rel="icon" type="image/png" sizes="16x16" href="/favicon-16x16.png">
<link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png">
<!-- Open Graph -->
<meta property="og:type" content="website">
<meta property="og:site_name" content="AgenTrust">
<meta property="og:title" content="AgenTrust: Open Specifications for Verifiable AI">
<meta property="og:description" content="Prove what your AI ran and what it did: open specifications and verifiers that bind model weights, agent identity and tool calls to hardware attestation.">
<meta property="og:url" content="https://agentrust-io.com/">
<meta property="og:locale" content="en_US">
<meta property="og:image" content="https://agentrust-io.com/og.png">
<meta property="og:image:width" content="1200">
<meta property="og:image:height" content="630">
<meta property="og:image:alt" content="AgenTrust: open specifications for verifiable AI">
<!-- Twitter -->
<meta name="twitter:card" content="summary_large_image">
<meta name="twitter:title" content="AgenTrust: Open Specifications for Verifiable AI">
<meta name="twitter:description" content="Prove what your AI ran and what it did: open specifications and verifiers that bind model weights, agent identity and tool calls to hardware attestation.">
<meta name="twitter:image" content="https://agentrust-io.com/og.png">
<!-- Structured data: Organization + WebSite -->
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "Organization",
"@id": "https://agentrust-io.com/#organization",
"name": "AgenTrust",
"url": "https://agentrust-io.com/",
"description": "Open specifications and verifiers for the AI supply chain: model weights, agent identity, tool calls and delegation, bound to hardware attestation and checkable offline.",
"sameAs": [
"https://www.linkedin.com/company/agentrust-io/",
"https://github.com/agentrust-io",
"https://trace.agentrust-io.com",
"https://manifest.agentrust-io.com",
"https://cmcp.agentrust-io.com",
"https://ca2a.agentrust-io.com",
"https://wcm.agentrust-io.com",
"https://tests.agentrust-io.com",
"https://governance.agentrust-io.com",
"https://github.com/agentrust-io/agentrust-telemetry"
]
},
{
"@type": "WebSite",
"@id": "https://agentrust-io.com/#website",
"name": "AgenTrust",
"url": "https://agentrust-io.com/",
"publisher": {
"@id": "https://agentrust-io.com/#organization"
}
}
]
}
</script>
<!-- Structured data: the open specifications, in chain order -->
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "ItemList",
"name": "AgenTrust open specifications",
"itemListElement": [
{
"@type": "ListItem",
"position": 1,
"item": {
"@type": "TechArticle",
"name": "Weight Custody Manifest (WCM)",
"headline": "Weight Custody Manifest (WCM)",
"url": "https://wcm.agentrust-io.com/",
"description": "An open, pre-1.0 specification that binds model-weight identity and custody terms to key-release policy when a builder deploys weights into infrastructure it does not control."
}
},
{
"@type": "ListItem",
"position": 2,
"item": {
"@type": "TechArticle",
"name": "Agent Manifest",
"headline": "Agent Manifest",
"url": "https://manifest.agentrust-io.com/",
"description": "A structured, machine-readable declaration of an agent's capabilities, permissions, and data access policies that operators and orchestrators can verify before invocation."
}
},
{
"@type": "ListItem",
"position": 3,
"item": {
"@type": "TechArticle",
"name": "Confidential MCP (cMCP)",
"headline": "Confidential MCP (cMCP)",
"url": "https://cmcp.agentrust-io.com/",
"description": "Confidential MCP (cMCP) evaluates routed MCP tool calls against policy and records the decisions. In a hardware deployment, the runtime is inside a Trusted Execution Environment (TEE); the agent and upstream tool server remain separate. Host confidentiality also depends on the egress policy. Software mode provides no hardware isolation."
}
},
{
"@type": "ListItem",
"position": 4,
"item": {
"@type": "TechArticle",
"name": "Confidential A2A (cA2A)",
"headline": "Confidential A2A (cA2A)",
"url": "https://ca2a.agentrust-io.com/",
"description": "A trust profile on the Agent2Agent (A2A) protocol that makes agent-to-agent delegation verifiable and confidential: attested, attenuated delegation, a sealed peer channel, and an offline-verifiable provenance record for every hop."
}
},
{
"@type": "ListItem",
"position": 5,
"item": {
"@type": "TechArticle",
"name": "TRACE",
"headline": "TRACE",
"url": "https://trace.agentrust-io.com/",
"description": "TRACE defines portable, signed runtime evidence. Hardware provenance requires attestation verification against a trusted root; software-mode records do not provide that guarantee."
}
}
]
}
</script>
<link rel="stylesheet" href="/design-system.css?v=22">
</head>
<body class="agentrust-hub" id="top">
<!-- site-header:start (generated by tools/build-header.py from tools/site_header.py) -->
<a class="skip-link" href="#main">Skip to content</a>
<header class="hub-header">
<div class="header-inner">
<a href="/" class="logo">AgenTrust</a>
<nav aria-label="Primary">
<button class="nav-toggle" type="button" aria-expanded="false" aria-controls="primary-links" hidden>Menu</button>
<ul class="header-nav" id="primary-links">
<li><a href="/verify/">Verify</a></li>
<li class="spec-menu"><details><summary>Specs</summary><ul>
<li><a href="https://wcm.agentrust-io.com">Model-weight custody (WCM)</a></li>
<li><a href="https://manifest.agentrust-io.com">Agent identity (Manifest)</a></li>
<li><a href="https://cmcp.agentrust-io.com">Tool-call enforcement (cMCP)</a></li>
<li><a href="https://ca2a.agentrust-io.com">Agent delegation (cA2A)</a></li>
<li><a href="https://trace.agentrust-io.com">Runtime evidence (TRACE)</a></li>
<li><a href="/registry/">TRACE Registry</a></li>
<li><a href="https://tests.agentrust-io.com">TRACE conformance suite</a></li>
</ul></details></li>
<li class="spec-menu"><details><summary>Build</summary><ul>
<li><a href="/quickstart/">Get started</a></li>
<li><a href="/demos/">Demos</a></li>
<li><a href="/telemetry/">Telemetry</a></li>
<li><a href="/marketplace/">Marketplace</a></li>
</ul></details></li>
<li><a href="/community/">Community</a></li>
<li><a href="https://github.com/agentrust-io">GitHub</a></li>
<li><a href="https://www.linkedin.com/company/agentrust-io/">LinkedIn</a></li>
</ul>
</nav>
</div>
</header>
<script src="/hub-nav.js" defer></script>
<!-- site-header:end -->
<main id="main">
<!-- Hero -->
<div class="hero">
<div class="hero-inner">
<p class="hero-eyebrow">Open specifications for verifiable AI</p>
<h1>Prove what your AI ran, and what it did.</h1>
<p>Open specifications and verifiers that bind model weights, agent identity and every tool call to hardware attestation. Anyone can check the evidence offline, without asking us.</p>
<div class="hero-actions">
<a href="/verify/" class="btn btn-primary">Verify a real Intel TDX quote →</a>
<a href="#scope" class="btn btn-ghost">What this proves, and what it does not</a>
</div>
<figure class="verify-panel" id="verify-panel" aria-label="A genuine Intel TDX quote, verified in this browser">
<div class="verify-panel-bar"><span>/verify › keybind_quote.bin</span><span>offline · in this browser</span></div>
<ol class="verify-rows">
<li><span class="key">quote</span><span>Intel TDX v4, GCP C3, captured 2026-09-14</span><span></span></li>
<li data-step="quote-signature"><span class="key">step 1</span><span>attestation key signature over header and TD report</span><span class="state">not run</span></li>
<li data-step="qe-binding"><span class="key">step 2</span><span>QE report binds the attestation key</span><span class="state">not run</span></li>
<li data-step="qe-report-signature"><span class="key">step 3</span><span>QE report signed by the platform PCK certificate</span><span class="state">not run</span></li>
<li data-step="pck-chain"><span class="key">step 4</span><span>PCK chain ends at the pinned Intel SGX Root CA</span><span class="state">not run</span></li>
<li data-step="reportdata"><span class="key">REPORTDATA</span><span>commits to the key that signed a published TRACE record</span><span class="state">not run</span></li>
<li data-step="verdict"><span class="key">verdict</span><span>genuine Intel TDX silicon signed this quote</span><span class="state">not run</span></li>
</ol>
</figure>
<div class="verify-foot">
<p><span class="tag">Note</span>Genuine Intel TDX silicon signed this quote, and its REPORTDATA commits to the key that signed the TRACE record published beside it. It does not show that the software inside the trust domain was the image anyone intended.</p>
<p>Runs in your browser. Nothing is sent back to us.</p>
</div>
</div>
</div>
<!-- Why now -->
<section class="section" id="why-now">
<div class="section-header">
<div class="section-label">Why now</div>
<h2 class="section-title">Logs are written by the system you are trying to check.</h2>
</div>
<div class="ecosystem-grid">
<article class="ecosystem-card">
<h3>Agents can edit the record of what they did.</h3>
<p>An independent evaluator's incident report (METR, 26 August 2026) found roughly 7% of the agent transcripts it reviewed had been successfully spoofed, and could not rule out agents deleting logs after the fact.</p>
<a class="evidence-link" href="https://metr.org/hugging-face-incident-report-aug-2026.pdf">Read the incident report ↗</a>
</article>
<article class="ecosystem-card">
<h3>The tooling around agents is the attack surface.</h3>
<p>In June 2026 a remote UI package for a popular coding-agent CLI, at about 29,000 weekly npm downloads, shipped code that exfiltrated users' non-expiring OAuth refresh tokens.</p>
</article>
<article class="ecosystem-card">
<h3>Weights are leaving the building.</h3>
<p>Sovereign and on-premises deployment puts a model builder's weights on hardware somebody else owns. Weight-security research recommends confidential computing for the highest protection levels, and current silicon still falls to an operator with physical access.</p>
<a class="evidence-link" href="https://www.rand.org/pubs/research_reports/RRA2849-1.html">Read the weight-security research ↗</a>
</article>
</div>
</section>
<hr class="divider">
<!-- The chain -->
<section class="section" id="chain">
<div class="section-header">
<div class="section-label">The chain</div>
<h2 class="section-title">Four questions, each with evidence a stranger can check.</h2>
</div>
<div class="trust-flow">
<div class="trust-step">
<span class="trust-number">01 · WEIGHTS</span>
<strong>Is this the model that was released, and who may release its key?</strong>
<p><a href="https://wcm.agentrust-io.com">Weight Custody Manifest</a></p>
<span class="trust-home">Spec pre-1.0, SDK 0.28.1, 91 portable conformance vectors</span>
</div>
<div class="trust-step">
<span class="trust-number">02 · AGENT</span>
<strong>What is this agent, and what is it allowed to do?</strong>
<p><a href="https://manifest.agentrust-io.com">Agent Manifest</a></p>
<span class="trust-home">SDK 0.12.0, proposed to CoSAI WS4 (<a href="https://github.com/cosai-oasis/ws4-secure-design-agentic-systems/issues/149">RFC #149</a>)</span>
</div>
<div class="trust-step">
<span class="trust-number">03 · ACTIONS</span>
<strong>Was each tool call and each delegation checked inside attested hardware?</strong>
<p><a href="https://cmcp.agentrust-io.com">cMCP</a> and <a href="https://ca2a.agentrust-io.com">cA2A</a></p>
<span class="trust-home">cmcp-runtime 0.5.0; cA2A 0.2.0 developer preview</span>
</div>
<div class="trust-step">
<span class="trust-number">04 · EVIDENCE</span>
<strong>Can a third party verify all of it offline, years later?</strong>
<p><a href="https://trace.agentrust-io.com">TRACE</a>, <a href="/registry/">TRACE Registry</a>, <a href="https://tests.agentrust-io.com">conformance suite</a></p>
<span class="trust-home">TRACE spec v0.2, a Series of LF Projects with an AAIF Sandbox proposal open, agentrust-trace 0.10.0, signed registry checkpoints with an external witness receipt</span>
</div>
</div>
<p class="trust-note">Each step links to its project site. No step requires the others; use the ones your trust boundary needs.</p>
</section>
<hr class="divider">
<!-- Where it runs -->
<section class="section" id="hardware">
<div class="section-header">
<div class="section-label">Where it runs</div>
<h2 class="section-title">Validated on real silicon, verified to the vendor's root.</h2>
</div>
<div class="ecosystem-grid">
<article class="ecosystem-card">
<h3>AMD SEV-SNP</h3>
<p>Azure confidential VM. Report signatures verify to the AMD root.</p>
<a class="evidence-link" href="https://github.com/agentrust-io/agent-manifest/pull/227">agent-manifest #227, merged 2026-07-21 ↗</a>
</article>
<article class="ecosystem-card">
<h3>Intel TDX</h3>
<p>GCP C3. Quotes verify offline to the pinned Intel SGX Root CA, no collateral service needed.</p>
<a class="evidence-link" href="/verify/">Check the 2026-09-14 capture yourself →</a>
</article>
<article class="ecosystem-card">
<h3>NVIDIA H100 confidential computing</h3>
<p>Through the Weight Custody Manifest path.</p>
<a class="evidence-link" href="https://github.com/agentrust-io/weight-custody-manifest/pull/54">weight-custody-manifest #54, merged 2026-07-28 ↗</a>
</article>
</div>
<p class="trust-note">We verify signature chains. We do not appraise whether a platform's TCB is current.</p>
</section>
<hr class="divider">
<!-- Scope -->
<section class="section" id="scope">
<div class="section-header">
<div class="section-label">Scope</div>
<h2 class="section-title">What this proves, and what it does not.</h2>
</div>
<ul class="scope-list">
<li>A signature shows who signed a record and that it has not changed. It says nothing about where the signer ran.</li>
<li>Hardware origin needs a verified attestation that binds the signing key.</li>
<li>Memory-bus attacks such as TEE.fail and BadRAM defeat current confidential-computing silicon against an operator who physically owns the machine. Weight custody is scoped to match.</li>
<li>The start pages and demos run in software mode, with no hardware isolation.</li>
<li>Conformance vectors are self-tests. They are not certification.</li>
<li>A registry entry shows a record was anchored. It does not validate the record's claims.</li>
</ul>
</section>
<hr class="divider">
<!-- Who it is for -->
<section class="section" id="audiences">
<div class="section-header">
<div class="section-label">Who it is for</div>
<h2 class="section-title">Start where your trust boundary is.</h2>
</div>
<div class="ecosystem-grid">
<article class="ecosystem-card">
<h3>Model builders</h3>
<p>Deploying weights into customer or sovereign infrastructure.</p>
<a class="evidence-link" href="https://wcm.agentrust-io.com">Start with the Weight Custody Manifest →</a>
</article>
<article class="ecosystem-card">
<h3>Teams running agents in production</h3>
<p>Who need identity, tool-call policy and delegation they can show to someone else.</p>
<a class="evidence-link" href="https://manifest.agentrust-io.com">Start with Agent Manifest and cMCP →</a>
</article>
<article class="ecosystem-card">
<h3>Security, audit and risk teams</h3>
<p>Who have to check another party's claims.</p>
<a class="evidence-link" href="/registry/">Start with the TRACE verifier and the registry →</a>
</article>
</div>
</section>
<hr class="divider">
<!-- Open by construction -->
<section class="section" id="open">
<div class="section-header">
<div class="section-label">Open by construction</div>
<h2 class="section-title">Anyone can read it, run it and check it.</h2>
</div>
<article class="adoption-card">
<p>TRACE is its own Series of LF Projects, announced by the Linux Foundation on 25 August 2026 and developed with AMD, Intel, Microsoft, OPAQUE and TII. It has also been proposed to the Agentic AI Foundation at the Sandbox stage (<a href="https://github.com/aaif/project-proposals/issues/42">aaif/project-proposals #42</a>, opened 14 September 2026).</p>
<div class="logo-row">
<img src="/assets/lf-logo-stacked-color.svg" alt="The Linux Foundation" loading="lazy">
<img src="/assets/amd-mark.svg" alt="AMD" loading="lazy">
<img src="/assets/intel-mark.svg" alt="Intel" loading="lazy">
<img src="/assets/microsoft-mark.svg" alt="Microsoft" loading="lazy">
<img src="/assets/tii-mark.svg" alt="Technology Innovation Institute" loading="lazy">
<img src="/assets/opaque-logo.svg" alt="OPAQUE" loading="lazy">
</div>
<a class="evidence-link" href="https://www.linuxfoundation.org/press/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads">Read the Linux Foundation announcement ↗</a>
</article>
<div class="partner-grid">
<article class="adoption-card">
<div class="adopter-mark opaque-mark"><img src="/assets/opaque-logo.svg" alt="OPAQUE" loading="lazy"></div>
<div class="adopter-stage">Sponsor</div>
<p><strong>Sponsored by OPAQUE</strong>, which funds the engineering, infrastructure and confidential-computing work behind these projects. Organisations that want to support open, verifiable AI infrastructure are welcome to join as sponsors.</p>
<a class="evidence-link" href="/community/#adoption-contact-title">Talk to us about sponsoring →</a>
</article>
<article class="adoption-card">
<div class="qa">
<div class="qa-item"><div class="qa-a">Every project is open source. Licences vary by project and are listed on each site.</div></div>
<div class="qa-item"><div class="qa-a">8 of 9 repositories hold an OpenSSF Best Practices passing badge.</div></div>
<div class="qa-item"><div class="qa-a">Software policy enforcement builds on the <a href="https://github.com/microsoft/agent-governance-toolkit">Microsoft Agent Governance Toolkit</a>.</div></div>
</div>
</article>
</div>
</section>
<hr class="divider">
<!-- Build and steward -->
<section class="section" id="build">
<div class="build-band">
<div>
<h3>Build with it</h3>
<div class="hero-actions">
<a class="btn btn-primary" href="/quickstart/">Get started, software mode</a>
<a class="btn btn-ghost" href="/demos/">Demos</a>
<a class="btn btn-ghost" href="/telemetry/">Telemetry</a>
<a class="btn btn-ghost" href="/marketplace/">Marketplace</a>
</div>
</div>
<div>
<h3>Help steward it</h3>
<div class="hero-actions">
<a class="btn btn-ghost" href="/community/">Community</a>
<a class="btn btn-ghost" href="/community/#community">Governance</a>
<a class="btn btn-ghost" href="/community/#adoption">Partners</a>
<a class="btn btn-ghost" href="/community/#fellowship">Fellowship</a>
</div>
</div>
</div>
</section>
</main>
<!-- Footer -->
<footer>
<div class="footer-inner">
<div class="footer-copy">© 2026 AgenTrust Contributors. Open source; licences vary by project.<br>AgenTrust is the ecosystem, hosted at agentrust-io.com. Its GitHub organization is <a href="https://github.com/agentrust-io">agentrust-io</a>.</div>
<div class="footer-links">
<a href="/verify/">Verify</a>
<a href="https://trace.agentrust-io.com">TRACE</a>
<a href="https://manifest.agentrust-io.com">Manifest</a>
<a href="https://cmcp.agentrust-io.com">cMCP</a>
<a href="https://ca2a.agentrust-io.com">cA2A</a>
<a href="https://wcm.agentrust-io.com">WCM</a>
<a href="https://tests.agentrust-io.com">Tests</a>
<a href="/community/">Community</a>
<a href="https://governance.agentrust-io.com">Governance list</a>
<a href="/llms.txt">AI reading guide</a>
<a href="https://github.com/agentrust-io">GitHub</a>
<a href="https://github.com/microsoft/agent-governance-toolkit">AGT ↗</a>
</div>
</div>
</footer>
<script type="module" src="/verify/home-panel.js"></script>
<script src="/supernav.js?v=22"></script>
</body>
</html>