The governed layer for machine intelligence
Everything that acts, bound to a person.
Agents, models, robots and devices act on their own. Keep the ones you already use. Zetna™ holds anything that matters until the right person approves it, lets it happen once, and leaves a receipt your auditor can check without us, on your own servers.
- An agent asks to pay an invoice.
- Held: it waits for its person.
- The person approves it.
- It happens once.
- A receipt anyone can check without us.
One thing, done properly
When an agent, a model or a device tries to do something that matters, such as paying an invoice, signing off work or taking a block of compute, Zetna holds it.
-
It waits for the right person
Nothing happens until that person approves. If approval is withheld, nothing happens at all.
Held
It waits in the gate, and nothing has happened yet.
-
The person approves on their own device
The approval is a signature from the approver's own device over that exact action, and the approver is a different identity from the one asking.
That device is a FIDO2 security key, or Touch ID on the Mac the server runs on. A synced passkey is refused.
Signed on the approver's device
A different identity from the one asking.
-
It happens once
Then it happens exactly once, and a replay is refused.
Verified
Out through the gate, once.
Replay: refused
-
It leaves a receipt
The receipt is signed and holds no prompt and no response, only references and commitments. Your auditor checks it on their own laptop, with our servers switched off.
Receipt
Signed
- id
- [receipt ID]
- action
- [action reference]
- decision
- [decision]
- approver
- [approver commitment]
- content
- none · commitments only
Two reasons to use it
-
Proof, not logs
A log asks you to trust whoever kept it. A receipt is a signed document that your auditor, your regulator or your customer can check offline, with every server of ours switched off.
Each receipt also sits in an append-only log with signed checkpoints and proofs of inclusion, and those verify offline too.
-
On your own infrastructure
Zetna runs on your servers, beside the model you choose.
An instance you run is complete: it serves, governs, receipts and verifies without calling us. Nothing leaves unless you have declared where it may go, and if you leave us, your receipts still verify.
Why this, why now
AI agents now act on their own: they pay invoices, sign off on work and request compute. Most governance, risk and compliance controls were built for people and applications, and with agents they leave three gaps.
- Logs that no outside party can verify.
- Policies that nothing enforces at the moment of action.
- Compliance that is asserted rather than proven.
Other tools watch, screen or record. Zetna holds the action itself until the right person approves it, and leaves evidence anyone can check. Why Zetna
Nine principles
Each one is a rule we build to.
Accountable
Bound to a person
Every agent, model, robot and device carries a credential that traces to a real person.
The approval means something
Anything that matters waits for a named person, happens once, and cannot be replayed.
Stop anyone, act as no one
An organisation can stop any person, agent or server at once, and can never act as one of them.
Secure
Closed by default
If no rule allows it, nothing happens; nothing leaves unless it is declared; a request is refused rather than widened.
Every lever is bounded
Who can stop, revoke or recover whom is a fixed table, and every use of it is scoped, time-limited, receipted and visible.
Detect, halt, report
A machine that fails verification halts, reports, and resumes only when it attests again.
Yours
Proven, not claimed
Every act that matters leaves a signed receipt with no content in it, and anyone can check it without us.
Never a middleman
An instance you run is complete, and your customers' content never reaches us as a condition of using it.
Yours to take, free to leave
Receipts keep verifying if every server is gone, and leaving is a real act that leaves you with evidence.
What Zetna runs today
One Credential
Sign-in and approval with one touch on a hardware security key, enrolment by invitation, and revocation at the next request.
The governance control plane
One console to invite people, give every agent to a person, approve or stop, and hand an examiner evidence to check offline.
Governed inference
Open models served from an operator's own server, metered, with a signed receipt for every call.
Pilots
Each product starts as a four-week pilot on a server you already run, with your own people approving, and nothing leaves your environment.