The governed layer for machine intelligence

Everything that acts, bound to a person.

Agents, models, robots and devices act on their own. Keep the ones you already use. Zetna™ holds anything that matters until the right person approves it, lets it happen once, and leaves a receipt your auditor can check without us, on your own servers.

The Zetna mark in its held state: a hollow ring waits in the open gate.
Held: the action waits in the gate until its person approves it.
  1. An agent asks to pay an invoice.
  2. Held: it waits for its person.
  3. The person approves it.
  4. It happens once.
  5. A receipt anyone can check without us.

One thing, done properly

When an agent, a model or a device tries to do something that matters, such as paying an invoice, signing off work or taking a block of compute, Zetna holds it.

  1. It waits for the right person

    Nothing happens until that person approves. If approval is withheld, nothing happens at all.

    Held

    It waits in the gate, and nothing has happened yet.

  2. The person approves on their own device

    The approval is a signature from the approver's own device over that exact action, and the approver is a different identity from the one asking.

    That device is a FIDO2 security key, or Touch ID on the Mac the server runs on. A synced passkey is refused.

    Signed on the approver's device

    A different identity from the one asking.

  3. It happens once

    Then it happens exactly once, and a replay is refused.

    Verified

    Out through the gate, once.

    Replay: refused

  4. It leaves a receipt

    The receipt is signed and holds no prompt and no response, only references and commitments. Your auditor checks it on their own laptop, with our servers switched off.

    Receipt

    Signed

    id
    [receipt ID]
    action
    [action reference]
    decision
    [decision]
    approver
    [approver commitment]
    content
    none · commitments only

Two reasons to use it

Why this, why now

AI agents now act on their own: they pay invoices, sign off on work and request compute. Most governance, risk and compliance controls were built for people and applications, and with agents they leave three gaps.

Other tools watch, screen or record. Zetna holds the action itself until the right person approves it, and leaves evidence anyone can check. Why Zetna

Nine principles

Each one is a rule we build to.

Accountable

  1. Bound to a person

    Every agent, model, robot and device carries a credential that traces to a real person.

  2. The approval means something

    Anything that matters waits for a named person, happens once, and cannot be replayed.

  3. Stop anyone, act as no one

    An organisation can stop any person, agent or server at once, and can never act as one of them.

Secure

  1. Closed by default

    If no rule allows it, nothing happens; nothing leaves unless it is declared; a request is refused rather than widened.

  2. Every lever is bounded

    Who can stop, revoke or recover whom is a fixed table, and every use of it is scoped, time-limited, receipted and visible.

  3. Detect, halt, report

    A machine that fails verification halts, reports, and resumes only when it attests again.

Yours

  1. Proven, not claimed

    Every act that matters leaves a signed receipt with no content in it, and anyone can check it without us.

  2. Never a middleman

    An instance you run is complete, and your customers' content never reaches us as a condition of using it.

  3. Yours to take, free to leave

    Receipts keep verifying if every server is gone, and leaving is a real act that leaves you with evidence.

What Zetna runs today

Delete your agents' API keys.

Pilots

Each product starts as a four-week pilot on a server you already run, with your own people approving, and nothing leaves your environment.