Why Zetna™

Least authority × cert-bound agents and machines × verification

= superintelligence that's safe to scale

Models will be moving faster than we can monitor them, so they have to be governed. Miss any one of these three and the whole thing is zero.

Tokens, and keys tied to a person

Today an agent proves who it is with a token: a string that works like a password. Whoever holds the string is the agent. It leaks from config files and logs, and a poisoned prompt can make the agent read it out.

Everything that acts, people, agents and machines, holds a key it can't give away.

With Zetna, each agent's key is created in hardware (a TPM chip or the Secure Enclave) and can't be copied off the machine; it signs every request. Each signature is fresh, so a copied request or log gives an attacker nothing to reuse, and a replay is refused. The key is tied to a named person, and revoking that person stops their agents.

It's the BeyondCorp idea, which moved staff from shared secrets to keys on their own managed devices, applied to agents.

Agents get their credentials from their person's, so a service accepts an agent because its request is signed by a key that traces back to a named person. There's no API key to paste into a config, leak or rotate. One revoke cuts off the person and every agent they issued, everywhere the credential is accepted. Every service that accepts it makes it worth more to the next. One Credential

Agent identity products already register agents, tie each one to a human owner and approve each tool call, and that's real work. Where we differ is the credential: a key held in hardware signs every request, where a bearer token can be copied. The evidence is a receipt anyone can check without the vendor, and it's one credential across services and organisations.

Token

config file, log api_key=sk-… copied attacker your systems call accepted who answers for it? nobody in particular

Cert-bound

a named person agent's device key in hardware signed Zetna checks accepted once copied request refused: replay revoke the person: their agents stop
A token works for whoever holds it. A cert-bound agent signs each request with its own key, a copied request is refused, and a named person answers for every agent.

What changes

A neutral place to check

Operators can witness each other's logs, so nobody has to take one vendor's word for its own record.

Every Zetna install is witnessed automatically through Veriplex, the open verification federation. If you run a network, audit, build agents or compete with us, run a witness: write to hello@veriplex.org.