How it works
From a request to a receipt anyone can check
Zetna™ sits under your agents and models, on your servers. It decides who may act, holds what matters for its person, and leaves evidence behind.
- credential
- limits
- held for its person
- happens once
- receipt, checked offline
- stop
-
A key tied to a person, not a bearer token
A bearer token is a string: whoever holds a copy is the agent, from anywhere, for as long as it lives. In Zetna each agent has its own credential. Each agent's key is created in hardware (a TPM chip or the Secure Enclave) and can't be copied off the machine; it signs every request. The credential chains to the person or organisation it acts for.
An agent joins only by invitation, and a key can be enrolled only once, under one name.
Tokens, and keys tied to a person
It is the idea large companies applied to their own staff years ago, applied to agents: trust comes from a key tied to a person, never from where a request comes from.
-
Limits before anything runs
Each credential carries what it may do and where it may send data. If no rule allows a request, nothing happens, and a request is refused rather than widened.
Everything the rail sends out passes through one exit, which refuses unless a policy allows it. It decides on the literal address and never looks a name up.
-
Held for its person
If a request would do something that matters, it is held until a named person approves it. The person sees the amount, the payee and the limit it exceeds, and approves with a FIDO2 security key, or with Touch ID on the Mac the server runs on.
-
It happens once
Then it happens exactly once. A replay, a second fire or a stranger's approval is refused, and a denied or expired hold never fires.
-
A receipt, checked without us
What comes out is a signed receipt that contains no prompt and no response, only references and commitments. Your auditor checks it on their own laptop, with our servers switched off, in either of two separate verifiers.
Operators can witness each other's logs: a witness co-signs the log's checkpoints, so a history rewritten later no longer matches what it saw.
Every Zetna install is witnessed automatically through Veriplex, the open verification federation, and any operator can witness for the others with one switch. If anyone's history ever forks, every install sees it. Zetna runs it as custodian, and it's built to be handed to a foundation, so no single company runs it, including us. veriplex.org
-
Stop anyone
When an officer stops an agent, its next request at any door that acts is refused by name, and the refusal is receipted. Revoking ends a credential for good, and the emergency switch halts every agent at once.
The layer beside ours
Other tools protect the models and the traffic: they validate models, screen prompts and see which applications talk to which models. We don't do that.
We start where a model's output becomes an action: who acted, under which credential and with whose approval, in a receipt anyone can check. The two layers fit together.