Let agents act.Keep trust in control.
AgentTrust sits directly in the execution path. Every agent action is validated, scored for confidence and business risk, and given a governance decision — before it reaches your users, tools, systems or data.
All deterministic checks passed. Confidence above threshold at low risk.
Built for the agent stack you already use
Framework adapters, a zero-code auto-instrumenter, and a plain HTTP endpoint for everything else.
Agents don’t behave like software.
Your trust layer shouldn’t either.
As enterprises deploy agents across frameworks, a category of risk appears that application security and output monitoring were never built to address.
Traditional applications execute deterministic code. Agentic systems make decisions independently.
Traditional software behaves the same every time. Agentic systems adapt based on context and evolving inputs.
Traditional apps operate within fixed boundaries. Agentic systems call tools and external systems to act.
Traditional software follows predefined flows. Agentic systems generate plans before taking action.
Monitoring output alone is no longer enough. Risk lives in reasoning, tool calls, and execution paths.
AI agents act.
AgentTrust decides what gets through.
Every execution passes through deterministic validation before it reaches your users, tools, systems or data. Four real shapes of that decision.
action="process_refund"
params={"amount": 1250, "order": "48213", "currency": "USD"}Four engines.
One decision.
A single POST to /v1/runtime/validate runs the whole chain, persists an append-only audit record, and answers before your agent's output is released.
Output structure validation against the declared contract.
Tool call and result verification against the declared-tool manifest.
Policy pack rules in YAML — financial, HIPAA, GDPR, PCI, SOC2, SOX, PII.
Output consistency with an optional contradiction detector.
YAML-defined regression rules pinned to an agent id pattern.
Evidence and grounding checks against retrieved sources.
Hard gate — a failure caps the policy score outright.
Every run writes an append-only audit record with content hashes, whatever the outcome — a blocked action is evidence too.
One hop, and the failure modes change
Monitoring tells you what an agent did. A gate in the execution path decides whether it gets to do it at all.
ValidationEngine target, with zero LLM calls on the critical path.
Schema, tool trust, policy, consistency, evidence, judge, historical reliability.
low · medium · high · critical, from four scored factors.
approve · retry · request_evidence · escalate · block · pending.
Add trust with one integration
A decorator for new agents, an auto-instrumenter for code you would rather not touch, and a plain HTTP endpoint for everything else. Promotion from laptop to production changes environment variables, not application code.
from agentrust_sdk import harness, BlockedError
@harness(agent_id="refund-agent", action="process_refund")
def refund_agent(user: str, input: str) -> dict:
# Pre-check runs before this body. A block here means
# the refund is never issued.
return {"status": "refunded", "amount": 1250, "order": "48213"}
try:
refund_agent(user="alice", input="Refund order #48213")
except BlockedError as e:
print(e.outcome, e.reason, e.envelope_id)Every score is on a 0–100 scale and confidence lives inside validation. The response also carries a governance disclosure string and a confidence rationale you can surface to end users.
agentrust-py; the import name is agentrust_sdk. A TypeScript client and wrap() helper ship in the repository.Five steps from install to enforcement
Integrate with your agent framework or orchestration layer in minutes.
Run pre-production security, reliability, and compliance certification.
Deploy runtime validation, confidence scoring, and decision governance.
Capture explainability, evidence trails, and compliance reporting.
Block, escalate, or approve — before critical business actions execute.
Certify. Govern. Audit.
End-to-end trust for the full agent lifecycle — from pre-production certification, through runtime governance, to enterprise audit.
Trust Certify
Independent certification of AI agents through security, reliability, compliance, and guardrail testing before they reach production.
- Agent discovery across LangGraph, CrewAI, OpenAI, Claude, MCP
- Attack engine: prompt injection, jailbreak, tool abuse testing
- Reliability engine: thousands of runs for consistency scoring
- Compliance packs: HIPAA, GDPR, PCI, SOC2, SOX
Illustrative scorecard shape. Real scores come from your own golden test suites and policy packs.
Trust Certify engine
Six specialised engines produce Security, Reliability, Compliance, Accuracy and Guardrail scores, with a final certification rating an agent carries into production.
Agent Discovery
LangGraph, CrewAI, OpenAI, Claude, MCP, Python & Node.js
Attack Engine
Prompt injection, jailbreak, tool abuse, memory poisoning
Reliability Engine
Thousands of repeated runs measuring consistency
Reasoning Engine
Chain-of-thought, tool patterns, loops, hallucination risks
Compliance Engine
HIPAA, GDPR, PCI, SOC2, SOX, enterprise policies
Certification Score
Security, Reliability, Compliance, Accuracy, Guardrails
Every certified agent makes the next one safer
Each execution contributes to a growing graph of which models, tools, workflows and agent patterns fail — and how. Over time that turns into predictive risk scoring before an agent is ever deployed.
Per-agent identity on every envelope — agent_id drives policy routing.
Historical reliability per agent, cached and scored on each run.
PII detection, 24-hour masking, and erasure on request.
Policy packs scoped per domain: financial, HIPAA, PCI, SOX.
Kill switch, alert engine, and the human review queue.
parent_envelope_id links multi-agent chains into one trust chain.
Start by observing.
Enforce when you’re ready.
The same application code runs at every stage. Promotion is an environment-variable change, so nothing about your agent has to be rewritten to tighten the gate.
Observe
Run the full pipeline with enforcement switched off. Every execution is scored and written to the ledger; nothing is stopped. Use it to see your real block rate before it can hurt you.
@harness(block_on_block=False) embed_gateway() # SQLite, no API key
Tune
Point staging at a real gateway and fail closed, so a wrong URL or a missing key surfaces as an exception instead of looking like a healthy system. Adjust policy packs and golden tests against live traffic shapes.
AGENTRUST_GATEWAY_URL=https://staging.internal:8000 AGENTRUST_FAILURE_MODE=closed @harness(raise_on_error=True)
Enforce
Turn enforcement on in production. Blocks raise, escalations route to the review queue, and you choose whether a governance outage should stop agents or let them through.
AGENTRUST_GATEWAY_URL=https://agentrust.internal:8000 AGENTRUST_FAILURE_MODE=open # or queue, for air-gap @harness(block_on_review=True) # high-stakes domains
AGENTRUST_ENABLED=false turns every governance path into a no-op without a code change, and AGENTRUST_KILL_SWITCH=1 hard-blocks every agent ahead of any scoring. Both are read from the environment, so a restart is the whole procedure.agentrust queue replay — built for intermittent connectivity and air-gapped sites.Every decision leaves evidence
A blocked action produces exactly as much evidence as an approved one. The ledger is append-only with content hashes, and Enterprise adds hash-chain integrity verification you can run on demand.
- Historical reliability
Redis cache, then the audit store, for this agent_id.
- ValidationEngine
Deterministic checks on the fast path — no LLM calls.
- ConfidenceEngine
Seven weighted signals converge into final_confidence.
- RiskEngine
Four factors produce a score and a tier.
- Trust chain
Multi-agent provenance via parent_envelope_id (Enterprise).
- DecisionEngine
Scores map to one of six governance outcomes.
- Audit persist
Append-only ledger entry with content hashes.
- Review queue
escalate and request_evidence route to human operators.
- LLM judge
Async enrichment on the slow path (Enterprise).
DELETE /v1/audit/executions/{id}/pii.The controls a risk committee asks for
Each of these is a shipped capability with an endpoint, an environment variable or a config file behind it — not a roadmap item.
Policy enforcement
Policy packs as versioned YAML: base, financial, hipaa, gdpr, pci_dss, soc2, sox, pii_controls, medical.
Developer+Append-only audit ledger
Every execution persisted with content hashes. Hash-chain verification via GET /v1/audit/chain/verify.
Team+Human review queue
escalate and request_evidence decisions route to operators with assignment and deadlines.
Team+Kill switch
AGENTRUST_ENABLED=false disables governance paths; AGENTRUST_KILL_SWITCH=1 hard-blocks every agent.
OSS+Self-hosted deployment
Docker Compose or Kubernetes in your own network. Postgres with pgvector, Redis, gateway, dashboard.
EnterpriseSAML SSO
Enterprise single sign-on through /v1/sso/*, with JWT sessions for the operator dashboard.
EnterprisePII detection & erasure
SSN, email, API keys and passwords detected by the policy engine; masked within 24 hours, erasable on request.
Developer+Compliance reporting
Regulator evidence packs and SOC 2 export from /v1/reports, aligned to ISO/IEC 42001 control areas.
EnterpriseEncryption & signing
AES-256-GCM on audit payloads at rest, Ed25519-signed audit packages, AES-256 on the archive store.
Team+Multi-agent trust chain
parent_envelope_id links sub-agent runs into one provenance chain that can block on violation.
EnterpriseFailure modes
open, closed or queue. Choose whether a governance outage stops agents, lets them run, or buffers for replay.
OSS+Telemetry & alerts
Prometheus metrics, OpenTelemetry traces from both SDK and gateway, plus the alert engine on /v1/alerts.
Team+Your data never leaves your network
AgentTrust is a tenant-owned runtime. Start embedded in the process, promote to a self-hosted edge gateway, and keep prompts, agent payloads and governance decisions inside your own perimeter.
OSS
SDK only · no API key
Agent
└── agentrust_sdk
└── in-process
schema validation- Local schema-only validation, no HTTP call
- Apache-2.0 core, pip install agentrust-py
- Useful for wiring the contract before you run a gateway
Embedded
In-process gateway on :8765
Agent
└── embed_gateway()
└── SQLite gateway :8765
└── full deterministic pipeline- Pre-check, post-check and the human-in-the-loop API
- Zero external services — good for dev, CI, demos and air-gap
- No LLM judge, trust chain or historical reliability
Full Edge
Self-hosted gateway in your network
Agents
└── AgentTrust Edge Gateway :8000
├── PostgreSQL + pgvector
├── Redis (jobs, cache, limits)
└── Operator dashboard- Every engine, the review queue, analytics and the async judge
- Docker Compose or Kubernetes, multi-replica gateway
- Prompts, agent data and decisions never leave your network
Trust across your entire agent stack
Adapters where a framework offers a hook, an auto-instrumenter where it does not, and a plain envelope over HTTP for anything bespoke. Hover a framework to trace it into the gateway.
The enterprise standard for agent trust
“No AI agent should enter production without AgentTrust certification and runtime governance.”
Built for teams deploying
Certify your agents. Govern every action. Prove all of it.
Independent certification before deployment, deterministic governance in the execution path, and an audit trail your risk committee can read. Start embedded on a laptop, or talk to us about a self-hosted rollout.