From 6ec22726df2897f7546f4e246d1fe3e4317a8a13 Mon Sep 17 00:00:00 2001 From: Imran Siddique Date: Mon, 14 Sep 2026 08:35:13 -0700 Subject: [PATCH] feat(home): lead with evidence a stranger can check The homepage opened on "Control agent actions. Verify the evidence." with a software-mode quickstart as the first click, which read as one more policy gateway. What AgenTrust actually has that others do not, hardware validation on three platforms, WCM, TRACE at the Linux Foundation and offline verification, sat far down the page or on other hosts. The new homepage names the category as the verifiable AI supply chain: four questions from weights to agent to actions to evidence, the silicon each is validated on with the PR that shows it, and one section on what the evidence proves and what it does not. The hero runs the /verify/ TDX check live on the committed GCP capture. Partner cards, community governance, the NSF submission, playbook plans, the fellowship and the book move to /community/ unchanged, and render-adoption.mjs now writes there. Also: - OPAQUE is named as sponsor, without the ownership disclaimer, on the homepage, /community/ and the registry footer. - The FAQ gave the TRACE specification licence as CC BY 4.0. trace-spec's LICENSE is the Community Specification License 1.0, code Apache 2.0. - "cA2A v0.1 preview" goes with the status strip; the chain cites 0.2.0. - supernav gains Verify, so every subdomain links to the check. - llms.txt anchors follow the move, and the marketplace link to /#standards now points at /#chain. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_013aK3gVWzNdcM3hZ2o2awK2 --- .github/workflows/adoption-data.yml | 4 +- community/index.html | 389 +++++++++++++ data/adoption.json | 4 +- design-system.css | 119 ++++ index.html | 844 ++++++++-------------------- llms.txt | 10 +- marketplace/index.html | 2 +- registry/index.html | 2 +- scripts/render-adoption.mjs | 4 +- sitemap.xml | 1 + supernav.js | 4 +- verify/home-panel.js | 32 ++ 12 files changed, 788 insertions(+), 627 deletions(-) create mode 100644 community/index.html create mode 100644 verify/home-panel.js diff --git a/.github/workflows/adoption-data.yml b/.github/workflows/adoption-data.yml index 2088077..be62203 100644 --- a/.github/workflows/adoption-data.yml +++ b/.github/workflows/adoption-data.yml @@ -5,14 +5,14 @@ on: paths: - data/adoption.json - scripts/render-adoption.mjs - - index.html + - community/index.html - .github/workflows/adoption-data.yml push: branches: [main] paths: - data/adoption.json - scripts/render-adoption.mjs - - index.html + - community/index.html permissions: contents: read diff --git a/community/index.html b/community/index.html new file mode 100644 index 0000000..06848ab --- /dev/null +++ b/community/index.html @@ -0,0 +1,389 @@ + + + + + + Community, Partners and Governance | AgenTrust + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + + + +
+
+
+

Community

+

The people and organisations behind AgenTrust

+

Partner and sponsor relationships linked to public evidence, how the projects are governed, and how to contribute.

+
+
+ +
+
+ +

An ecosystem built around adoption

+
+
+

Use it

Start with runnable demos, reference implementations, schemas, and conformance tests. Move from evaluation to a production pilot without waiting for a proprietary platform.

+

Improve it

Bring implementation feedback, integrations, threat models, deployment evidence, and research. Public repositories and issue trackers make the contribution path visible.

+

Sustain it

Grow maintainers, review contributions, document adoption patterns, and share stewardship across organizations so critical governance infrastructure outlives any one team.

+
+
Adoption pathway: explore a ten-minute demo → test against the open suites → pilot one trust boundary → contribute results and integrations → help govern and maintain the shared infrastructure.
+ +
+ +
+ +
+
+ +

Relationships the public record supports

+
+

Every organization named here has a traceable relationship through a public announcement, open-source repository, or explicit AgenTrust partner statement. The label on each card states that relationship precisely; sponsorship, partnership, contribution, and adoption are distinct relationships, and none implies blanket endorsement of the full stack.

+ +
+
The Linux Foundation
+
Neutral host

TRACE Specification is an LF Project

TRACE is hosted at the Linux Foundation as its own series. Its specification, IP, trademark, and conformance mark sit with the series under the Community Specification License and LF Projects policies, so no single vendor decides what conformance means.

Read the project governance ↗
+
+
+
+
OPAQUE Systems
+
Sponsor
+

OPAQUE funds the engineering, infrastructure and confidential-computing work behind AgenTrust, and contributes to the projects.

+ Review the public project record ↗ +
+
+
Microsoft
+
Open-source project home
+

Microsoft hosts the Agent Governance Toolkit, the open runtime-governance foundation that the AgenTrust trust chain builds on.

+ View the repository ↗ +
+
+
Technology Innovation Institute
+
Confirmed founding partner
+

TII is the confirmed AgenTrust founding partner anchoring the work in sovereign-AI deployment requirements.

+ Read the OPAQUE announcement ↗ +
+
+
AMD
+
Founding member and hardware partner
+

AMD is a founding partner of AgenTrust. AMD and OPAQUE published a joint implementation blueprint for hardware-backed Confidential AI, and the implementation verifies SEV-SNP report signatures to the AMD root.

+ Read the joint white paper ↗ +
+
+
Intel
+
Founding member and hardware partner
+

Intel is a founding partner of AgenTrust. The implementation verifies Intel TDX DCAP v4 quotes to the pinned Intel SGX Root CA, hardware-validated on GCP C3.

+ Review the public implementation record ↗ +
+
+
ServiceNow
+
OPAQUE customer implementation
+

OPAQUE publicly documents how ServiceNow used its Confidential AI Platform to reduce commission-inquiry workflows from days to seconds.

+ View the OPAQUE customer story ↗ +
+
+
CSA Agentic Trust Framework
+
Public framework collaboration
+

ATF's author publicly supports positioning AGT as a reference implementation and invited implementation input into the conformance specification.

+ Read the public collaboration thread ↗ +
+
+
PRONATIVE AI
+
Ecosystem Training & Adoption Partner
+

PRONATIVE AI works with AgenTrust to bring verifiable agent governance into enterprise engineering education and adoption. The partnership includes joint educational programming and the planned integration of cMCP, cA2A, and TRACE into PRONATIVE AI's AI-Native Engineering Foundry curriculum. PRONATIVE AI is also adopting the Microsoft Agent Governance Toolkit within its delivery environment and will publish implementation guidance as that work becomes publicly available.

+ View the featured session ↗ +
+
+
+
+
XRSI: Human Intelligence In The Loop
+
Ecosystem partner

Governance and Ecosystem Sustainability Partner

XRSI brings governance, community-building, and long-term ecosystem sustainability expertise to the AgenTrust adoption programme.

+
+
+
Action State Group
+
Technical collaborator

Trust Registry and Verifiable Record Collaboration

Action State Group is collaborating with AgenTrust on an open contribution path for the TRACE Trust Registry, connecting TRACE runtime evidence with neutral, independently verifiable record and witness infrastructure.

Visit Action State Group ↗
+
+
+
Odystra AI
+
Startup supporter

Odystra AI

Odystra builds an agentic governance, risk, and compliance platform for regulated enterprises.

Visit Odystra ↗
+
+
+
o1Labs
+
Startup supporter

o1Labs

o1Labs develops applications and infrastructure powered by zero-knowledge cryptography.

Visit o1Labs ↗
+
+
+ + +
+ +
+ +
+
+ +

Open work, visible decisions, more maintainers

+
+

AgenTrust develops in public through open repositories, reviewable proposals, implementation evidence, and conformance testing. The goal is not simply to publish specifications: it is to create a contributor community capable of operating, improving, and stewarding the technology.

+
+
Technical stewardship

Imran Siddique

AgenTrust
Architecture, implementation, conformance, and maintainer development.

+
Governance & sustainability

XRSI

Named organizational partner for community governance, ecosystem adoption, and long-term sustainability. Individual committee appointments will be published only after confirmation.

+
Committee formation

Community seats

Adopter, maintainer, research, and public-interest representation will be added as the steering model is formalized.

+
+ + +
+ +
+ +
+
+ +

From runtime evidence to compliance playbooks

+
+

The fellowship will turn AgenTrust implementation patterns into practical, public playbooks. Each playbook will map governance controls and TRACE evidence to an authoritative framework without claiming certification or legal compliance.

+ +
+ +
+ +
+
+ +

AgenTrust Fellowship 2026

+
+

The AgenTrust Fellowship supports emerging maintainers of open infrastructure for verifiable AI systems. Fellows contribute code, tests, integrations, documentation, and adoption guidance across AgenTrust projects, grounded in real issues and verifiable work.

+

Applications closed early on 26 August 2026 due to exceptional volume. More than 150 applications are under review. The fellowship will not start in September as originally planned. The schedule and decision timeline are being reviewed and there is no firm notification date yet. Applicants do not need to send anything further; the submitted proposal is what is assessed. A revised timetable will be published here once it is confirmed, and applicants will be contacted directly.

+ +
+ +
+
+ +

Architecting at Scale

+
+

AgenTrust founder Imran Siddique has turned the lessons behind production cloud and AI systems into a practical book. It connects the architecture of distributed systems with the harder problem now in front of us: building AI-native systems that remain observable, governable, and correct when they meet production.

+ +
+ +
+ +
+
+ +

What is AgenTrust?

+
+

AgenTrust is an open ecosystem for verifiable AI agent governance. It connects reusable technology with the people and practices needed to adopt it: maintainers, implementers, researchers, enterprise operators, conformance testing, integration guidance, and transparent community governance.

+

Agent Manifest declares identity and intended authority. cMCP governs tool calls; cA2A governs delegation to another agent. TRACE carries signed runtime evidence for verification against a trust policy. Hardware provenance depends on verified attestation. Use the components required by your trust boundary. Explore each project's specification, reference implementation, and license through the chain on the homepage.

+

AgenTrust Telemetry is the integration layer across that chain. It gives runtimes a common, metadata-only contract for governance facts, projects those facts into caller-owned OpenTelemetry, and can turn a complete durable evidence set into TRACE. It does not replace a policy engine, collector, observability backend, or dashboard.

+
+ +
+ +
+
+ +

About the project

+
+
+
+
Is AgenTrust a standards-development programme?
+
No. AgenTrust is an open-source ecosystem focused on adoption, implementation, interoperability, maintainer development, and long-term sustainability. Its open specifications are shared technical building blocks; community implementations, test infrastructure, integrations, documentation, and deployment evidence make those building blocks useful in practice.
+
+
+
What is OPAQUE Systems' role in AgenTrust?
+
OPAQUE Systems sponsors AgenTrust, funding the engineering, infrastructure and confidential-computing work behind these projects, and contributes to them. Organisations that want to support open, verifiable AI infrastructure are welcome to join as sponsors.
+
+
+
+ +
+ + + + + + + + + diff --git a/data/adoption.json b/data/adoption.json index 9e5925d..12e97d2 100644 --- a/data/adoption.json +++ b/data/adoption.json @@ -15,8 +15,8 @@ "name": "OPAQUE Systems", "logo": "/assets/opaque-logo.svg", "markClass": "opaque-mark", - "label": "Founding engineering and infrastructure sponsor", - "description": "OPAQUE provides funding, engineering time, infrastructure, and confidential-computing contributions. Sponsorship does not confer ownership of AgenTrust projects or governance authority over their technical decisions.", + "label": "Sponsor", + "description": "OPAQUE funds the engineering, infrastructure and confidential-computing work behind AgenTrust, and contributes to the projects.", "evidenceUrl": "https://github.com/agentrust-io", "evidenceLabel": "Review the public project record" }, diff --git a/design-system.css b/design-system.css index 44dfb6e..258423e 100644 --- a/design-system.css +++ b/design-system.css @@ -2052,3 +2052,122 @@ html:has(body.agentrust-hub) { scroll-behavior: smooth; } .agentrust-hub .hero-actions { gap: .75rem; } .agentrust-hub .hero-actions .btn { text-align: center; white-space: normal; } } + +/* Homepage, verifiable AI supply chain (September 2026) + * + * The hero runs the in-browser TDX verifier (verify/home-panel.js), so the + * panel is a terminal whose states fill in from the live result rather than + * a picture of one. The other blocks are the few layouts the new homepage + * needs that the hub vocabulary above did not already have. + */ +.agentrust-hub .verify-panel { + margin: 3.5rem 0 0; + overflow: hidden; + border-radius: var(--at-radius); + background: var(--at-code-bg); + color: var(--at-code-fg); + box-shadow: var(--at-shadow); +} +.agentrust-hub .verify-panel-bar { + display: flex; + flex-wrap: wrap; + justify-content: space-between; + gap: 0.25rem 1rem; + padding: 0.85rem 1.5rem; + border-bottom: 1px solid rgba(243, 240, 232, 0.12); + color: var(--at-code-dim); + font-family: var(--at-mono); + font-size: 0.8rem; +} +.agentrust-hub .verify-rows { + display: grid; + gap: 0.55rem; + margin: 0; + padding: 1.3rem 1.5rem 1.4rem; + list-style: none; + font-family: var(--at-mono); + font-size: 0.9rem; + line-height: 1.5; +} +.agentrust-hub .verify-rows li { + display: grid; + grid-template-columns: 8rem minmax(0, 1fr) 6rem; + gap: 1rem; +} +.agentrust-hub .verify-rows .key { color: var(--at-code-dim); } +.agentrust-hub .verify-rows .state { color: var(--at-code-dim); text-align: right; } +.agentrust-hub .verify-rows .state.pass { color: var(--at-code-accent); font-weight: 600; } +.agentrust-hub .verify-rows .state.fail { color: var(--at-code-alert); font-weight: 600; } +.agentrust-hub .verify-rows .state.note { color: var(--at-code-string); } +.agentrust-hub .verify-foot { + display: flex; + flex-wrap: wrap; + justify-content: space-between; + gap: 0.75rem 2rem; + margin-top: 1rem; + color: var(--at-muted); +} +.agentrust-hub .verify-foot p { + max-width: 46rem; + margin: 0; + font-size: 0.9rem; + line-height: 1.55; +} +.agentrust-hub .verify-foot .tag { + margin-right: 0.5rem; + color: var(--at-red); + font-size: 0.7rem; + font-weight: 700; + letter-spacing: 0.12em; + text-transform: uppercase; +} +.agentrust-hub .scope-list { + display: grid; + grid-template-columns: repeat(2, minmax(0, 1fr)); + gap: 0 3rem; + margin: 2rem 0 0; + padding: 0; + list-style: none; +} +.agentrust-hub .scope-list li { + padding: 1.1rem 0; + border-top: 1px solid var(--at-line); + color: var(--at-ink); + line-height: 1.6; +} +.agentrust-hub .logo-row { + display: grid; + grid-template-columns: repeat(6, minmax(0, 1fr)); + gap: 1rem; + align-items: center; + margin-top: 1.5rem; +} +.agentrust-hub .logo-row img { + display: block; + max-width: 120px; + max-height: 44px; + margin: auto; +} +.agentrust-hub .build-band { + display: grid; + grid-template-columns: repeat(2, minmax(0, 1fr)); + gap: 1rem; +} +.agentrust-hub .build-band h3 { + margin: 0 0 1rem; + color: var(--at-ink); + font-family: var(--at-serif); + font-size: clamp(1.5rem, 2.4vw, 2.1rem); + font-weight: 500; + letter-spacing: -0.02em; +} +@media (max-width: 700px) { + .agentrust-hub .verify-rows li { grid-template-columns: minmax(0, 1fr) auto; gap: 0 1rem; } + .agentrust-hub .verify-rows .key { grid-column: 1 / -1; } + .agentrust-hub .scope-list, + .agentrust-hub .build-band { grid-template-columns: 1fr; } + .agentrust-hub .logo-row { grid-template-columns: repeat(3, minmax(0, 1fr)); } +} +@media (max-width: 900px) { + .agentrust-hub .ecosystem-grid { grid-template-columns: 1fr; } +} diff --git a/index.html b/index.html index 3eeadf1..fdace7a 100644 --- a/index.html +++ b/index.html @@ -3,8 +3,8 @@ - AgenTrust: An Open Ecosystem for Verifiable AI Agents - + AgenTrust: Open Specifications for Verifiable AI + @@ -17,8 +17,8 @@ - - + + @@ -28,8 +28,8 @@ - - + + @@ -42,12 +42,14 @@ "@id": "https://agentrust-io.com/#organization", "name": "AgenTrust", "url": "https://agentrust-io.com/", - "description": "An open ecosystem where developers, researchers, operators, and enterprises build, test, adopt, and sustain verifiable governance for AI agents.", + "description": "Open specifications and verifiers for the AI supply chain: model weights, agent identity, tool calls and delegation, bound to hardware attestation and checkable offline.", "sameAs": [ "https://github.com/agentrust-io", "https://trace.agentrust-io.com", "https://manifest.agentrust-io.com", "https://cmcp.agentrust-io.com", + "https://ca2a.agentrust-io.com", + "https://wcm.agentrust-io.com", "https://github.com/agentrust-io/agentrust-telemetry" ] }, @@ -64,21 +66,21 @@ } - + - + - + @@ -208,560 +183,256 @@ - - +
-
-

Open source tools for AI agent governance

-

Control agent actions.
Verify the evidence.

-

AgenTrust helps you check an AI agent's tool calls against policy and produce signed records of the decisions. Start locally, then explore hardware-backed enforcement.

+

Open specifications for verifiable AI

+

Prove what your AI ran, and what it did.

+

Open specifications and verifiers that bind model weights, agent identity and every tool call to hardware attestation. Anyone can check the evidence offline, without asking us.

-

Python 3.11+ · No cloud account · Software demo; no hardware attestation

-
-
-
-

What do you want to try?

-
- - - -
-
-
-
- -

Where policy runs. Where evidence goes.

-
-

Start with the boundary you need. Tool calls use cMCP; delegation to another agent uses cA2A. These are separate paths, and neither requires every component below.

-
-
Agent ManifestDeclares identity, artifacts, and intended authority. A runtime must verify and enforce those declarations.
-
-
Your agentRequests a tool action
-
request
-
cMCP runtimeCatalog lookup + policy decisionTEE boundary in hardware deployments; software process in the demo.
-
allow
-
MCP tool serverRuns the allowed call outside the runtime's boundary
-
-
-
Deny → return an error

The runtime does not forward a denied call to the tool server.

-
Session record → TRACE verifier

Check signed evidence against trusted keys, expected policy, and the required attestation level.

-
Optional anchoring → TRACE Registry

Publish commitments and verify inclusion under signed checkpoints. Independent witness receipts add an external observation; they do not certify the record's claims.

-
Optional delegation → cA2A peer

A separate agent-to-agent path narrows delegated authority and links provenance across hops.

+
+
/verify › tdx_quote.binoffline · in this browser
+
    +
  1. quoteIntel TDX v4, GCP C3, captured 2026-07-21
  2. +
  3. step 1attestation key signature over header and TD reportnot run
  4. +
  5. step 2QE report binds the attestation keynot run
  6. +
  7. step 3QE report signed by the platform PCK certificatenot run
  8. +
  9. step 4PCK chain ends at the pinned Intel SGX Root CAnot run
  10. +
  11. REPORTDATA32 bytes set by the guestsee note
  12. +
  13. verdictgenuine Intel TDX silicon signed this quotenot run
  14. +
+
+
+

NoteThis quote proves genuine Intel TDX silicon signed it. Its REPORTDATA holds a manifest hash whose input was not published, so it does not yet tie a specific record to this machine.

+

Runs in your browser. Nothing is sent back to us.

-
Tool-call path and evidence path. Protecting the runtime does not put the model, agent process, or upstream tool server inside its TEE.
-
-
OBSERVE & CORRELATEAgenTrust Telemetry connects governance events with your application's OpenTelemetry traces. Telemetry records decisions; it does not enforce policy.
-

A signature establishes who signed a record and whether it changed. Hardware provenance additionally requires verified attestation and a trust policy. See the software demo's expected verification result →

-
- -
- -
-
- -

An ecosystem built around adoption

-
-
-

Use it

Start with runnable demos, reference implementations, schemas, and conformance tests. Move from evaluation to a production pilot without waiting for a proprietary platform.

-

Improve it

Bring implementation feedback, integrations, threat models, deployment evidence, and research. Public repositories and issue trackers make the contribution path visible.

-

Sustain it

Grow maintainers, review contributions, document adoption patterns, and share stewardship across organizations so critical governance infrastructure outlives any one team.

-
-
Adoption pathway: explore a ten-minute demo → test against the open suites → pilot one trust boundary → contribute results and integrations → help govern and maintain the shared infrastructure.
- -
- -
- -
-
- Linux Foundation - TRACE joins the Linux Foundation. The open specification now has vendor-neutral governance for portable, verifiable runtime evidence across AI agents and confidential workloads. - Read the Linux Foundation announcement →
-
+ +
- -

Relationships the public record supports

-
-

Every organization named here has a traceable relationship through a public announcement, open-source repository, or explicit AgenTrust partner statement. The label on each card states that relationship precisely; sponsorship, partnership, contribution, and adoption are distinct relationships, and none implies blanket endorsement of the full stack.

- -
-
The Linux Foundation
-
Neutral host

TRACE Specification is an LF Project

TRACE is hosted at the Linux Foundation as its own series. Its specification, IP, trademark, and conformance mark sit with the series under the Community Specification License and LF Projects policies, so no single vendor decides what conformance means.

Read the project governance ↗
-
-
-
-
OPAQUE Systems
-
Founding engineering and infrastructure sponsor
-

OPAQUE provides funding, engineering time, infrastructure, and confidential-computing contributions. Sponsorship does not confer ownership of AgenTrust projects or governance authority over their technical decisions.

- Review the public project record ↗ -
-
-
Microsoft
-
Open-source project home
-

Microsoft hosts the Agent Governance Toolkit, the open runtime-governance foundation that the AgenTrust trust chain builds on.

- View the repository ↗ -
-
-
Technology Innovation Institute
-
Confirmed founding partner
-

TII is the confirmed AgenTrust founding partner anchoring the work in sovereign-AI deployment requirements.

- Read the OPAQUE announcement ↗ -
-
-
AMD
-
Founding member and hardware partner
-

AMD is a founding partner of AgenTrust. AMD and OPAQUE published a joint implementation blueprint for hardware-backed Confidential AI, and the implementation verifies SEV-SNP report signatures to the AMD root.

- Read the joint white paper ↗ -
-
-
Intel
-
Founding member and hardware partner
-

Intel is a founding partner of AgenTrust. The implementation verifies Intel TDX DCAP v4 quotes to the pinned Intel SGX Root CA, hardware-validated on GCP C3.

- Review the public implementation record ↗ -
-
-
ServiceNow
-
OPAQUE customer implementation
-

OPAQUE publicly documents how ServiceNow used its Confidential AI Platform to reduce commission-inquiry workflows from days to seconds.

- View the OPAQUE customer story ↗ -
-
-
CSA Agentic Trust Framework
-
Public framework collaboration
-

ATF's author publicly supports positioning AGT as a reference implementation and invited implementation input into the conformance specification.

- Read the public collaboration thread ↗ -
-
-
PRONATIVE AI
-
Ecosystem Training & Adoption Partner
-

PRONATIVE AI works with AgenTrust to bring verifiable agent governance into enterprise engineering education and adoption. The partnership includes joint educational programming and the planned integration of cMCP, cA2A, and TRACE into PRONATIVE AI's AI-Native Engineering Foundry curriculum. PRONATIVE AI is also adopting the Microsoft Agent Governance Toolkit within its delivery environment and will publish implementation guidance as that work becomes publicly available.

- View the featured session ↗ -
+ +

Logs are written by the system you are trying to check.

-
-
-
XRSI: Human Intelligence In The Loop
-
Ecosystem partner

Governance and Ecosystem Sustainability Partner

XRSI brings governance, community-building, and long-term ecosystem sustainability expertise to the AgenTrust adoption programme.

-
-
-
Action State Group
-
Technical collaborator

Trust Registry and Verifiable Record Collaboration

Action State Group is collaborating with AgenTrust on an open contribution path for the TRACE Trust Registry, connecting TRACE runtime evidence with neutral, independently verifiable record and witness infrastructure.

Visit Action State Group ↗
+
+
+

Agents can edit the record of what they did.

+

An independent evaluator's incident report (METR, 26 August 2026) found roughly 7% of the agent transcripts it reviewed had been successfully spoofed, and could not rule out agents deleting logs after the fact.

+ Read the incident report ↗
-
-
Odystra AI
-
Startup supporter

Odystra AI

Odystra builds an agentic governance, risk, and compliance platform for regulated enterprises.

Visit Odystra ↗
+
+

The tooling around agents is the attack surface.

+

In June 2026 a remote UI package for a popular coding-agent CLI, at about 29,000 weekly npm downloads, shipped code that exfiltrated users' non-expiring OAuth refresh tokens.

-
-
o1Labs
-
Startup supporter

o1Labs

o1Labs develops applications and infrastructure powered by zero-knowledge cryptography.

Visit o1Labs ↗
+
+

Weights are leaving the building.

+

Sovereign and on-premises deployment puts a model builder's weights on hardware somebody else owns. Weight-security research recommends confidential computing for the highest protection levels, and current silicon still falls to an operator with physical access.

+ Read the weight-security research ↗
- -

-
+ +
- -

Open work, visible decisions, more maintainers

-
-

AgenTrust develops in public through open repositories, reviewable proposals, implementation evidence, and conformance testing. The goal is not simply to publish specifications: it is to create a contributor community capable of operating, improving, and stewarding the technology.

-
-
Technical stewardship

Imran Siddique

AgenTrust
Architecture, implementation, conformance, and maintainer development.

-
Governance & sustainability

XRSI

Named organizational partner for community governance, ecosystem adoption, and long-term sustainability. Individual committee appointments will be published only after confirmation.

-
Committee formation

Community seats

Adopter, maintainer, research, and public-interest representation will be added as the steering model is formalized.

+ +

Four questions, each with evidence a stranger can check.

- -
- Contribute code, tests, and documentation ↗ - Browse open contribution pathways ↗ - Follow the public project roadmap ↗ +
+
+ 01 · WEIGHTS + Is this the model that was released, and who may release its key? +

Weight Custody Manifest

+ Spec pre-1.0, SDK 0.28.1, 91 portable conformance vectors +
+
+ 02 · AGENT + What is this agent, and what is it allowed to do? +

Agent Manifest

+ SDK 0.12.0, proposed to CoSAI WS4 (RFC #149) +
+
+ 03 · ACTIONS + Was each tool call and each delegation checked inside attested hardware? +

cMCP and cA2A

+ cmcp-runtime 0.5.0; cA2A 0.2.0 developer preview +
+
+ 04 · EVIDENCE + Can a third party verify all of it offline, years later? +

TRACE, TRACE Registry, conformance suite

+ TRACE spec v0.2 at the Linux Foundation, agentrust-trace 0.10.0, signed registry checkpoints with an external witness receipt +
+

Each step links to its project site. No step requires the others; use the ones your trust boundary needs.


-
+ +
- -

From runtime evidence to compliance playbooks

+ +

Validated on real silicon, verified to the vendor's root.

-

The fellowship will turn AgenTrust implementation patterns into practical, public playbooks. Each playbook will map governance controls and TRACE evidence to an authoritative framework without claiming certification or legal compliance.

-
- Management systemISO/IEC 42001Planned playbook - TransparencyEU AI Act · Article 50Planned playbook - Data protectionGDPRPlanned playbook - Assurance controlsSOC 2Planned playbook - Risk managementNIST AI RMFPlanned playbook +
+ + +
+

We verify signature chains. We do not appraise whether a platform's TCB is current.


- -
+ +
- -

Specifications, protocols, and shared building blocks

-
- -
- - - -
-
-
Attestation Standard
-
TRACE
-
TRACE defines portable, signed runtime evidence. Hardware provenance requires attestation verification against a trusted root; software-mode records do not provide that guarantee.
-
- -
- - - -
-
-
Evidence Infrastructure
-
TRACE Registry
-
A public, append-only registry of anchors, checkpointed on activity and signed by the registry key. Record holders retain their evidence; the published registry contains commitments. Offline verifier on PyPI; no hosted query endpoint. Supports independent witnesses, with one checkpoint receipt demonstrated.
-
- -
- - - -
-
-
Identity Standard
-
Agent Manifest
-
A structured declaration of an agent's capabilities, permissions, and data access policies. Machine-readable identity that operators and orchestrators can verify before invocation.
-
- -
- - - -
-
-
Protocol Extension
-
Confidential MCP
-
The confidential, security-hardened way to run the Model Context Protocol. MCP tool calls are evaluated against policy inside a Trusted Execution Environment, so tool-call plaintext is not readable from the host. The guarantee is bounded: it holds where the egress policy denies telemetry endpoints, and it covers the tool boundary, not model inference.
-
- -
- - - -
-
-
Delegation Profile
-
Confidential A2A
-
The secure, confidential profile for the Agent2Agent (A2A) protocol. Adds attested, attenuated delegation, a sealed peer channel, and offline-verifiable provenance per hop, so agent-to-agent delegation is verifiable and confidential, not just authenticated at the front door.
-
- -
- - - -
-
-
Curated Resource
-
Awesome AI Governance
-
A community-curated list of tools, frameworks, standards, and research for governing autonomous AI agents. Covers policy engines, audit frameworks, risk assessments, and deployment guidance.
-
- -
- + +

What this proves, and what it does not.

+
    +
  • A signature shows who signed a record and that it has not changed. It says nothing about where the signer ran.
  • +
  • Hardware origin needs a verified attestation that binds the signing key.
  • +
  • Memory-bus attacks such as TEE.fail and BadRAM defeat current confidential-computing silicon against an operator who physically owns the machine. Weight custody is scoped to match.
  • +
  • The quickstart and demos run in software mode, with no hardware isolation.
  • +
  • Conformance vectors are self-tests. They are not certification.
  • +
  • A registry entry shows a record was anchored. It does not validate the record's claims.
  • +

- -
+ +
- -

Test Suite & Tooling

+ +

Start where your trust boundary is.

- -
- - - -
-
-
Governance Telemetry · Alpha
-
AgenTrust Telemetry
-
A backend-neutral event contract and reference SDKs for policy decisions, approvals, actions, classified data flow, usage and cost, and evidence lifecycle, correlated with OpenTelemetry and able to finalize complete evidence into TRACE.
-
- -
- - - -
-
-
Runnable Demos
-
Ten Runnable Demos
-
Run the specs on your own machine, no hardware required. Block a data leak, verify a signed receipt, refuse tampered model weights, and govern OpenAI-compatible model calls.
-
- -
- - - -
-
-
Test Infrastructure
-
TRACE Test Suite
-
Conformance tests and integration harness for TRACE implementations. Verify that your attestation receipts meet the spec before shipping to production.
-
- -
- - - -
-
-
Microsoft Open Source
-
Agent Governance Toolkit
-
GitHub Actions, policy checks, and CI integrations for governing agent behavior in software repositories. Contributor reputation, workflow provenance, and supply-chain verification.
-
- -
- - - -
-
-
Source Code
-
GitHub Organization
-
All spec source, examples, registry entries, and integration guides. TRACE spec, Agent Manifest schema, cMCP protocol, cA2A profile, and the full awesome-ai-governance curated list.
-
- -
- +
+ + +

- -
+ +
- -

What's Launched

+ +

Anyone can read it, run it and check it.

-
-
-
Registry briefing · September 9, 2026
- -
-
-
Attestation Standard
-
TRACE v0.2
-
-
-
Identity Standard
-
Agent Manifest spec v0.1
-
-
-
Protocol Extension
- -
-
-
Delegation Profile
-
cA2A v0.1 · preview
-
-
-
Launched
-
June 23, 2026
-
-
-
License
-
Apache 2.0, MIT, CC BY 4.0
-
-
-
Standardization
- -
-
-
Hardware Evidence
- -
-
-
Conformance
- +
+

TRACE is its own Series of LF Projects, announced by the Linux Foundation on 25 August 2026 and developed with AMD, Intel, Microsoft, OPAQUE and TII.

+
+ The Linux Foundation + AMD + Intel + Microsoft + Technology Innovation Institute + OPAQUE
+ Read the Linux Foundation announcement ↗ +
+
+
+
OPAQUE
+
Sponsor
+

Sponsored by OPAQUE, which funds the engineering, infrastructure and confidential-computing work behind these projects. Organisations that want to support open, verifiable AI infrastructure are welcome to join as sponsors.

+ Talk to us about sponsoring → +
+
+
+
Every project is open source. Licences vary by project and are listed on each site.
+
8 of 9 repositories hold an OpenSSF Best Practices passing badge.
+
Software policy enforcement builds on the Microsoft Agent Governance Toolkit.
+
+

- -
-
- -

AgenTrust Fellowship 2026

-
-

The AgenTrust Fellowship supports emerging maintainers of open infrastructure for verifiable AI systems. Fellows contribute code, tests, integrations, documentation, and adoption guidance across AgenTrust projects, grounded in real issues and verifiable work.

-

Applications closed early on 26 August 2026 due to exceptional volume. More than 150 applications are under review. The fellowship will not start in September as originally planned. The schedule and decision timeline are being reviewed and there is no firm notification date yet. Applicants do not need to send anything further; the submitted proposal is what is assessed. A revised timetable will be published here once it is confirmed, and applicants will be contacted directly.

- -
- -
-
- -

Architecting at Scale

-
-

AgenTrust founder Imran Siddique has turned the lessons behind production cloud and AI systems into a practical book. It connects the architecture of distributed systems with the harder problem now in front of us: building AI-native systems that remain observable, governable, and correct when they meet production.

- -
- -
- -
-
- -

What is AgenTrust?

-

AgenTrust is an open ecosystem for verifiable AI agent governance. It connects reusable technology with the people and practices needed to adopt it: maintainers, implementers, researchers, enterprise operators, conformance testing, integration guidance, and transparent community governance.

-

Agent Manifest declares identity and intended authority. cMCP governs tool calls; cA2A governs delegation to another agent. TRACE carries signed runtime evidence for verification against a trust policy. Hardware provenance depends on verified attestation. Use the components required by your trust boundary. Explore each project's specification, reference implementation, and license through the technology links above.

-

AgenTrust Telemetry is the integration layer across that chain. It gives runtimes a common, metadata-only contract for governance facts, projects those facts into caller-owned OpenTelemetry, and can turn a complete durable evidence set into TRACE. It does not replace a policy engine, collector, observability backend, or dashboard.


@@ -773,14 +444,14 @@

What is AgenTrust?

Frequently Asked Questions

-
-
Is AgenTrust a standards-development programme?
-
No. AgenTrust is an open-source ecosystem focused on adoption, implementation, interoperability, maintainer development, and long-term sustainability. Its open specifications are shared technical building blocks; community implementations, test infrastructure, integrations, documentation, and deployment evidence make those building blocks useful in practice.
-
What is TRACE?
TRACE defines portable, signed runtime evidence. Hardware provenance requires attestation verification against a trusted root; software-mode records do not provide that guarantee.
+
+
What is the Weight Custody Manifest?
+
The Weight Custody Manifest (WCM) is an open, pre-1.0 specification for protecting model weights a builder deploys into a customer's own or sovereign infrastructure. It binds weight identity and custody terms to key-release policy. Against an operator who physically owns the hardware it provides accountability, not cryptographic custody.
+
What is Agent Manifest?
Agent Manifest is a structured, machine-readable declaration of an agent's capabilities, permissions, and data access policies. Operators and orchestrators can verify an agent's manifest before invocation.
@@ -794,24 +465,12 @@

Frequently Asked Questions

Confidential A2A is a trust profile on the Agent2Agent (A2A) protocol. Where A2A's Signed Agent Card verifies only the domain owner, cA2A adds attested, attenuated delegation, a sealed peer channel that binds the task payload to the peer's attested measurement, and an offline-verifiable provenance record per hop. It is a developer preview.
-
Can I try cMCP without confidential-computing hardware?
-
Yes. The 10-minute quickstart runs in software mode: write a policy, observe a denied tool call, and inspect the signed session record. This demonstrates policy enforcement and record verification. It provides no hardware isolation or hardware-backed provenance.
-
-
-
What is the secure version of A2A?
-
Confidential A2A (cA2A) is the security profile for the Agent2Agent (A2A) protocol. A2A authenticates a peer's domain but not what it does with a delegated task. cA2A adds attested, attenuated delegation (each hop's authority is a provable subset of its parent's), runtime attestation of the peer, a sealed peer channel, and offline-verifiable provenance, so agent-to-agent delegation is secure and confidential end to end, not just authenticated at the front door.
-
-
-
How do the AgenTrust standards relate to each other?
-
Agent Manifest declares identity and intended authority. cMCP governs tool calls; cA2A governs delegation to another agent. TRACE carries signed runtime evidence for verification against a trust policy. Hardware provenance depends on verified attestation. Use the components required by your trust boundary.
+
Can I try it without confidential-computing hardware?
+
Yes. The 10-minute quickstart runs cMCP in software mode: write a policy, observe a denied tool call, and inspect the signed session record. It provides no hardware isolation or hardware-backed provenance. The verify page checks a genuine Intel TDX quote in your browser with no hardware of your own.
-
Are the AgenTrust standards open source?
-
Yes, though not all under one licence. Agent Manifest and the TRACE conformance suite are Apache 2.0, cMCP and cA2A are MIT, and the TRACE specification text is CC BY 4.0 with its reference code under Apache 2.0. Source, schemas, and examples are on GitHub at github.com/agentrust-io.
-
-
-
What is OPAQUE Systems' role in AgenTrust?
-
OPAQUE Systems is a founding engineering and infrastructure sponsor and an active contributor. Sponsorship itself does not grant ownership or governance authority. Each project's licence, charter, maintainer list, and published governance process define its legal and technical stewardship.
+
Are the AgenTrust specifications open source?
+
Yes, though not all under one licence. Agent Manifest, the Weight Custody Manifest and the TRACE conformance suite are Apache 2.0, cMCP and cA2A are MIT, and the TRACE specification is under the Community Specification License 1.0 with its code under Apache 2.0. Source, schemas, and examples are on GitHub at github.com/agentrust-io.
@@ -823,12 +482,15 @@

Frequently Asked Questions

-
Independent open-source project. OPAQUE Systems provides funding, engineering time, infrastructure, and confidential-computing contributions as a founding sponsor. Sponsorship does not confer ownership or governance authority.
+
Sponsored by OPAQUE, which funds the engineering, infrastructure and confidential-computing work behind these projects.
diff --git a/scripts/render-adoption.mjs b/scripts/render-adoption.mjs index 3b5c328..2c243e4 100644 --- a/scripts/render-adoption.mjs +++ b/scripts/render-adoption.mjs @@ -2,7 +2,7 @@ import { access, readFile, writeFile } from 'node:fs/promises'; const root = new URL('../', import.meta.url); const dataUrl = new URL('data/adoption.json', root); -const pageUrl = new URL('index.html', root); +const pageUrl = new URL('community/index.html', root); const start = ' '; const end = ' '; @@ -71,7 +71,7 @@ const next = page.slice(0, startAt) + generated + page.slice(endAt + end.length) if (process.argv.includes('--check')) { if (page !== next) { - console.error('index.html adoption section is stale; run node scripts/render-adoption.mjs'); + console.error('community/index.html adoption section is stale; run node scripts/render-adoption.mjs'); process.exit(1); } console.log(`PASS ${relationships.length} adoption relationships are in sync`); diff --git a/sitemap.xml b/sitemap.xml index ea90ffc..2f8d75f 100644 --- a/sitemap.xml +++ b/sitemap.xml @@ -1,6 +1,7 @@ https://agentrust-io.com/ + https://agentrust-io.com/community/ https://agentrust-io.com/demos/ https://agentrust-io.com/extensions/ca2a/v0.1/ https://agentrust-io.com/go/ diff --git a/supernav.js b/supernav.js index 62631cd..afaf4be 100644 --- a/supernav.js +++ b/supernav.js @@ -10,6 +10,7 @@ var SITES = [ { id: 'home', label: 'agentrust-io', url: 'https://agentrust-io.com', ext: false }, + { id: 'verify', label: 'Verify', url: 'https://agentrust-io.com/verify/', ext: false }, { id: 'quickstart', label: 'Quickstart', url: 'https://agentrust-io.com/quickstart/', ext: false }, { id: 'demos', label: 'Demos', url: 'https://agentrust-io.com/demos/', ext: false }, { id: 'telemetry', label: 'Telemetry', url: 'https://agentrust-io.com/telemetry/', ext: false }, @@ -32,7 +33,8 @@ // at agentrust-io.com/wcm/: it highlights WCM for the instant before the // reader is moved to wcm.agentrust-io.com. - var CURRENT_ID = (HOST === 'agentrust-io.com' && PATH.indexOf('/quickstart') === 0) ? 'quickstart' + var CURRENT_ID = (HOST === 'agentrust-io.com' && PATH.indexOf('/verify') === 0) ? 'verify' + : (HOST === 'agentrust-io.com' && PATH.indexOf('/quickstart') === 0) ? 'quickstart' : (HOST === 'agentrust-io.com' && PATH.indexOf('/demos') === 0) ? 'demos' : (HOST === 'agentrust-io.com' && PATH.indexOf('/telemetry') === 0) ? 'telemetry' : (HOST === 'agentrust-io.com' && PATH.indexOf('/registry') === 0) ? 'registry' diff --git a/verify/home-panel.js b/verify/home-panel.js new file mode 100644 index 0000000..9a4bb72 --- /dev/null +++ b/verify/home-panel.js @@ -0,0 +1,32 @@ +/* Fills the homepage hero panel from a live run of verify/tdx-verify.js on the + * committed GCP capture, so "runs in your browser" is literally what the panel + * shows. Without JavaScript the rows keep their "run it" link to /verify/. + */ +import { verifyTdxQuote } from './tdx-verify.js'; + +const panel = document.getElementById('verify-panel'); + +function set(id, word, kind) { + const state = panel.querySelector(`[data-step="${id}"] .state`); + if (!state) return; + state.textContent = word; + state.className = `state ${kind}`.trim(); +} + +if (panel) { + panel.querySelectorAll('.state').forEach((state) => { state.textContent = 'checking'; state.className = 'state'; }); + try { + const response = await fetch(new URL('fixtures/gcp-tdx-2026-07-21-tdx_quote.bin', import.meta.url)); + if (!response.ok) throw new Error(`HTTP ${response.status}`); + const result = await verifyTdxQuote(new Uint8Array(await response.arrayBuffer())); + for (const step of result.steps) { + if (step.status === 'pass') set(step.id, 'PASS', 'pass'); + else if (step.status === 'fail') set(step.id, 'FAIL', 'fail'); + else set(step.id, 'not run', ''); + } + set('verdict', result.accepted ? 'ACCEPTED' : 'REJECTED', result.accepted ? 'pass' : 'fail'); + set('reportdata', 'see note', 'note'); + } catch (error) { + panel.querySelectorAll('.state').forEach((state) => { state.textContent = 'not run'; state.className = 'state'; }); + } +}