AI trust infrastructure

Proof,
not permission.

Your agent authenticates with a secret. That proves possession, not identity — and nothing proves what it was authorized to do, or what it actually did. Rezos is the layer that does.

0
Agents registered
0
Median verify
0
Covered notional
0
Active attestors
issuer

Three questions
nobody can answer

An agent authenticates by presenting a secret. That mechanism answers exactly one question — does this caller possess the secret. It cannot answer the ones that now matter.

identity
Which agent is this, really?

A bearer token proves someone holds a string. It doesn't prove the request came from the model you chose, on the version you vetted, running unmodified.

authority
What may it do, and who can check?

Permissions live inside one company's database. The counterparty on the other side of the trade cannot verify them. Neither can you.

evidence
What actually happened?

When an autonomous system loses money, the record is held by parties with their own exposure to what's in it. Evidence shouldn't be owned by an interested party.

context_class

An agent can't tell
data from orders

Put an instruction inside content an agent reads, and it will follow it. Nobody has solved this at the model layer. So we make it refusable — a mandate can say act only on vetted sources, and the action dies before it reaches the venue.

Edit the research note below. Then run the agent.

live verification
Untrusted source — research-feed.example
Gateway
awaiting run
context_class: [principal, attested] · notional_cap: $12,000
subject

Four primitives

We make no claim about whether an agent's reasoning is sound. We constrain and record what it is permitted to do, which is checkable.

Rezos identity

Identity that means something

A key bound to attested provenance — which operator, which model family and version, and where available a hardware attestation of the runtime. Assurance tiers from A0 to A3 let a counterparty decide what it accepts, without asking anyone to open their weights.

Mandate

Authority that travels

A signed capability grant, verifiable offline, without calling us. Caps, venues, rate limits, expiry. Delegation computes an intersection with its parent — widening isn't forbidden by policy, it's arithmetically inert. About 280 bytes, verified in under a millisecond.

Context commitment

Decisions bound to inputs

Before acting, an agent commits to a hash of everything it read and the provenance class of each source. You can constrain what it may act on, and when something goes wrong the record names the exact document. We don't detect the attack — we make it refusable and attributable.

Action receipt

Evidence anyone can check

Every decision emits a signed receipt — mandate, intent, inputs, verdict, which caveats fired. Merkle-accumulated and anchored on chain every 30 seconds. An auditor can reconstruct the whole history without trusting any Rezos operator, including us.

notional_cap

Authority you can
actually see

A mandate isn't a settings page. It's a signed object your agent carries, and any counterparty can verify it without asking us.

Per action cap$12,000
Monthly cap$90,000
Valid for30 days
May act on
Signed mandate

        
verdict

One honest auditor

Mandate evaluation is deterministic. Two honest verifiers always agree, so disagreement isn't noise to average — it's a fault to prove. That lets us drop staked voting entirely, and it buys a much weaker security assumption than honest majority.

01 / submit
Agent acts

The action reaches the gateway carrying its mandate chain and context commitment.

~0.4 ms local eval
02 / attest
Verdicts signed

A VRF-sampled set evaluates independently. Two of three agree, the action proceeds.

12 ms p50 added
03 / anchor
Receipt anchored

Receipts accumulate into a Merkle root committed on chain on a fixed cadence.

every 30 s
04 / challenge
Anyone re-runs it

A bonded auditor re-executes and proves a wrong verdict. No oracle, no vote, no judgment call.

24 h window
origination

Where the rewards
come from

Emissions are a subsidy — dilutive by construction, paying people in claims on our own future. Fees are external value entering because someone outside got something they wanted. Only one of those lasts.

Value-moving actionsoperators buying market access · 0.8 bps
$59,520
Coverage premiumsprincipals buying bounded risk · 2.5 bps
$37,000
Institutional gatewayregulated firms buying evidence
$11,974
Reads and previewsintegrators buying liability reduction
$5,200
2.4×
Coverage ratio

Fee-funded rewards divided by emission-funded rewards. Not price — this is the number worth watching, and we publish it every epoch. Crossover targeted in year three.

Three of our four payer classes would pay for reasons that exist even if there were no token. That's the test.

sequence

Useful before
it's trusted

Each phase ships something worth using before the next one exists. Risk rises only after the layer has earned it.

phase 01
Explorer and docs
Public receipts, no login, nothing to break.
Live
phase 02
Console in advisory mode
Mandates evaluated, violations flagged but never blocked.
Building
phase 03
Enforcement
Gateway blocks, opt-in per principal and per tier.
Q4
phase 04
Network and coverage
Permissionless attestors, token live, coverage pool opens.
2027

Agents will move a lot of the world's capital

The question was never whether they'd be allowed to act. It's whether their authority could be proven. Read the whitepaper, argue with it, tell us where the model breaks.