The trust layer for AI agents
MCP and A2A define how agents talk.
Custos decides whether they should be trusted.
Identity, credential-free tool access, policy enforcement, sub-second revocation and a verifiable audit trail for every agent request. It runs on top of the protocols you already use, like TLS for agentic services.
Get early accessSix questions, answered on every request
Who are you?
Every agent gets a cryptographic identity: a did:web DID and a W3C Verifiable Credential.
Can I trust you?
Each request carries a fresh proof signed with a key only the agent holds. A copied credential is useless.
What may you do?
Deny-by-default allowlists per agent and tool, enforced before any token is issued.
What data may you receive?
Every tool declares the data categories it touches, recorded on every decision.
Can I revoke you?
One command cuts an agent off from every connected tool in under a second.
Can I prove what happened?
Every action is a signed audit record: which agent, under whose authority, what was decided.
How it works
- 1
Register
The agent generates its own key. Custos issues a signed credential naming it.
- 2
Grant
An operator allows the agent one tool at a time. Everything else is denied.
- 3
Call
The agent gets a 60-second token scoped to one tool. The vault makes the call. The agent never sees the tool's password.
- 4
Revoke
A signed revocation is pushed to every enforcement point. The next call fails, everywhere.
Built for audit
Agents act on someone's authority. Custos records whose: every record carries the agent identity, its authority chain, the data categories touched, the policy applied and the decision, signed and independently verifiable. Designed with regimes like India's DPDP Act in mind.
Coming soon
Custos is in private development and opening to early design partners. If you run AI agents against real tools and need to prove what they did, we'd like to hear from you.
Join the early access list