Agent Security License 1.0

The security license AI agents can prove.

Before an AI agent reaches code, data, tools, or money, CapitalGuard helps expose the risk, apply preventive controls, and issue a signed status record that people and software can verify.

A checkable trust model

Signed. Scoped. Expiring. Revocable.

SSL made website trust checkable. CapitalGuard applies that principle to AI-agent security without pretending one record can guarantee complete protection.

Who issued the record
What public scope it covers
Which CapitalGuard Standard version applies
Whether the evidence signature is valid
Whether the status is active, expired, or revoked
Which Guardprint and evidence digest are bound to it

One license. Three security jobs.

Detect

Map exposed secrets, risky files, permissions, tools, data paths, and agent actions before access expands.

Control

Install local guardrails for protected paths, approvals, egress, spending, delegation, memory, and changes.

Prove

Create a signed record with live status, scope, expiry, revocation, and a public verification URL.

Machine verification

Any system can check the license before trust.

CapitalGuard publishes the verification endpoint, Ed25519 keys, schemas, support matrix, threat model, and deterministic test vectors. The protected enforcement code remains available only through a paid license.

Inspect the nine-case verification benchmark

Exact boundary

This record confirms a CapitalGuard-signed security state for the named public scope and evidence digests under the stated Standard version. It does not guarantee breach prevention, prove that every agent or action is safe, attest systems outside the authorized scope, or replace account, endpoint, identity, cloud, and human security controls.