Trust and security

Defensive scans. Redacted findings. Clear authorization.

CapitalGuard is built for teams that need a focused AI-agent exposure review without overclaiming protection, compliance, or certainty.

Production readiness is public

Defensive scanning only

Written authorization required for every scope

Included local scanner does not upload source code

Secret-like values redacted from customer output

Private delivery bound to license and purchase email

Stripe state reverified before license issuance

Scan credits consumed atomically

Distributed abuse controls on sensitive routes

Public badges expire and can be revoked

Responsible disclosure channel

Public proof

Verify a security license without exposing customer systems.

CapitalGuard public verification confirms license status, scope label, and scan date only. It never shows private findings, raw paths, source code, secrets, or license keys.

Signed AI Agent Security License records

Customers can share a public license ID after an approved scan. The record binds to signed evidence and can be checked without accessing the customer dashboard.

Verification lifecycle

Public proof is issued only after payment, authorization, and operator approval.

The badge system is designed to help customers share a restrained proof point while keeping sensitive security work private.

Paid license

The customer purchases Starter, Pro, or Agency through the hosted checkout before private delivery starts.

Authorized scan

CapitalGuard records repository ownership or written authorization before reviewing any scope.

Operator approval

A public record is issued only after the completed scan is approved for external status sharing.

Public verification

People and software can check license status, public scope, scan date, expiry, revocation, and signature.

Claim boundaries

Useful public proof without dangerous overclaiming.

CapitalGuard verification should help a customer prove that a specific public scan status exists. It should not become a misleading security seal.

Open Verification
Shows status, public scope, last scan date, expiry, and approved summary only.
Never shows source code, raw paths, secrets, private findings, license keys, or customer credentials.
Does not claim breach prevention, compliance certification, or complete security.
Can be revoked when scope, status, authorization, or claim safety changes.

Security license badge

Publish proof that stays bound to the ledger.

Only an active, cryptographically valid AI Agent Security License record can produce the official badge.

Enter the public code issued after a completed CapitalGuard review.

Ledger-bound preview

A badge appears only after the signed Guardprint is promoted from recorded to an active security license.

Responsible disclosure

Report suspected vulnerabilities to support@capitalguard.io. Include affected paths, reproduction steps, impact, and contact details. Do not access customer data or third-party systems without authorization.