Your AI agents don't trust each other.
And you cannot prove what any of them did.
Which of these is you?
I build with agents and I want the identity primitive.
BuildersThe repo, the spec, and the conformance vectors three implementations reproduce byte-for-byte. No marketing screens in the way.
about 90 seconds 02I am responsible for securing agents my organisation runs.
Security leadersA live refusal by a named rule, then the published trust anchor you would verify it against — and a written account of where this wedge stops.
about 6 minutes 03My business is adopting AI and I need to know what could go wrong.
Business ownersAn agent refused in plain English before any code appears, then the price and what it does not include.
about 4 minutes 04I want this operated for us, on our terms.
EnterpriseA conversation. There is nothing to buy on this route and the page says so before you spend any time on it.
about 3 minutes 05None of those, or not sure yet.
Everyone elseWhat this is, in one screen, with the live demo on it.
about 2 minutesEach door ends somewhere different, and each one says where before you follow it. Nothing here needs an account, a key, or anything installed.
The one-paragraph version
When an agent acts on your behalf, someone eventually has to answer two questions: who acted, and with what authority. Today that answer lives inside whoever ran the agent, in their logs, inside their trust domain, on their word. SYNTHERA makes the answer travel with the action. Every action an agent takes carries a proof of who acted and with what authority, and anyone holding the signer's public key can check that proof: offline, against a gateway you do not control, long after the fact, with no shared trust domain, no prior relationship, and no service to call. Whether that authority still stands right now is a separate question, and one revocation answers.
The problem
Agents are multiplying. Trust isn't keeping up.
Your company already uses AI agents. Some were built in-house, some came from vendors, some were spun up by teams you've never met. They work fine alone. But the moment one agent needs to call another, or act on another's behalf, four questions have no good answer.
Identity
Which agent is this? Can you verify that claim, or are you just taking its word for it?
Authority
What is this agent actually allowed to do? Where does that permission stop?
Provenance
Who created it? Who approved it? What chain of trust does it carry?
Accountability
What did it do? Is there a record nobody can quietly edit after the fact?
Without a shared way to answer them, trust is something you build by hand, one pair of agents at a time.
Right now, every pair of agents that needs to cooperate gets custom glue code.
5 agents means 10 trust relationships. 20 agents means 190. 50 means 1,225.
It doesn't scale, and it can't be audited. Drag it yourself:
Every pair of agents needs its own bespoke trust. It grows quadratically.
The answer
One identity standard every agent speaks.
SYNTHERA gives every agent a VAID – a verifiable agent identity. Think of it like a passport bound to an action. It says who the agent is, what it's allowed to do, and who issued it. Every action it takes carries a proof any other party can check with the signer's public key – without trusting the agent's own claim, and without a prior relationship.
Cryptographically signed
The action's proof is checked, not asserted. Any party can verify a signed action with the signer's public key – no trust in the sender required. Public-key verification of the VAID document itself — ✓ Shipped.
Capability-scoped
The VAID carries exactly what the agent may do, and nothing more. Permissions travel with identity.
Lineage-tracked
Every VAID records where it came from – its parent and issuer. A third party can now walk that chain and confirm each child's authority sits inside its parent's, across organisations, provided the presenter supplies the ancestors – ✓ Shipped.
If an agent speaks VAID, every action it takes is checkable against the signer's public key – even if you've never seen it before.
Verify a signed action yourself, in the browser →The stack
One foundation. Everything else builds on it.
There are two things to learn here, not seven: VAID, the open standard for verifiable agent identity, and SYNTHERA, the foundation that operates it. Everything below is a capability of that foundation, named by what it does rather than by a product name, because a stranger should not have to hold a brand vocabulary to read this page. Each is designed around the same identity, the same policy engine and the same audit-of-record — which is not the same as saying each is wired to them today, and two are not. Follow any card for the name, the stage, and what does not work.
Any party can verify who did what, and with what authority, by checking one signature – with no shared trust domain and no prior relationship.
Read the page →One deterministic policy engine and one audit-of-record rather than one of each per framework – enforced today on the root agent SYNTHERA provisions, instead of bespoke enforcement per stack.
Read the page →Compose a governed multi-agent system — the roles, and how much authority each may hand on — on one surface, and provision it with the identity and least-privilege wiring already done.
Read the page →Author the rules your agents must follow once and publish them as a versioned constitution, so you can point to the one that was in force. Binding it to what the foundation evaluates is the design and is not connected today.
Read the page →Watch tool calls and trajectories, classify threats by deterministic pattern, shield data at the boundary, and cut a compromised agent off by revoking its identity. Written and tested; running in no environment today.
Read the page →Every change is built and independently reviewed by a second model before a human signs off, so nothing ships on one model's judgement alone.
Read the page →Do I rip anything out?
No. It sits above what you already run.
SYNTHERA is framework-neutral by design and cloud-neutral. The agents you already run stay where they are. One policy engine and one audit-of-record, not one per framework – identity conformance is proven across ADK and OpenAI adapters by a dated run, and policy is enforced today on the root agent SYNTHERA provisions.
SYNTHERA + VAID – one verifiable identity, one policy engine, one audit-of-record, rather than one of each per framework below.
Keep the frameworks and clouds you already run. SYNTHERA sits above them – today it enforces policy on the root agent it provisions.
Where this goes
Containers followed a pattern. This is following the same one.
SYNTHERA is the trust layer for multi-agent systems: every agent gets a verifiable identity, scoped authority and a tamper-evident record, so software from different teams, vendors and frameworks can act on each other’s behalf without custom glue between every pair.
The primitive
Docker turned "how to ship software" into a standard unit anyone could verify. VAID does that for agent identity: a working core and a verifiable envelope, proven against the systems already built on it.
The orchestration layer
Kubernetes grew around containers once they were portable. The same shape is emerging here – independent layers that compose because the primitive underneath is stable.
Open governance
Kubernetes moved to neutral stewardship under CNCF, so no single vendor owned the standard. VAID is built with the same handover in mind. Direction, not commitment.
Talk to us about SYNTHERA.
For teams putting agents into production who already feel the cost of making them work together safely.