AIC binds every agent action to an accountable principal — with capability limits, delegation evidence, and offline-verifiable authorization, built on standards your security team already trusts.
AIC answers the question IAM leaves open: who authorized this agent action, why, and under what limits?
Every agent action is cryptographically attributable to the principal who signed its delegation — traceable in audit, not just in policy.
Capabilities, constraints, and lifetime are signed into a DelegationAuthorization, so agents operate within a verifiable permission envelope.
Authorization evidence verifies without external database lookups — critical for edge, air-gapped, and intermittently connected deployments.
Two IETF Experimental drafts with a Royalty-Free IPR commitment, and an independent implementation reproducing 13/13 conformance cases.
16,000+ regular and 8,000+ AIC certificates per second on one x86 machine, benchmarked against a modeled 500,000-agent workload.
Fully open-source reference implementation in five languages, with published security and gateway audit reports.
Public benchmarks on documented hardware, with MariaDB persistence — reproducible from the open repository.
AIC extends your existing trust infrastructure rather than demanding a new one.
The X.509 profile rides your current CA chain and signing hardware; no new trust anchor required.
AIC is a standard X.509 v3 extension — authentication stays in TLS, authorization verification happens at the gateway.
The AIC-JWT profile brings the same model to HTTP, SaaS, and browser pipelines.
A zero-trust gateway evaluates principal grant ∩ agent capabilities ∩ runtime policy on every request — TCP, HTTP, and UDP.
Machine-readable, signed capability schemes let different organizations share a common authorization vocabulary.
The accountability and traceability properties enterprises are being asked to demonstrate.
Effective human oversight and traceability for high-risk AI: agent actions map to the human who authorized them.
Accountability and transparency as first-class properties, not afterthoughts.
Immutable decision records with identity, principal, capability, decision, and timestamp.
Issuer authority and principal delegation authority are cryptographically separated — a compromised CA cannot mint new principal grants.
We work directly with a small number of design partners to deploy AIC in real infrastructure and shape the standard together.
Email the pilot team; tell us about your agent workloads and existing PKI/IAM.
A short call to map AIC onto your architecture and pick a pilot use case.
Joint integration with direct engineering support and conformance testing.
Review audit trails, performance, and fit; decide on production rollout.
Hands-on integration help from the implementers — not a ticket queue.
Access to the independent interoperability test suite and joint conformance results.
Real deployment feedback shapes the next IETF draft revisions.
Co-publish a public case study, or keep the engagement confidential.
We respond to every serious inquiry. Tell us where your agents act, and we will show you how AIC fits.