Coming soon

The trust layer for AI agents

MCP and A2A define how agents talk.
Custos decides whether they should be trusted.

Identity, credential-free tool access, policy enforcement, sub-second revocation and a verifiable audit trail for every agent request. It runs on top of the protocols you already use, like TLS for agentic services.

Get early access

Six questions, answered on every request

Who are you?

Every agent gets a cryptographic identity: a did:web DID and a W3C Verifiable Credential.

Can I trust you?

Each request carries a fresh proof signed with a key only the agent holds. A copied credential is useless.

What may you do?

Deny-by-default allowlists per agent and tool, enforced before any token is issued.

What data may you receive?

Every tool declares the data categories it touches, recorded on every decision.

Can I revoke you?

One command cuts an agent off from every connected tool in under a second.

Can I prove what happened?

Every action is a signed audit record: which agent, under whose authority, what was decided.

How it works

  1. 1

    Register

    The agent generates its own key. Custos issues a signed credential naming it.

  2. 2

    Grant

    An operator allows the agent one tool at a time. Everything else is denied.

  3. 3

    Call

    The agent gets a 60-second token scoped to one tool. The vault makes the call. The agent never sees the tool's password.

  4. 4

    Revoke

    A signed revocation is pushed to every enforcement point. The next call fails, everywhere.

Built for audit

Agents act on someone's authority. Custos records whose: every record carries the agent identity, its authority chain, the data categories touched, the policy applied and the decision, signed and independently verifiable. Designed with regimes like India's DPDP Act in mind.

Coming soon

Custos is in private development and opening to early design partners. If you run AI agents against real tools and need to prove what they did, we'd like to hear from you.

Join the early access list