Software that acts must be held accountable. Cryptographic proof is not optional. The age of trusting logs is over. That's why we built Vane.
The lineage

Every decade, the internet gets a new trust layer. This is ours.

SSL / HTTPS

Encrypted transport for the web. Nobody trusted plaintext anymore. The internet got its first cryptographic handshake.

Became infrastructure

SSH Keys

Cryptographic identity for machines. Servers could prove who they were. Human passwords gave way to keypairs.

Became infrastructure

OAuth

Delegated authorization for applications. Apps could act on behalf of users with scoped, revocable permission.

Became infrastructure

JWT & SPIFFE

Portable identity tokens for services. Microservices could verify each other without a central directory.

Became infrastructure

Zero Trust

Never trust, always verify. The network perimeter died. Identity became the only perimeter that mattered.

Became infrastructure

Agent Identity

Autonomous software acts, transacts, and decides. Nobody built cryptographic trust infrastructure for agents. Until now.

Vane

The US Commerce Secretary ordered Anthropic to shut down Fable 5 — the most capable AI model ever released — effective immediately. Reason: nobody could verify who was accessing it.

What happens when your agents do something nobody can prove was authorized?

Scenario 01 — Fintech

Your trading agent executes $47M in positions over 6 hours. The SEC opens an inquiry. Your legal team asks: who authorized each trade?

Without Vane

You have server logs. Timestamps. IP addresses. The SEC wants cryptographic proof of authorization. You cannot provide it.

With Vane

Every trade carries an Ed25519-signed attestation. Authorization chain is cryptographically provable in court. Inquiry closed in 72 hours.

Scenario 02 — Healthcare

Your clinical AI agent accessed 12,000 patient records over 3 months. A HIPAA audit begins. The question: was each access authorized?

Without Vane

Your access logs were stored in the same system the agent used. The auditor cannot verify they weren't modified. You face a $1.9M fine.

With Vane

Every PHI access is attested with a cryptographic receipt. Immutable. Independently verifiable. The audit takes 4 hours, not 4 months.

Scenario 03 — Enterprise

Your MCP agent calls a partner's API and executes a $2M contract modification. The partner disputes authorization. Who's right?

Without Vane

Both sides have their own logs. Neither can verify the other's. Legal fees start at $400K. The relationship is over.

With Vane

The Vane passport carries the delegation chain. The modification was authorized by a specific human, at a specific time, with specific scope. Case closed.

Why cryptographic proof

A log file is a promise.
A signature is a proof.

01

Offline verification

Any party can verify any Vane attestation with only our public key. No API call. No uptime dependency. No trust in us required. The math is the guarantee.

02

Cross-organizational by design

Vane passports are verifiable by any party — inside or outside your organization. When Agent A calls Agent B across company boundaries, both sides hold cryptographic proof. No other solution provides this.

03

Tamper-evident by construction

Every attestation is anchored in a SHA-256 Merkle tree. Altering any record invalidates every record that came after it. An auditor can verify the entire history hasn't been touched.

The question is not whether agents need identity. The question is whether you'll have proof before something goes wrong. Vane.