Offline verification
Any party can verify any Vane attestation with only our public key. No API call. No uptime dependency. No trust in us required. The math is the guarantee.
Encrypted transport for the web. Nobody trusted plaintext anymore. The internet got its first cryptographic handshake.
Became infrastructureCryptographic identity for machines. Servers could prove who they were. Human passwords gave way to keypairs.
Became infrastructureDelegated authorization for applications. Apps could act on behalf of users with scoped, revocable permission.
Became infrastructurePortable identity tokens for services. Microservices could verify each other without a central directory.
Became infrastructureNever trust, always verify. The network perimeter died. Identity became the only perimeter that mattered.
Became infrastructureAutonomous software acts, transacts, and decides. Nobody built cryptographic trust infrastructure for agents. Until now.
VaneThe US Commerce Secretary ordered Anthropic to shut down Fable 5 — the most capable AI model ever released — effective immediately. Reason: nobody could verify who was accessing it.
What happens when your agents do something nobody can prove was authorized?
Your trading agent executes $47M in positions over 6 hours. The SEC opens an inquiry. Your legal team asks: who authorized each trade?
You have server logs. Timestamps. IP addresses. The SEC wants cryptographic proof of authorization. You cannot provide it.
Every trade carries an Ed25519-signed attestation. Authorization chain is cryptographically provable in court. Inquiry closed in 72 hours.
Your clinical AI agent accessed 12,000 patient records over 3 months. A HIPAA audit begins. The question: was each access authorized?
Your access logs were stored in the same system the agent used. The auditor cannot verify they weren't modified. You face a $1.9M fine.
Every PHI access is attested with a cryptographic receipt. Immutable. Independently verifiable. The audit takes 4 hours, not 4 months.
Your MCP agent calls a partner's API and executes a $2M contract modification. The partner disputes authorization. Who's right?
Both sides have their own logs. Neither can verify the other's. Legal fees start at $400K. The relationship is over.
The Vane passport carries the delegation chain. The modification was authorized by a specific human, at a specific time, with specific scope. Case closed.
Any party can verify any Vane attestation with only our public key. No API call. No uptime dependency. No trust in us required. The math is the guarantee.
Vane passports are verifiable by any party — inside or outside your organization. When Agent A calls Agent B across company boundaries, both sides hold cryptographic proof. No other solution provides this.
Every attestation is anchored in a SHA-256 Merkle tree. Altering any record invalidates every record that came after it. An auditor can verify the entire history hasn't been touched.