TRUSTFIX · NON-HUMAN IDENTITY SECURITY
— LIVE · SIGNED TRUST LEDGER —
2026-04-24 · 14:00:00 UTC
Non-Human Identity Security · 2026

The identitiesrunning yourcompany are not human.

Service accounts. IAM roles. OAuth apps. AI agents. MCP servers.
They already outnumber your people. And nobody — until now — has been running the registry.

CONNECTS TO THE STACK YOU ALREADY RUN
LIVE · SIGNED TRUST MANIFEST · LEDGER.v2
TRUSTFIX · SIGNED AGENT PASSPORT
Agent Passport
Non-human principal · verified · ephemeral
SUBJECT
bedrock-agent-prod.meridian-north.aws
Signature
0x7f3c9a2e4b8d1c6f
Scope
iam:* → s3:GetObject/analytics-*
TTL
sts:15m · single-use · ephemeral
Baseline
within envelope · no drift detected
Ledger receipt
#RXP-2026-41204 · offline-verifiable
✓ SIGNATURE VERIFIES OFFLINE
Signed by org authority key · no trust in us required
Every identity on TrustFix gets one.
Signed. Replayable. Auditable by anyone, offline.
THE GATEallow · mediate · deny
TRUST LEDGERsigned + tamper-evident
AGENT PASSPORTsigned authority
BLAST RADIUSranked in $
TRUST MANIFESTsigned export
DELEGATIONauthority verified to only narrow
TIME-TO-FIXengine-verified
STANDARDSA2A · AAT · VC
MCP SUPPLY CHAINdrift-monitored
AGENTIC ATTACKS8 behavior detectors
SECRETLESS ISSUANCEproof-carrying · short-lived
THE GATEallow · mediate · deny
TRUST LEDGERsigned + tamper-evident
AGENT PASSPORTsigned authority
BLAST RADIUSranked in $
TRUST MANIFESTsigned export
DELEGATIONauthority verified to only narrow
TIME-TO-FIXengine-verified
STANDARDSA2A · AAT · VC
MCP SUPPLY CHAINdrift-monitored
AGENTIC ATTACKS8 behavior detectors
SECRETLESS ISSUANCEproof-carrying · short-lived
THE GATEallow · mediate · deny
TRUST LEDGERsigned + tamper-evident
AGENT PASSPORTsigned authority
BLAST RADIUSranked in $
TRUST MANIFESTsigned export
DELEGATIONauthority verified to only narrow
TIME-TO-FIXengine-verified
STANDARDSA2A · AAT · VC
MCP SUPPLY CHAINdrift-monitored
AGENTIC ATTACKS8 behavior detectors
SECRETLESS ISSUANCEproof-carrying · short-lived
Don't take our word for it

Most vendors prove themselves with a wall of customer logos. We're new — so we prove ourselves with cryptography you can check, and breadth you can verify in our code.

10
Open standards
signed · served · offline-verifiable
65
Integrations built in code
no aspirational logos · AWS + GitHub live today
14
NHI breaches tracked
every one a non-human identity
Anyone
Can verify a receipt
offline · no TrustFix account
DISCOVER · PROVE · SEAL
01 · Discover
See every non-human identity.

Service accounts, IAM roles, OAuth apps, AI agents and MCP servers across AWS, GCP, Azure, GitHub, GitLab and Bitbucket — mapped into one live graph of who can reach what.

02 · Prove
Prove the fix is safe.

Every remediation is verified to only remove access — never add it — before a pull request is ever opened. We prove it; we don’t just assert it.

03 · Seal
Seal it into the ledger.

Every decision is sealed into a signed, append-only Trust Ledger that an auditor, a regulator, or a rival can verify offline — with no TrustFix account.

THE PROBLEM

Agents, pipelines, and service accounts run your company now. Almost none of them can prove what they’re allowed to do.

Identity tooling was built for humans logging in — usernames, MFA, who-did-what audit trails. The things making decisions today can’t be interviewed, can’t be MFA’d, and can’t show you their authority. TrustFix gives every one of them a signed, verifiable answer.

THE ATTESTATION ENGINE

Every non-human identity, sealed.

Service accounts, IAM roles, API keys, containers, webhooks, CI tokens, functions, workloads, MCP servers, AI agents. Each becomes a signed Agent Passport — bound to a purpose and a scope ceiling, recorded in the signed Trust Ledger.

SEAL
AI AGENT
CLOUD IAM
SERVICE ACCT
CONTAINER
WORKLOAD
API KEY
WEBHOOK
CI TOKEN
FUNCTION
MCP SERVER
OAUTH APP
SECRET
ONE SIGNED AUTHORITY PER PRINCIPAL · ANCHORED IN THE TRUST LEDGER
THE METHOD

Discover. Prove. Seal.

The operating model behind every screen and receipt — the principle, not a walkthrough. You’ll watch it run on a single identity below, and across your whole estate in the live graph.

01
DISCOVER
Map every non-human identity

Connect AWS, GCP, Azure, GitHub read-only — no agents, no keys to rotate. TrustFix inventories the IAM roles, service accounts, OAuth apps, AI agents, MCP servers, and workloads already running.

AGENTLESS · READ-ONLY
02
PROVE
Issue a cryptographic authority

Each identity is bound to a purpose and a scope ceiling and issued an Agent Passport — a W3C Verifiable Credential signed with a did:key (eddsa-jcs-2022) and recorded as a hash-chained, Merkle-proofed entry in the Trust Ledger.

did:key · W3C VC · MERKLE LEDGER
03
SEAL / REMEDIATE
Hand over a receipt anyone can verify

You get a signed Trust Receipt that verifies in-app or offline, with no TrustFix account. Where authority is too broad, TrustFix proposes a fix proven to only narrow access — and re-attests once it lands.

OFFLINE-VERIFIABLE · SCOPE-NARROWINGTrust Receipt signed
THE SEALED LEDGER

A living registry of signed authority.

Every identity TrustFix attests becomes an append-only, signed entry — issuer did:key, principal, scope, sequence. Hash-chained and Merkle-proofed, so any entry can be opened and verified independently.

TRUST LEDGER · APPEND-ONLY · SIGNED
ILLUSTRATIVE REGISTRY
AI AGENT
urn:trustfix:agent:fraud-analysis-agent
iss did:key:z6MkkBgR…MkM9SP · seq #20418
SEALED
CLOUD IAM
arn:aws:iam::402194:role/payments-batch
iss did:key:z6MkwLNB…xdXdej · seq #20402
SEALED
CI TOKEN
github://meridian-pay/ledger-svc
iss did:key:z6MktUYz…D6hASX · seq #20389
SEALED
CONTAINER
k8s://prod/ingest-worker-7f9c
iss did:key:z6MksWj1…Jpaqpx · seq #20377
SEALED
WEBHOOK
webhook://stripe/payouts.settled
iss did:key:z6MknSUi…8dWCHs · seq #20361
SEALED
FUNCTION
lambda://reconcile-eod
iss did:key:z6MkoSWf…sb54nm · seq #20344
SEALED
WORKLOAD
gcp://analytics/dbt-runner
iss did:key:z6Mkszs9…Au5m4m · seq #20330
SEALED
SECRET
vault://meridian/db-replica-ro
iss did:key:z6Mkj2gk…SDpu3Q · seq #20317
SEALED
SAMPLE DATA · NO LIVE COUNTS SHOWN · EACH ROW IS A SIGNED, INDEPENDENTLY VERIFIABLE LEDGER ENTRY
THE REGISTRY, LIVE

Mapping the risk is table stakes. We prove the fix — and seal it.

Your entire estate as one continuously-updated graph — every identity and every reachable path at once. Below, we slow the same loop down to a single identity.

LIVE · NON-HUMAN IDENTITY GRAPH
DISCOVERDiscovering non-human identities
AI AgentSvc AcctIAM RoleMCPCrown jewel

Most tools stop at the map. TrustFix catches the toxic path, proves the fix only ever removes access — never adds it — and seals a receipt anyone can verify for themselves, even without us.

ONE IDENTITY · END TO END

Follow one non-human identity — from first sighting to sealed receipt.

The same discover → prove → seal loop the live graph runs across your whole estate — slowed down to a single principal, one stage at a time.

Discover
Scan
Flag
Prove
Fix
Seal
DISCOVER
A non-human principal appears

A new agent shows up in your cloud — no human will ever log in as it.

bedrock-agent-prod · non-human · aws

Every step above is real: 200+ finding types, verified delegation authority, an engine-verified PR, and a signed, independently verifiable ledger receipt. Nothing here is a mockup of a feature we don’t ship.

THE THESIS
“Trust is not a toggle. It is a ledger.”
THE FOUNDING DOCTRINE

For forty years, security was built around one idea: humans log in. Usernames. Passwords. MFA. Audit trails of who-did-what.

That idea is now obsolete. Your Bedrock agent runs as a service account. Your CI pipeline writes to production as a machine. Your Claude MCP server signs transactions. The humans left the loop years ago.

TrustFix is what you build when you accept that every critical decision in your company is now made by something that can’t be interviewed, can’t be fired, and can’t explain itself. We built the registry.

In the newsTHREAT FEED

Every breach here was a non-human identity.

Not phished passwords — leaked tokens, forgotten OAuth apps, unrotated service accounts, stolen signing certs. The machine identities nobody was watching. Real, public incidents; click any to read the source.

IN FOCUSMay 2026· CISA / DHS (via Nightwing contractor)
CISA contractor leaked AWS GovCloud admin keys in a public GitHub repo for ~6 months
Administrative credentials for three AWS GovClouRead the source
May 2026Extended-Validation code
DigiCert social-engineered into issuing EV code-signing certs later used to sign malware
DigiCert and EV code-signing subscribers (incl. Lenovo, Kingston, Shuttle, Palit)
Apr 2026MCP servers — the creden
Model Context Protocol design flaw exposes thousands of MCP servers to remote code execution
The AI-agent ecosystem (7,000+ publicly reachable MCP servers; ~200k vulnerable instances)
Apr 2026A Google Workspace OAuth
Vercel breached via an "Allow All" OAuth grant to a compromised third-party AI tool
Vercel and a subset of its customers
Feb 2026Stolen system/service cr
AI-assisted attacker breaches nine Mexican government agencies, exfiltrating taxpayer records
Mexican federal, state and municipal agencies including the tax authority (SAT)
Nov 2025Stolen npm publish token
Shai-Hulud 2.0: self-replicating npm worm compromises ~500 packages, leaks secrets across 25k+ repos
npm ecosystem incl. packages from Zapier, PostHog, Postman, AsyncAPI, ENS
Nov 2025OAuth access and refresh
Gainsight Salesforce OAuth integration abused to access data at hundreds of companies
Salesforce customers using Gainsight apps (ShinyHunters / UNC6240)
Nov 2025Agent credentials and to
Anthropic disrupts GTG-1002 — the first reported large-scale AI-orchestrated espionage campaign
~30 global targets (tech firms, financial institutions, chemical makers, government agencies)
Nov 2025Long-lived AWS IAM user
Compromised AWS IAM credentials power a large EC2/ECS crypto-mining campaign
AWS customers running EC2 and ECS

Sourced from vendor postmortems, CISA, and reputable security press. TrustFix inventories, proves, and governs exactly these identities — and tells you, with signed proof, the moment one steps out of line.

THE GAP

Your existing stack was built for humans.

Every tool in your SOC today answers a question about humans. None answers the question “which of my 50,000 machine identities can reach your production payments system, right now?”

TOOL 01
CSPM / CNAPP
Answers: Cloud misconfigs
Misses: the identities behind them
e.g. Wiz · Orca · Palo Alto
TOOL 02
IAM / IdP
Answers: Who the humans are
Misses: everything that isn't human
e.g. Okta · Entra · Ping
TOOL 03
Secret scanner
Answers: Where keys leaked
Misses: what the keys unlock
e.g. GitGuardian · TruffleHog
TOOL 04
SIEM / XDR
Answers: What already broke
Misses: what's about to
e.g. Splunk · Sentinel · CrowdStrike
THE ANSWER
TrustFix
The registry for non-human identity. Every agent, NHI, and MCP — discovered, verified, and governed with signed receipts for every decision.
Pre-launch
Built for the agent era
THE INSTRUMENTS

Four instruments. One registry.

TrustFix is not a dashboard. It is four precision instruments, each built for one job, composed into a single institutional workflow.

INSTRUMENT 01
The Ledger.

Every policy change, every Gate decision, every rotation — written to an append-only, signed ledger. Every number you see in TrustFix is clickable back to its receipt. Prove, don’t promise.

append-only
hash-chained
Cryptographically signed
tamper-evident
independently
verify offline
The Gate · Runtime Enforcement

Every identity,
decided in real time.

Most tools stop at the alert. TrustFix decides — allow, mediate, or deny — and signs every verdict into the ledger. No queue to triage. Just provable allow or deny, with the proof attached.

6
ALLOW PATTERNS
2
MEDIATE PATTERNS
2
DENY PATTERNS
See The Gate →
trustfix · decision-log
region us-east-1
16:08:26svc:checkout-agent · call from a new regionBLOCKED
16:08:24agent:fraud-model · broaden delegation chainMEDIATED
16:08:22svc:batch-runner · assume role · external-id okVERIFIED
16:08:20agent:doc-summarizer · re-attest authorityVERIFIED
16:08:18svc:checkout-agent · escalate scope → admin:*BLOCKED
16:08:16agent:route-planner · delegate · 1 hop · narrowsVERIFIED
16:08:14mcp:github · tool drift vs signed baselineMEDIATED
Illustrative — the decision types The Gate emits. Your stream is yours, and every row is signed.
DETECTION

Built to catch how AI agents actually attack.

Eight behavior detectors watch your non-human identities for machine-speed attack patterns — not static misconfiguration. Every finding lands on the signed agent-event feed and exports to your SIEM as OCSF: correlation you can trace back to a receipt, not a black-box score.

01Reconnaissance bursts

A read fan-out beyond the agent’s own attested scope — the recon phase before an attack, that no per-action rule sees.

02Tool-abuse chains

Individually-allowed calls composed over the crown-jewel graph to a sensitive sink — what per-call gateways structurally cannot catch.

03Autonomous privilege escalation

Enumerate → grant-self → assume → reach a crown jewel, bound to faster-than-human timing and a before/after reachability delta.

04Delegation bursts

A change-point in how many principals an agent suddenly acts for — over a signed, tamper-evident delegation series.

05Injection → action

An MCP tool-poisoning event causally joined to a later out-of-baseline action by a consuming agent (OWASP ASI01), across two signed surfaces.

06Multi-agent campaigns

NHIs acting in concert — clustered by shared infrastructure fingerprint and fused with the signed delegation graph.

07AI-tool fingerprinting

Non-human call cadence against an agent’s attested baseline — forward-looking detection of autonomous offensive tooling. Conservative by design.

08Denied-spray → success pivot

A burst of AccessDenied probes followed by a success on a just-denied target — the loud NHI-compromise tell that discarded deny-logs normally hide.

Every detector is a pure, unit-tested engine that emits a signed, ledger-provenanced event — so even a risk no one can auto-fix is something you’re told about, with proof, the moment it happens.

Detection and notification — you decide the response.

THE ARITHMETIC · ILLUSTRATIVE EXAMPLE

What reducing blast radius looks like in dollars.
An illustrative example — here’s the math.

BLAST RADIUS · BEFORE → AFTERILLUSTRATIVE
Before — reachable sensitive data100%
After the proven, scope-narrowing fix18%
Relative reach, shown for illustration — not a customer figure. Every fix is proven to only narrow access, never widen it.
Sensitive data in blast radius (before)
over-broad grant → sensitive store
Wide
Fix applied
dry-run replayed · no breakage
Scoped
Sensitive data in blast radius (after)
access narrowed, never widened
Narrow
Regulatory exposure
fewer records reachable = less to lose
Lower
Signed receipt
tamper-evident · cryptographically signed
Issued
Dry-run
Validated before merge
replayed against real traffic
Signed
Engine-verified fix
proven to only narrow access
Signed
Evidence bundle
on demand
Signed
Tamper-evident ledger
verify every receipt offline
OUR DESIGN TEST
A security product a board reads instead of tolerates — that is the bar every screen and receipt is built to.
The board-legible test
EVERY SCREEN · EVERY RECEIPT
HOW IT WORKS

Connect in 5 minutes.
First fix in 10.

01
Connect
2 min
One-click AWS, GCP, Azure, GitHub. Read-only. No agents. No keys to rotate.
02
Discover
7 min
Every identity mapped — IAM roles, service accounts, OAuth apps, AI agents, MCP servers, certificates.
03
Verify
Verified safe
Every proposed fix is verified to only narrow access before it reaches you — and toxic combinations across identities are surfaced, not just single findings.
04
Fix
1 PR
Validated Terraform PR opened in your repo. Proven to only narrow access. Merge when ready.
HOW WE COMPARE

The NHI platform that
fixes what it finds.

Capability
Posture tools
NHI inventory
Secrets vaults
TrustFix
RECOMMENDED
Discovery
AI Agent Security
MCP Server Detection
Auto-Remediation (IaC)
Terraform Fix PRs
Independent Fix Verification
Toxic Combination Detection
Compliance Evidence Export
Discovery is everywhere. Proven, sealed remediation is not.
Category-level view of typical offerings (2026). Specific capabilities vary by vendor and tier.
Head-to-head · 01
TrustFix vs find-only tools
Find-only tools stop at the alert. We close it.
Head-to-head · 02
TrustFix vs Manual Audit
A signed ledger, not a PDF.
VERIFY IT YOURSELF

Don’t trust us. Run the math.

This is a real Agent Passport, serialized as a W3C Verifiable Credential with an eddsa-jcs-2022 proof and a did:key issuer. The subject is an illustrative sample — the cryptography is genuine. Verify the signature right here, in your browser. Offline. No account.

agent-authority.vc.json
{
"@context": [
"https://www.w3.org/ns/credentials/v2",
"https://trustfix.dev/credentials/agent-authority/v1"
],
"type": [
"VerifiableCredential",
"AgentAuthorityCredential"
],
"issuer": "did:key:z6MkhNa7rXnHsN53oRoUdNaNZ3hbBNvdaZ8FiRQ8vYF2sWkN",
"validFrom": "2026-06-01T00:00:00.000Z",
"validUntil": "2026-08-30T00:00:00.000Z",
"credentialSubject": {
"id": "arn:aws:iam::402194:role/meridian-fraud-agent",
"type": "AIAgent",
"agentRef": "fraud-analysis-agent",
"purpose": "read-only payments fraud analysis",
"authorizedTools": [
"payments-query-mcp",
"s3:GetObject/analytics-*"
],
"scopeCeiling": "read-only · payments-query-mcp",
"delegationDepthMax": 1,
"issuedBy": "security@meridian-pay.example"
},
"credentialStatus": {
"id": "https://trustfix.dev/api/status-list/meridian-pay#47",
"type": "BitstringStatusListEntry",
"statusPurpose": "revocation",
"statusListIndex": "47",
"statusListCredential": "https://trustfix.dev/api/status-list/meridian-pay"
},
"trustfixAuthority": {
"passportId": "le_3Qd1Xk2mAa9fZ7",
"ledgerSeq": 20418,
"inclusionVerified": true,
"notRevoked": true,
"verifyUrl": "https://trustfix.dev/agent-passport/le_3Qd1Xk2mAa9fZ7"
},
"proof": {
"type": "DataIntegrityProof",
"cryptosuite": "eddsa-jcs-2022",
"created": "2026-06-01T00:00:00.000Z",
"verificationMethod": "did:key:z6MkhNa7rXnHsN53oRoUdNaNZ3hbBNvdaZ8FiRQ8vYF2sWkN#z6MkhNa7rXnHsN53oRoUdNaNZ3hbBNvdaZ8FiRQ8vYF2sWkN",
"proofPurpose": "assertionMethod",
"proofValue": "z5sFSE4quKXyTXAufsihEw1roWztpNLehZXm4gtZjf99JYQhbJkqVjPPvqhMBaPix6Xb5nqr7HN55eQfKiMMkudmu"
}
}
OFFLINE VERIFIER · IN YOUR BROWSER
Check the signature
W3C VC 2.0 contextCONTEXT
AgentAuthorityCredential typeTYPE
Issuer is a resolvable did:keyISSUER
Revocation = Bitstring Status ListSTATUS
eddsa-jcs-2022 Ed25519 signaturePROOF
AWAITING VERIFICATION

The math runs locally with @noble Ed25519/SHA-256 and the issuer’s did:key — no call to TrustFix. Change a single character above and the signature stops verifying.

VERIFIABLE BY ANYONE

Don’t take our word for it. Take the proof.

Most tools assert that a change is safe. TrustFix issues a signed proof — on open standards — that an auditor, a regulator, or a rival can verify themselves, offline.

W3C Verifiable Credential 2.0Agent Passport

Every agent identity is a W3C VC with an eddsa-jcs-2022 proof — it verifies in any standards-compliant verifier, not just ours.

OFFLINE-VERIFIABLE · NO ACCOUNT NEEDED
IETF Delegation ReceiptEvery hop

Each delegated grant emits a signed receipt proving the hop only grants what it needs — and showing exactly which hops it refuses. Verifies offline.

OFFLINE-VERIFIABLE · NO ACCOUNT NEEDED
W3C Bitstring Status ListRevocation

An agent’s standing is a public, signed status bitstring. Check whether authority was revoked without ever calling us.

OFFLINE-VERIFIABLE · NO ACCOUNT NEEDED
NIST OSCAL 1.1.2Evidence

Export signed Assessment Results where every control points to a signed, tamper-evident ledger entry an auditor can independently replay.

OFFLINE-VERIFIABLE · NO ACCOUNT NEEDED
OCSF Detection FindingsYour SIEM

Agent and identity events are exportable as schema-1.3 OCSF records (retrievable via the events API), each anchored to the signed ledger.

OFFLINE-VERIFIABLE · NO ACCOUNT NEEDED
did:key · Ed25519Forever

The issuer is a resolvable did:key. The signatures keep verifying offline, with zero dependency on TrustFix staying online.

OFFLINE-VERIFIABLE · NO ACCOUNT NEEDED
Coverage · every non-human identity

One read-only connection. Every non-human identity.

Connect your estate once — agentless and read-only. TrustFix is built to discover, prove, and govern every non-human identity across cloud, code, CI/CD, AI agents, MCP, IaC, and on-prem — with live discovery shipping connector by connector (AWS and GitHub today, the rest wiring in progress below).

Service accountsIAM & cloud rolesOAuth appsAI agentsMCP serversCI/CD tokensStatic access keysSAML & OIDC trustWorkload identitiesFederated identitiesWebhooks & botsIaC resourcesActivity logsOn-prem sensors…and built for the AI models and agents that don't exist yet.
The stack you connect
65 code-backed integrations in the catalog — a curated sample below, never an aspirational logo.
Clouds · agentless, read-only
Amazon Web ServicesAmazon Web Services
Google CloudGoogle Cloud
Microsoft AzureMicrosoft Azure
Source control & CI/CD
GitHubGitHub
GitHub ActionsGitHub Actions
GitLabGitLab
BitbucketBitbucket
Infrastructure as code
Formats we parse through the cloud + repo grants — not a "connect this vendor" integration.
TerraformTerraform
CFCloudFormation
Realtime & on-prem
AWS CloudTrail, GCP Audit Logs, Azure Activity Logs and repo events stream in close-to-real-time.
KubernetesKubernetes
VaultHashiCorp Vault
ADActive Directory
AI agents & MCP
Agent frameworks — LangChain, CrewAI, OpenAI, Anthropic — are recognized by traffic fingerprint, not ingested.
BRAWS Bedrock
MCPMCP
ITSM · bidirectional ticketing
JiraJira
SNServiceNow
PagerDutyPagerDuty
SIEM & observability · signed event export (OCSF · CEF · ECS)
SplunkSplunk
DatadogDatadog
ELElastic
WHWebhook
Notifications
SlackSlack
@Email
WHWebhook
Built on open standards

Conformant to the standards that govern machine trust.

Signed, served, and offline-verifiable — no proprietary lock-in.
W3C Verifiable Credential 2.0did:keyNIST OSCALOCSF 1.3A2A Agent CardIETF AATIETF Delegation ReceiptToken Status ListCycloneDX & SPDX (AI-BOM)JWKS / .well-known
Agentless and read-only. Every logo here is real and code-verified — never aspirational.
Don't see yours? Request a connector →
Start now

Stop finding.
Start fixing.

Connect your first platform in two minutes. Request a demo to see TrustFix run on your environment.

Launch app Book a CISO briefing
SOC 2 evidence exportRead-only accessHuman approval requiredCustom enterprise terms
TrustFix — Non-Human Identity Security Platform