Most vendors prove themselves with a wall of customer logos. We're new — so we prove ourselves with cryptography you can check, and breadth you can verify in our code.
Agents, pipelines, and service accounts run your company now. Almost none of them can prove what they’re allowed to do.
Identity tooling was built for humans logging in — usernames, MFA, who-did-what audit trails. The things making decisions today can’t be interviewed, can’t be MFA’d, and can’t show you their authority. TrustFix gives every one of them a signed, verifiable answer.
The operating model behind every screen and receipt — the principle, not a walkthrough. You’ll watch it run on a single identity below, and across your whole estate in the live graph.
Connect AWS, GCP, Azure, GitHub read-only — no agents, no keys to rotate. TrustFix inventories the IAM roles, service accounts, OAuth apps, AI agents, MCP servers, and workloads already running.
Each identity is bound to a purpose and a scope ceiling and issued an Agent Passport — a W3C Verifiable Credential signed with a did:key (eddsa-jcs-2022) and recorded as a hash-chained, Merkle-proofed entry in the Trust Ledger.
You get a signed Trust Receipt that verifies in-app or offline, with no TrustFix account. Where authority is too broad, TrustFix proposes a fix proven to only narrow access — and re-attests once it lands.
Every identity TrustFix attests becomes an append-only, signed entry — issuer did:key, principal, scope, sequence. Hash-chained and Merkle-proofed, so any entry can be opened and verified independently.
The same discover → prove → seal loop the live graph runs across your whole estate — slowed down to a single principal, one stage at a time.
A new agent shows up in your cloud — no human will ever log in as it.
Every step above is real: 200+ finding types, verified delegation authority, an engine-verified PR, and a signed, independently verifiable ledger receipt. Nothing here is a mockup of a feature we don’t ship.
For forty years, security was built around one idea: humans log in. Usernames. Passwords. MFA. Audit trails of who-did-what.
That idea is now obsolete. Your Bedrock agent runs as a service account. Your CI pipeline writes to production as a machine. Your Claude MCP server signs transactions. The humans left the loop years ago.
TrustFix is what you build when you accept that every critical decision in your company is now made by something that can’t be interviewed, can’t be fired, and can’t explain itself. We built the registry.
Not phished passwords — leaked tokens, forgotten OAuth apps, unrotated service accounts, stolen signing certs. The machine identities nobody was watching. Real, public incidents; click any to read the source.
Sourced from vendor postmortems, CISA, and reputable security press. TrustFix inventories, proves, and governs exactly these identities — and tells you, with signed proof, the moment one steps out of line.
Every tool in your SOC today answers a question about humans. None answers the question “which of my 50,000 machine identities can reach your production payments system, right now?”
TrustFix is not a dashboard. It is four precision instruments, each built for one job, composed into a single institutional workflow.
Most tools stop at the alert. TrustFix decides — allow, mediate, or deny — and signs every verdict into the ledger. No queue to triage. Just provable allow or deny, with the proof attached.
Eight behavior detectors watch your non-human identities for machine-speed attack patterns — not static misconfiguration. Every finding lands on the signed agent-event feed and exports to your SIEM as OCSF: correlation you can trace back to a receipt, not a black-box score.
Detection and notification — you decide the response.
This is a real Agent Passport, serialized as a W3C Verifiable Credential with an eddsa-jcs-2022 proof and a did:key issuer. The subject is an illustrative sample — the cryptography is genuine. Verify the signature right here, in your browser. Offline. No account.
The math runs locally with @noble Ed25519/SHA-256 and the issuer’s did:key — no call to TrustFix. Change a single character above and the signature stops verifying.
Most tools assert that a change is safe. TrustFix issues a signed proof — on open standards — that an auditor, a regulator, or a rival can verify themselves, offline.
Every agent identity is a W3C VC with an eddsa-jcs-2022 proof — it verifies in any standards-compliant verifier, not just ours.
Each delegated grant emits a signed receipt proving the hop only grants what it needs — and showing exactly which hops it refuses. Verifies offline.
An agent’s standing is a public, signed status bitstring. Check whether authority was revoked without ever calling us.
Export signed Assessment Results where every control points to a signed, tamper-evident ledger entry an auditor can independently replay.
Agent and identity events are exportable as schema-1.3 OCSF records (retrievable via the events API), each anchored to the signed ledger.
The issuer is a resolvable did:key. The signatures keep verifying offline, with zero dependency on TrustFix staying online.
Connect your estate once — agentless and read-only. TrustFix is built to discover, prove, and govern every non-human identity across cloud, code, CI/CD, AI agents, MCP, IaC, and on-prem — with live discovery shipping connector by connector (AWS and GitHub today, the rest wiring in progress below).