The verifiable authority layer for non-human and AI-agent identity. TrustFix proves what an identity may do — signed agent passports, a tamper-evident Trust Ledger, engine-verified fixes — and (optionally) enforces it. Start with the platform quick start, or run the open-source CLI.
The verifiable authority layer for non-human and AI-agent identity — a platform that proves what an identity may do, and (optionally) enforces it.
Zero to your first signed fix: connect your estate, discover, find your highest-consequence risk, let the engine verify a fix, and get a signed receipt.
Read-only, agentless grants for AWS, GitHub, GCP, and Azure — least-privilege by construction, with no agent to install.
Two ways to bring your non-human identities into TrustFix — the agentless API connectors (no install) or the read-only on-prem sensor (data stays inside your network). Both converge on the same findings, the same platform.
Issuing and signing what an identity may do up front — and degrading honestly to a reviewed suggestion when the proof can't be run.
A signed, publicly verifiable grant naming what an agent may do — and revocable in one signed kill-switch entry.
A continuous, signable, offline-verifiable per-agent trust score — a deterministic blend of real signals, coverage-honest by design.
Per-hop proof that delegated authority only ever narrowed — attested only when proven, observed when it can't be. Currently a PREVIEW screen.
Individually-tolerable findings that together open a real attack path — deduplicated and risk-scored by the engine, so you fix the path, not the noise.
Per-credential correlation of rotation, usage, privilege, and exposure into one profile — confirmed only when risk and exposure share the same credential id.
Trust treated as something that decays — an exponential half-life per identity class and an operational re-attestation worklist.
An append-only, Ed25519-signed, hash-chained ledger with Merkle inclusion proofs — re-verified on every load, and offline-verifiable by anyone.
Audit-grade evidence generated, not gathered — real signed artifacts mapped onto the controls auditors ask for, with empty controls shown honestly.
The Index, Trust Graph, Counter-Factual, Risk Heatmap, Toxic Combinations, Credential Leaks, Issuance, Lineage, and the born-verified Agent Authority and Agent Trust screens.
The Consequence Queue and Remediation Dry-Run — triage open findings and run the same engine that gates every shipped fix, with no side effects on preview.
The Gate records real PIE fix-gate verdicts as signed decisions; Trust Boundaries treats your settings as policy, with mutations routed through a separate signed flow.
Evidence, Trust Ledger, Time Travel, and Board Brief — the proof layer: signed artifacts mapped to controls, an append-only ledger, posture replay, and an executive summary.
Discovery and Integrations for connector health, Analyze IaC for ad-hoc analysis, and the Admin Portal with a ledger-anchored audit trail.
On the roadmap: Delegation Provenance, Attribution, Agent Baselines, MCP Supply Chain, and Federated Intel — real engines whose live capture/federation legs are not yet wired.
Scan your AWS IAM roles for GitHub Actions OIDC misconfigurations from your terminal in minutes — open source, no account required.
Run TrustFix's OIDC scanner locally — open source, no account required. Flags, options, and CI integration.
The OIDC trust-policy misconfigurations the open-source oidc-audit CLI detects in GitHub Actions roles — what each finding means, and how to fix it.
Run the open-source CLI now, or talk to us about the platform.