Govern every autonomous agent as a first-class identity.
Issue every agent a signed Agent Passport that pins its purpose, its tool ceiling, and an expiry — then watch its behavior, so an agent that starts acting outside its mandate is caught, not trusted by default.
- A signed Agent Passport per agent: scoped purpose, tool ceiling, and expiry — issued, not assumed
- Behavioral detection of agentic attacks — agents acting outside their granted mandate are flagged for your review
- Built on real standards: W3C Verifiable Credentials 2.0 and did:key, revocable via a Token Status List
Verify the agent supply chain.
Inventory every MCP server an agent can reach, see exactly which tools and credentials each one exposes, capture every tool-call, and govern what an agent is actually allowed to invoke.
- A live inventory of MCP servers and the tool + credential scope each one exposes
- Every tool-call captured — so the agent supply chain is auditable, not a black box
- Govern what an agent may invoke: pin its allowed tools to its Agent Passport ceiling
Find the identities that ship to prod before one breaks.
CI/CD tokens, OIDC trust policies, and pipeline service accounts are machine identities with production reach. TrustFix discovers them, shows their exact exposure, and proposes a fix that only narrows access — never widens it.
- Discover CI/CD tokens, OIDC trust relationships, and pipeline service accounts that reach prod
- See the exact exposure on a wildcard trust policy — which branches and repos can actually deploy
- A proposed fix you can ship as a pull request, scoped down to least privilege
Map who-can-reach-what across every cloud.
Roles, service accounts, and keys — discovered agentlessly with read-only access on AWS today (GCP and Azure connectors in preview), mapped into a graph of who can reach what, and scoped down to least privilege.
- Agentless, read-only discovery of roles, service accounts, and keys — live on AWS today, with GCP and Azure connectors in preview
- A reach graph that shows the real blast radius — not just the policy on paper
- Over-scoped paths surfaced and ranked by the exposure they actually create
Find the leaked credential — and the exact exposure on it.
Leaked, over-scoped, and unrotated credentials are the shortest path to a breach. TrustFix finds them, shows the precise access each one carries, and proves the fix only narrows that access.
- Surface leaked, over-scoped, and never-rotated credentials across your clouds and code hosts
- See the exact exposure on each one — the specific actions it grants and which go unused
- Tighten or rotate, then prove the change only narrowed access with a signed receipt
Turn live posture into auditor-ready evidence.
Map your live identity posture to SOC 2, ISO 27001, NIST, and the EU AI Act, then export it as signed evidence — in the open OSCAL format an auditor can verify offline, with no vendor in the loop.
- Live posture mapped to SOC 2, ISO 27001, NIST, and EU AI Act controls — not a point-in-time PDF
- Each control links to a real, signed, replayable artifact — not a screenshot
- Exportable as open, signed OSCAL, so evidence isn’t locked to one vendor’s format