The control plane for agentic AI trust.
Tesseral secures AI agents from creation through end of life: hardware-anchored identity, integrity-bound permissions, and temporal authorization — continuously re-verified at every interaction. Every action provable. Every delegation traceable to an accountable human. Built on the Gradient identity platform already proven in production.
payments.settle
Trust, rebuilt for a new kind of actor
Six mechanisms, one control plane — securing what an agent is, what it may do, and who answers for it.
Composite agent identity
An agent’s identity is a measurement of everything it actually is — we developed a composite identity to reflect this — capable of representing code, model weights, system prompt, and registered tools, in one identity. Change any of them, and the agent is, cryptographically, no longer itself.
Platform-anchored keys
Private keys are generated inside the hardware root of trust already in the host — cloud instance, server, laptop or GPU — and can never leave it. A stolen Tesseral credential works nowhere else, and expires anyway.
Continuous re-verification
Before every renewal, on a clock measured in minutes or less, the agent must re-prove its identity and integrity from the hardware up. Verification isn’t an onboarding event — it’s a heartbeat.
Agent Capability Tokens
Permissions are issued as short-lived tokens scoped to exactly the task at hand. A payments agent holds payment authority for the transaction window it needs — and not a second longer. Authorization becomes temporal, and verifiable at every interaction.
Governed delegation
Whether an agent may spawn sub-agents at all is a token-governed decision. Every child is strictly bounded to no more than its parent’s permissions, valid only as long as its parent’s remaining lifetime.
Provenance, end to end
Every delegation is cryptographically traceable back through sub-agent, to parent agent, to the human or team that originally authorized the work. Provenance is a property you verify — not one you take on faith.
Outcomes an AI-speed adversary can’t argue with
A stolen credential is worthless
It is bound to attested hardware, so it works nowhere else — and it expires, by design, within minutes. Not harder to abuse. Pointless to steal.
Tampering costs the credential
A modified binary, substituted weights, a poisoned prompt, an unauthorized tool — any of them fails the next attestation, and the agent’s authority ends automatically.
A rogue agent contains itself
Whether an agent goes off-script through emergent behavior or outside manipulation, its authority is capped at what its current token permits and expiring on its own. No scramble. No revocation lists.
An audit trail you can hand a regulator
Every action maps, in real time, to a specific agent, in a specific verified state, holding specific authority, under a named human owner. Forensics becomes lookup, not reconstruction.
Meets the highest tier of published guidance
The NSA-led Five Eyes guidance and Anthropic’s Zero Trust for AI Agents framework converge on the same top tier: identity cryptographically rooted in hardware with remote attestation, permissions scoped just-in-time to the task, and delegation with verifiable provenance. Tesseral meets or exceeds that bar on all three — it is the architecture the guidance describes.
A control plane, not a construction project
Tesseral works with the systems you already run — your identity provider, your directory, your network, your agent frameworks. Credentials are standard certificates your tools already understand, and deployment is incremental, without interrupting what’s running.
It plugs into your identity stack rather than standing in front of it: no data-path proxy, no TLS decryption, no latency tax. Your IdP stays the source of record.
Tesseral extends the same Gradient platform that secures human authentication — StealthMFA for your people, Tesseral for your agents. One attestation-driven architecture under both.
No proxy. No rip-and-replace.
One trust plane for every non-human identity
The same architecture that secures your agents secures your CI/CD pipelines, service accounts, and automated workloads. You’re not buying a point solution for the GenAI moment — you’re replacing the brittle machine-credential model across the enterprise.
Put a control plane under your agents
See Tesseral in a 30-minute working session.
Request Demo →