Engineers and AI agents
Your agents leave as anonymous cloud IPs.Fix that.
Your agents reason confidently about infrastructure they cannot see, and leave as anonymous cloud IPs you cannot tell apart.
Five questions your stack cannot answer.
Your agents share a cloud range and carry tokens that leak. Nothing in the stack can say what any one of them may reach.
- How many agents are running in here?
Nobody filed a ticket for the ones that matter.
- Who started this one?
The identity is in the payload. The connection carries none.
- What is it allowed to reach?
Your allowlist is addresses, and the infrastructure moves.
- Can you prove it never touched anything sanctioned?
You have logs of what you saw. You have no proof of what was prevented.
- Can you switch off one agent and leave the rest?
Not while they share an address.
An identity, and a leash, for every agent.
One address per agent
A routable IPv6 address from our own RIPE-allocated space, RPKI signed, with forward and reverse DNS in step.
Answers it can ground
Any MCP client queries real infrastructure mid-task, and can tell no data from known clean.
One call to revoke
Kill the identity and close its egress. The agent is off the network whether or not it still runs.
Anyone can check it.
A third party checks one of your agents with dig, whois and openssl. No account, and no Whisper service in the trust path.
Tied to whoever launched it
Every identity traces back to the person or system that created it, with the tree for sub-agents.
Policy in the terms you think in
Rules on sanctions, geography, Tor exits, new registrations and RPKI, applied at resolution and at egress.
Deployed with what you run
Intune, Jamf, Kandji, Omnissa or Hexnode, or a universal installer that does not care which.
Where to start building.
This job is set up once, so each card opens the guide for its part.
Ground an agent over MCP
Connect any MCP client once. It queries real infrastructure mid-task.
Give an agent an identity
One routable IPv6 address per agent, tied to whoever launched it.
Attributable egress for fleets
Every request leaves from an address whose record names you.
Issue and revoke identities
One call to issue an identity, and one to take it away.
Check it yourself.
Every kind of identity
Host, mobile, software agent, sub-agent, BYOD, OT and IoT.
Three tools to verify
dig, whois and openssl. You already have all three.
For a crawler operator
Every request arrives from an address whose registry record names the operator and the abuse contact. An origin checks that at its own edge, without calling us.