Authority infrastructure for AI agents and autonomous systems

The authority layer
for AI agent actions.

Authority for AI agents at the policy layer. A firewall for AI agent actions at the execution boundary.

Fidacy is the execution firewall for payments, refunds, supplier changes and binding communications made by AI agents. Define what any agent may do, block what exceeds its mandate and independently prove every consequential action.

DEPLOYED TODAYAI AGENTSIN DEVELOPMENTPHYSICAL AI
ONE BOUNDARY · EVERY AI AGENT STACK

Works with the AI agents and frameworks your teams already run.

Native integrations where available. Universal coverage through MCP, SDK and API — without moving private prompts, files or tool arguments outside your environment.
Native integrationMCP hostSDK / API
Claude CodeNative plugin
OpenClawNative plugin
LangChainNative · JS + Python
OpenAI AgentsNative adapter
Vercel AI SDKNative middleware
MCPFidacy MCPUniversal server
CodexMCP host
CursorMCP host
Gemini CLIMCP host
GitHub CopilotMCP host
WindsurfMCP host
Hermes AgentMCP + hooks
OpenCodeMCP host
ClineMCP host
CrewAISDK / API
PydanticAISDK / API
Cloudflare AgentsSDK / API
Strands AgentsSDK / API
Microsoft Agent FrameworkSDK / API
Google ADKSDK / API
GrokBotAPI agent
ANY CUSTOM AGENTSDKAPIMCPUCPAP2A2ASTRIPEBREXGITHUBBITCOINPAYMENTSREFUNDSCRMEMAILFILESINFRASTRUCTURE
From AI agents to autonomous systems

One authority architecture.From AI agents to autonomous machines.

Fidacy already implements the core authority chain in software: identity, signed mandates, pre-action decisions, enforceable grants, revocation and independently verifiable evidence.

DEPLOYED TODAY

AI AGENT ACTIONS

Money · data · communications · enterprise systems

CORE ARCHITECTURE REUSE≈90%

Already implemented at the software authority layer.

IN DEVELOPMENT NOW

EDGE AUTHORITY

Gateway · device identity · local enforcement · safety validation

Fidacy authority gateway connecting an AI system to a robot, drone and autonomous vehicle
NEXT PRODUCT LAYERFIDACY EDGE AUTHORITY GATEWAY

Mission-level authority for robots, drones, vehicles and safety-critical autonomous infrastructure, without entering the motor-control loop.

≈90% is an architecture-reuse estimate, not physical-product readiness or safety certification.

Intelligence decides what to do.Authority decides whether it may happen.

Elegant by architecture

The most powerful infrastructure does not add complexity. It removes uncertainty.

Fidacy turns identity, authorization, enforcement and evidence into one compact authority layer between an AI agent and the real world.

Enterprise team working confidently with AI in a calm, collaborative workplace
Govern the agent.Keep the team free.
01 / AUTHORIZE

Bind the payment, not just the agent.

Fix the identity, action, payee, amount, invoice, policy, expiry and delegation depth.

02 / ENFORCE

Make the boundary impossible to ignore.

A connected executor refuses an altered payee, excessive amount or side effect without one matching grant.

03 / PROVE

Leave evidence outside the argument.

Every ALLOW, REVIEW and DENY is signed, hash-chained and independently verifiable.

Protected workflows

Control the actions that create economic exposure.

01 / REFUNDS

Resolve the case.
Not an unlimited credit.

Bind the customer, request, policy and value limit before a refund or customer commitment is released.

stripe.refund.createGATED
02 / PAYMENTS

Pay the supplier.
Not a changed IBAN.

Spend Guard binds payee, amount, invoice, currency and approval threshold before settlement.

payment.transferGATED
03 / ERP AND CRM

Move the workflow.
Not the whole database.

Supplier changes, CRM exports and critical updates stop when scope, destination or policy changes.

crm.customer.exportBLOCKED
04 / ENGINEERING

Ship the fix.
Keep the blast radius narrow.

File, credential and infrastructure actions inherit explicit authority boundaries.

system.production.writeREVIEW
From request to proof

Inspect the action before the consequence.

Follow a consequential request from agent intent to signed authority, enforced execution and independent evidence. Switch scenarios to see the same boundary protect payments, refunds, communications and enterprise systems.

FidacyCONTROL PLANE / PRODUCTIONENFORCEMENT ACTIVE
Agent runtime

support agent · live conversation

OBSERVED
Independent control

Decision record

RECORDING
IDENTITY
Workload verified
AUTHORITY
Mandate active
EXECUTION
Hard gate connected
EVIDENCE
Externally verifiable
Connected enforcement replay. No valid grant means the protected action does not execute.Inspect the verification model →
The freedom to deploy

Let agents do the work. Keep people in control.

Trust is not a dashboard full of warnings. It is the confidence to let automation move faster because the boundaries are real.

Operations leader working calmly while an AI agent handles routine tasks
Customer operations

Let the routine move. Escalate the promise.

The agent can solve the ordinary case. Commitments outside its authority wait for the person who owns the consequence.

Finance team reviewing a supplier payment handled by an agent
Finance

Pay the supplier. Not a blank instruction.

Bind every grant to the payee, amount and invoice.

Insurance and security leaders reviewing verifiable AI evidence
Risk and insurance

Settle the facts before the dispute.

Give auditors and underwriters a record neither party can quietly rewrite.

One boundary. The complete authority cycle.

Block. Allow. Record. Anchor.

Most products observe risk after an agent acts. Fidacy identifies the agent, verifies its mandate, enforces the boundary before execution and produces independently verifiable evidence after every decision.

IDENTIFYAUTHORIZEDECIDEENFORCERECORDANCHOR
A protected agent action stopped at the Fidacy execution boundary
01BLOCK

Stop what exceeds the mandate.

Fidacy Firewall and Spend Guard refuse altered payees, excessive amounts, replayed grants and unauthorized side effects before the connected system is called.

FIREWALLSPEND GUARDHARD GATE
Inspect enforcement →
An agent action passing through an exact Fidacy authority boundary
02ALLOW

Release exactly what was authorized.

KYA binds the workload identity. A signed mandate fixes the action, resource, amount, destination and duration. One matching request receives one executable grant.

KYAMANDATESONE-TIME GRANTS
Build authority →
A sequence of agent decisions preserved as ordered evidence
03RECORD

Preserve the decision and its coverage.

Every ALLOW and DENY is signed. Continuous Control Monitoring shows whether the path was gated, merely observed, incomplete or outside current evidence.

SIGNED JWSCONTROL COVERAGEINCIDENT PACK
See Control Coverage →
Fidacy evidence fixed to an external cryptographic checkpoint
04ANCHOR

Put the evidence outside the argument.

Signed records enter append-only history, become Merkle checkpoints and receive an external Bitcoin timestamp that any third party can verify.

HASH CHAINMERKLEBITCOIN
Verify the proof →
Three consequences. Three verifiable records.

Prove the money, the message and the document.

The action is only half the risk. Fidacy preserves neutral evidence of what moved, what was said and which exact artifact existed, without taking custody of the payment, transcript or file.

01 / PAYMENT AUTHORITYHARD GATE

No valid grant.
No money moves.

Bind payee, amount, invoice, currency and expiry. Where the payment rail is connected through Fidacy, an altered, excessive or replayed request is refused before settlement.

REQUESTUS$4,280
MANDATEPAYEE + CAP MATCH
ALLOW · ONE USE
Explore Spend Guard and Firewall →
02 / CONVERSATION RECEIPTSLOCAL HASHING

Prove exactly what the chatbot said.

Hash each message locally, anchor the final session digest through Fidacy and give both sides a receipt they can verify. The transcript stays inside your infrastructure.

AS
Acme SupportAI support agent · online
14:02
CUSTOMER

My card was charged twice. Can you refund the second US$900 payment?

ACME SUPPORT

Yes. I approved the full US$900 refund. You’ll see it within two business days.

SESSION DIGEST SEALED
2 verifiable receipts issuedTranscript retained by Acme
See conversation receipts →
03 / ARTIFACT RECEIPTSBITCOIN CHECKPOINT

Prove the file has not changed.

Anchor the hash of a prescription, insurance claim, contract, invoice, image or recording. Fidacy receives the digest, never the source file.

MEDICAL PRESCRIPTIONSHA-2568d8c3f…a217
VERIFIED
See artifact receipts →
Insurance infrastructure

The evidence layer that makes AI agent risk insurable.

Fidacy does not price risk or issue policies. It gives underwriters a defensible view of which controls were operating, which actions were hard-gated, where coverage stopped and what happened in a specific incident.

01UNDERWRITEControl Coverage

Current boundaries, policy versions, connector state and evidence gaps.

02CONDITIONVerified controls

Require hard-gated actions and current evidence for protected workflows.

03ADJUDICATEIncident Pack

Identity, mandate, signed decision, receipt, chain position and checkpoint.

NEUTRAL RECORDVerifiable without trusting the model, insured or Fidacy.
Primary sources, not predictions

The liability is not a thesis anymore. It is on the record.

Courts and regulators in three jurisdictions reached the same practical conclusion: an organization remains responsible for the automated action it deploys.

THE VERIFIABLE RECORD4 CONTROL LAYERS
ONE EVENT · FOUR LAYERSChange the record and the public verification fails.
Risk leaders reviewing AI control evidenceCONTROL COVERAGE · LIVE BOUNDARIES
Continuous control monitoring

Know where the control is real, and where the evidence stops.

Fidacy separates a hard gate from a heartbeat, current coverage from historical proof and a complete trail from a telemetry gap.

GATEDA verified execution boundary enforced the grant.
OBSERVEDA current authenticated connector is reporting.
LIMITEDThe latest evidence trail is incomplete.
NO EVIDENCEFidacy will not claim protection it cannot prove.
Independent by design

The party inside the transaction should not certify itself.

Fidacy is neutral to the model, agent framework, payment rail and system of record. The proof can be checked without calling us.

FIDACY INCIDENT PACK

One event. Every fact a third party needs.

Decision, agent identity, governing mandate, policy version, receipt, chain position and external checkpoint in one portable package for the owner, auditor, insurer or regulator.

See the evidence package →
SIGNEDBoth ALLOW and DENY carry a public-key verifiable JWS.
CHAINEDEach append-only record commits to the record before it.
ANCHOREDMerkle checkpoints are externally timestamped against Bitcoin.
PORTABLEIncident Packs package one decision for audit, insurance or dispute review.
Agent-agnostic by design

Mission-grade authority infrastructure. Simple to deploy. Difficult to bypass.

Start through an SDK, MCP host or API. One compact layer fits the stack you already run while private prompts, files and tool arguments remain inside your environment.

MCP HOSTS

Claude, Cursor, Codex and more

One local server for agent tools and action boundaries.

npx -y @fidacy/mcp
LANGCHAIN

JavaScript and Python

Wrap the tool so a denied call never executes.

@fidacy/langchain
OPENAI AGENTS

Gate the tool call

Enforce between model intent and the external action.

@fidacy/openai-agents
OPENCLAW

Native agent hooks

Observe sessions, gate actions and export independent proof.

@fidacy/openclaw-plugin
Production authority for consequential actions

Deploy the agent.
Not a blank check.

Put Fidacy between your agents and the payments, suppliers, enterprise systems, data and communications they can affect. Start with the highest-exposure workflow and expand under one production contract.