Built for production agent security.
Cryptographic identities, granular permissions, and immutable audit trails. Every capability is designed for security, performance, and compliance in production.
The platform, in seven parts.
Each capability is a primitive you can adopt on its own or compose into a full trust layer.
Cryptographic agent identity
cryptographic · one-time keyEvery agent gets a unique cryptographic identity on registration. The private key is returned once and never stored. Public keys and fingerprints enable trustless verification across your entire infrastructure.
Fine-grained permissions
verify · <5msControl exactly what each agent can do with 7 hierarchical scopes. Set time-based validity windows, rate limits, and conditional constraints. Permissions are cached for sub-5ms verification.
Immutable audit trail
signed · tamper-evidentEvery agent action is recorded in an ordered, tamper-evident trail with optional cryptographic signatures. Efficient storage and querying built in.
Runtime control
allow · deny · escalateCheck every sensitive action before it runs. One SDK call returns allow, deny, escalate, or a modified payload against your live policy. High-risk actions route to a named human approver, segregation-of-duties rules stop one agent doing both halves of a sensitive task, and every decision is recorded for audit.
AI cost management
real-time · token budgetsMeter and enforce token spend at the agent or workflow level. Set a rolling budget, and the one workflow that runs away is hard-blocked at the decision point, before it ever lands on the invoice. Spend and remaining allowance are visible in real time.
Zero data retention
opt-in · proof without the dataTurn it on and none of the content your agents handle is retained. Payload summaries, context, and event metadata are dropped before they are ever written to disk. Only the cryptographic proof remains, so the audit trail still shows which agent acted, when, and with what result.
Multi-agent fabric
verified hand-offGive a team of agents a shared trust layer. When one agent hands work to another, the hand-off carries a verified identity and a strictly narrowed set of permissions, so the receiver can only ever do less than the sender. Shared memory is governed, with every write attributed and signed, and the whole workflow reconstructs as one provable record of which agent did what, on whose authority.
Everything else you get out of the box.
Trust scoring
Multi-factor algorithm scoring agents 0-100 based on status, age, success rate, and scope breadth.
Real-time streaming
Real-time audit event streaming with channel subscriptions for live monitoring.
Public trust API
Rate-limited public endpoints for third-party trust verification and embeddable SVG badges. Opt agents into the public directory so anyone can look them up before interacting.
API key management
Scoped API keys. Create, list, and revoke keys through the dashboard.
Multi-tenant isolation
Organization-scoped data with row-level security. Every query is automatically tenant-isolated.
TypeScript SDK
Full-featured @vorim/sdk with typed methods for agent registration, permission checks, audit submission, and trust verification.
Python SDK
Synchronous and async clients via the vorim PyPI package. Full feature parity with the TypeScript SDK, including framework integrations.
Framework integrations
Built-in support for LangChain, OpenAI, Anthropic/Claude, CrewAI, and LlamaIndex. Automatic permission checks and audit trails on every tool call.
MCP server
Model Context Protocol server for Claude Desktop, Cursor, and VS Code. 19 tools — agents can register, check permissions, and log actions via natural language.
Cloud-native infrastructure
Containerised microservices with a real-time dashboard, fully managed so you can focus on building.
Compliance exports
Generate signed audit bundles for regulatory reporting.
Put agents into production, provably.
See how Vorim gives every agent identity, permissions, and a signed audit trail.