VORIM
We use cookies

We use cookies to analyze site traffic and improve your experience. You can choose to accept all cookies or only essential ones. See our Privacy Policy.

Product

Built for production agent security.

Cryptographic identities, granular permissions, and immutable audit trails. Every capability is designed for security, performance, and compliance in production.

Core capabilities

The platform, in seven parts.

Each capability is a primitive you can adopt on its own or compose into a full trust layer.

Cryptographic agent identity

cryptographic · one-time key

Every agent gets a unique cryptographic identity on registration. The private key is returned once and never stored. Public keys and fingerprints enable trustless verification across your entire infrastructure.

Cryptographic key generationFingerprintingOne-time private key deliveryStandard-format export

Fine-grained permissions

verify · <5ms

Control exactly what each agent can do with 7 hierarchical scopes. Set time-based validity windows, rate limits, and conditional constraints. Permissions are cached for sub-5ms verification.

7 hierarchical scopesTime-based validity windowsRate limiting per scopeCached checks

Immutable audit trail

signed · tamper-evident

Every agent action is recorded in an ordered, tamper-evident trail with optional cryptographic signatures. Efficient storage and querying built in.

Ordered event trailTamper-evident recordsBatch event ingestionEfficient long-term storage

Runtime control

allow · deny · escalate

Check every sensitive action before it runs. One SDK call returns allow, deny, escalate, or a modified payload against your live policy. High-risk actions route to a named human approver, segregation-of-duties rules stop one agent doing both halves of a sensitive task, and every decision is recorded for audit.

Pre-action policy checksNamed human approvers with signed approvalsSegregation of duties enforcementModified-payload responsesFail-open or fail-closed per org

AI cost management

real-time · token budgets

Meter and enforce token spend at the agent or workflow level. Set a rolling budget, and the one workflow that runs away is hard-blocked at the decision point, before it ever lands on the invoice. Spend and remaining allowance are visible in real time.

Per-agent and per-workflow budgetsReal-time budget enforcementHard block or soft flagCost and token visibility

Zero data retention

opt-in · proof without the data

Turn it on and none of the content your agents handle is retained. Payload summaries, context, and event metadata are dropped before they are ever written to disk. Only the cryptographic proof remains, so the audit trail still shows which agent acted, when, and with what result.

Content dropped at ingest, never storedHashes and signatures always retainedPer-organisation settingOff by default, on when you choose

Multi-agent fabric

verified hand-off

Give a team of agents a shared trust layer. When one agent hands work to another, the hand-off carries a verified identity and a strictly narrowed set of permissions, so the receiver can only ever do less than the sender. Shared memory is governed, with every write attributed and signed, and the whole workflow reconstructs as one provable record of which agent did what, on whose authority.

Verified hand-off with attenuated permissionsGoverned shared memory with attributed, signed writesWhole-workflow provenance graphWorks through the same TypeScript and Python SDKs
And more

Everything else you get out of the box.

Trust scoring

Multi-factor algorithm scoring agents 0-100 based on status, age, success rate, and scope breadth.

Real-time streaming

Real-time audit event streaming with channel subscriptions for live monitoring.

Public trust API

Rate-limited public endpoints for third-party trust verification and embeddable SVG badges. Opt agents into the public directory so anyone can look them up before interacting.

API key management

Scoped API keys. Create, list, and revoke keys through the dashboard.

Multi-tenant isolation

Organization-scoped data with row-level security. Every query is automatically tenant-isolated.

TypeScript SDK

Full-featured @vorim/sdk with typed methods for agent registration, permission checks, audit submission, and trust verification.

Python SDK

Synchronous and async clients via the vorim PyPI package. Full feature parity with the TypeScript SDK, including framework integrations.

Framework integrations

Built-in support for LangChain, OpenAI, Anthropic/Claude, CrewAI, and LlamaIndex. Automatic permission checks and audit trails on every tool call.

MCP server

Model Context Protocol server for Claude Desktop, Cursor, and VS Code. 19 tools — agents can register, check permissions, and log actions via natural language.

Cloud-native infrastructure

Containerised microservices with a real-time dashboard, fully managed so you can focus on building.

Compliance exports

Generate signed audit bundles for regulatory reporting.

Start building

Put agents into production, provably.

See how Vorim gives every agent identity, permissions, and a signed audit trail.