The commitment layer for AI agents

Commitments, under proof.

Your agents are already committing you to things — a payment, a deadline, a change. EcoCloud records what was promised, checks it against your constitution before it runs, and signs what actually happened. Anyone can verify it without trusting us.

59
Governance kernels
ES256
Every action signed
~2ms
Per decision
refund-bot · did:agent:refund-botlive
Every receipt provesEU AI ActSOC 2ISO 42001NIST AI RMFHIPAA
Scroll
Constitution enforced • ES256 signed • Audit chained • Actions reversible • Deterministic kernels • Human four-eyes Constitution enforced • ES256 signed • Audit chained • Actions reversible • Deterministic kernels • Human four-eyes

Agents are
shipping. Nothing
is checking them.

Every team is handing real work to autonomous agents. But an LLM is trained to be helpful — not to be governed. One injected web page, one over-broad tool call, one silent failure mid-workflow, and the damage is already done.

Ungoverned
  • Policy lives in the prompt — which the next input can override.
  • No signed record of what ran, when, or why.
  • A failure on step four leaves three systems out of sync.
  • Compliance means exporting the whole database and hoping.
On EcoCloud
  • Policy lives at the action layer — enforced before the tool call executes.
  • Every action is notarized — ES256-signed and hash-chained.
  • Failures self-heal — a saga planner unwinds the steps in order.
  • Compliance is a signed receipt — verifiable without the raw data.
Where you start

Governance is a ladder,
not a feature you buy.

You don’t need 59 primitives on day one. You start with a signed record of what your agents already do — and climb one rung at a time, as you earn trust in the gate.

1
Stage 01 · Recorded

A record nobody can quietly edit.

Every agent action mints an ES256-signed receipt, hash-chained to the last. Not a log line someone can rewrite — a cryptographic record of what happened, in order.

What it proves: “this event happened, in this sequence, and hasn’t been altered since.” The floor every serious deployment starts on.

2
Stage 02 · Enforced

Policy checked before the action runs.

A machine-readable constitution gates every tool call — allow, stage for a human, or deny. Identity is scoped, high-risk actions are reversible, and inputs are screened for injection.

What it proves: “this couldn’t have happened outside policy — the gate was in the path, not a dashboard watching from the side.”

3
Stage 03 · Provable

Verify it yourself — zero trust.

Anyone can check integrity offline, against a public key, with no access to our servers or database — and confirm one component without seeing the rest.

What it proves: “verify this yourself — you don’t have to take our word, or even query our systems.”

4
Stage 04 · Continuous & cross-org

Watched, and it holds across org lines.

Assurance doesn’t stop at deployment or your org chart — anomalies are watched continuously, obligations net across parties, and two organizations’ policies compose without either loosening.

What it proves: “this isn’t a point-in-time attestation — it’s watched, and it survives a second party’s policy in the mix.”

Score your workspace → Stages 1–2 score automatically from your live config. Most teams start at Stage 1 — a signed record of what already happens.
Proof, not promises

We don’t ask for
trust. We sign for it.

No logos to flash yet — just receipts anyone can verify. Governance you can prove is the only kind that scales to machines.

59
Deterministic
governance kernels
· count them ↗
100%
Reproducible —
same input, same proof
· hash it twice ↗
~2ms
Per decision at
the edge
· time it here ↗
ES256
Signed & hash-chained,
offline-verifiable
· sign one now ↗

Every claim above is measured or open-source — tap a number and watch it verify itself.

The governed loop

Six steps
between intent
and outcome.

01

Parse

Plain intent becomes a structured, typed action — owner, deadline, risk band and scope resolved before anything runs.
02

Constitution

The action is checked against your workspace rules. Out of bounds? It’s denied or staged for a human — never silently executed.
03

Route

The runtime picks the model or connector by capability, cost and privacy — with the cheapest safe option that clears policy.
04

Sign

The result is sealed with an ES256 signature and linked to the previous block — a tamper-evident chain of everything that happened.
05

Receipt

A compact, verifiable receipt is issued. Auditors confirm conformance without ever touching the sensitive payload.
06

Undo

Anything can be reversed. A saga planner computes the compensations and rolls dependent systems back, in order.
Step 01 — Intake
Start free

Priced per agent,
not per seat.

Full governance on every tier, and unlimited governed actions on every paid agent — you should never have to wonder whether an action is worth checking. Bring your own model key, or use ours.

Operator
One person, putting their first agents under governance.
$0
  • 1 governed agent
  • Full constitution & audit chain
  • 25 AI dispatches / month
  • All 59 kernels, client-side
Start free
Most teams
Fleet
Teams running agents on real, revenue-bearing work.
$39 / agent · mo
  • Unlimited governed actions per agent
  • Team roles, four-eyes & delegation
  • 26 governed connectors
  • Bring-your-own model key
Start free, upgrade later
Bank-tier
Regulated
Examined institutions — banks, insurers, health systems, public sector.
from $2k / mo
  • Bank-tier controls — recovery constitution, supervisory returns, examination workspace, model validation, information barriers
  • Signing keys you hold — your HSM or KMS, never ours
  • On-prem / air-gapped kernel runtime, no egress
  • SOC export — OCSF, ECS, CEF, Splunk, Datadog
Book a walkthrough
Ship autonomy you can defend

Let the agents
run. Keep control.

Give your agents a conscience — enforced, signed, and reversible. Set up your first governed workspace in minutes.