AuthorityRailExecution Authority Infrastructure
Execution Authority Infrastructure

Execution Authority Infrastructure. Authority is enforced before execution.

The Authority Gateway intercepts every autonomous action. VEX-1 verifies every voice command. Every decision is sealed in a Certified Action Record.

Execution Exposure Scoring bounds spend before execution. VEX-1 denies voice-clone fraud at the gate. Provenance Tagging and the Session Exposure Ledger contain regulated data with cryptographic proof. Five planes. Twenty Foundation standards. Six Industry Authority Packs. Ten of ten industry rails fully built. One cryptographic chain sealing every Certified Action Record.

Mapped, not yet third-party audited. Cryptographer review pending. Foundation reviewer engagement pending.

/v1/execute
Guardidentity, intent, policy, compliance
Walletspend, exposure, insurance
Contextmemory, routing, coordination
Dataprovenance, exposure, egress
Proofsigning, audit, verification
Certified Action Record
How is this different from Microsoft Agent 365?

Microsoft Agent 365 is a registry and access control plane inside the Microsoft estate. AuthorityRail is the pre-execution authorization standard with cryptographically signed evidence records, governed by an open standards foundation, that works across every cloud, every agent framework, and every regulated industry.

How is this different from Zenity?

Detection platforms show what agents did. AuthorityRail decides what they are allowed to do — before they do it — and produces a cryptographically signed record of that decision.

How AuthorityRail Compares

How AuthorityRail compares

Three product categories operate in the agent-authority space. They are not substitutes for one another — they act at different moments, produce different artifacts, and are governed differently. AuthorityRail is the execution authority layer.

Registry / Access Control

Microsoft Agent 365, Entra Agent ID
Primary function
Agent registry and access control plane
Decision moment
Identity and access provisioning — before and around the agent lifecycle
Evidence output
Registry entries, access grants, identity records
Governance model
Vendor-controlled

Detection / AISPM

Zenity, Noma Security, Virtue AI
Primary function
Detection and AI security posture management
Decision moment
Observation — during and after the agent acts
Evidence output
Alerts, posture findings, observability telemetry
Governance model
Vendor-controlled

AuthorityRail

Execution Authority Infrastructure
Primary function
Execution Authority Infrastructure — a distributed authorization network
Decision moment
Pre-execution — before the agent acts
Evidence output
Cryptographically signed Certified Action Records (CARs)
Governance model
AuthorityRail Standards Foundation (ASFC-v1), open standard

Governed by a foundation, not a vendor

ARES-v1 — the Agent Runtime Execution Standard — is governed by the AuthorityRail Standards Foundation, not by AuthorityRail the company. This is the same separation that lets the PCI Security Standards Council govern PCI DSS rather than Visa or Mastercard, and the IETF govern TCP/IP rather than Cisco or AWS. The AuthorityRail platform is the production reference implementation of ARES-v1, under the same Foundation that governs the standard. No Tier 1 competitor in the agent-authority space has a credible standards-body governance story.

ARES-v1 specification
Why Now

Why now

AuthorityRail launches in the window between the autonomous-agent adoption maturity gap and the enforcement-driven procurement urgency that closes it.

  • Colorado AI Act enforceable June 2026.
  • EU AI Act high-risk obligations begin August 2026.
  • 79% of enterprises have adopted AI agents; 11% run them in production (Gartner).
  • Only 21% of organizations have a mature governance model for autonomous AI agents (Gartner).
  • AI governance platform spending is projected to reach $492M in 2026 and exceed $1B by 2030 (Gartner).
  • Gartner predicts more than 40% of agentic AI projects will be canceled by end of 2027 — primary drivers: escalating costs, unclear business value, inadequate risk controls.

The adoption has happened. The governance maturity has not. The enforcement deadlines are dated. AuthorityRail is the execution authority layer that closes the gap.

§2 Unified-Architecture Claim

Five dimensions of authority. One cryptographic chain.

The AI agent authority category contains substantial vendors — Microsoft Agent Governance Toolkit (Agent Mesh + Agent Runtime + Agent Compliance), Zenity (Gartner Company to Beat April 2026), OpenBox (single-SDK runtime authority with cryptographic verification), Sekuire OAGS (Open Agent Governance Specification), Bifrost, Virtue AI, OpenAI Frontier (Promptfoo acquisition), Microsoft Agent 365. Each addresses a subset of enterprise AI authority. None ships all five planes (Guard, Wallet, Context, Data, Proof) as first-class peers governed by twenty open standards under independent Foundation governance with six vertical Authority Packs and one cryptographic chain across all of it. AuthorityRail does.

Voice authorization

VEX-1 with three-class clone detection. Voice credential enrollment with privacy-by-design (raw audio NEVER persisted). HCES-1 escalation for high-stakes voice actions.

No competitor ships voice.

Data egress control

Eight ingestion adapters, eight destination types, seven default detectors (PII, PHI, PCI, secrets, IP, attorney-client privilege, fair-lending), three-state consent engine, signed egress audit.

No competitor ships this depth.

Agent fleet authority

Agent Registry with declared scope, four-state lifecycle, seven drift classes, four-CAR atomic decommissioning, Bypass Detection for shadow agents.

Customer-owned, runtime-independent — not Microsoft-only.

Continuous compliance adaptation

Six regulatory feed adapters (Federal Register, EU Official Journal, NIST, ISO, state legislative, bar associations), 4-hour critical-priority review, Compliance Posture Timeline for board reporting.

No competitor ships this.

Industry-specific authority baselines

Six pre-configured packs covering 105 regulatory citations: HCP-v1 (healthcare), FSP-v1 (financial), DEP-v1 (defense), INP-v1 (insurance), LGP-v1 (legal), ESP-v1 (enterprise SaaS).

Deploy in 30 seconds via /v1/packs/apply.

Every autonomous system requires authority before execution. AI agents are the leading edge — voice-driven systems are next, robotic systems and physical AI follow. AuthorityRail is built for the full category, starting with where the urgency is highest today.

§3 What We Cover

What AuthorityRail covers

AuthorityRail evaluates every autonomous action before it executes. The five planes — Guard, Wallet, Context, Data, Proof — assess identity, intent, policy, compliance, spend, exposure, insurance, memory, routing, coordination, provenance, signing, and audit. Latency is published decision-class-tiered and processing-path-tiered — Fast Path, Standard Path, Escalation Path — never as a single conflated number. The substance is the guarantee: the gate signs and durably persists a Certified Action Record before the action reaches any downstream system. A gate that returns a decision label fast but issues the record slowly has not authorized anything fast. AuthorityRail prioritizes deterministic authorization integrity over speculative latency theater.

For autonomous AI agents

  • Pre-execution authorization across the five planes
  • Agent Registry with declared scope and drift detection
  • Four AI-native modules (Adaptive, Packs, Compliance Monitor, Registry)
  • Decision-class-tiered latency SLAs — Fast Path, Standard Path, Escalation Path

AI agents are the leading edge of autonomous systems.

For voice-driven autonomous systems

  • VEX-1 Voice Execution Gateway
  • Three-class clone detection (synthesis, replay, biometric)
  • HCES-1 escalation for high-stakes voice actions
  • Voice as Data Plane destination class with vertical-specific trust scores

Voice-clone wire fraud is an active attack vector. AuthorityRail closes it at the architectural layer.

For regulated data movement

  • Data Plane with eight ingestion adapters and eight destination types
  • Seven default detectors (PII, PHI, PCI, secrets, IP, privilege, fair-lending)
  • Customer-registered custom detectors
  • Three-state consent engine
  • Session Exposure Ledger with cumulative tracking
  • Egress audit module under ARES-v1.3

Data egress under cryptographic audit, not retroactive logging.

For enterprise compliance posture

  • Six pre-configured Industry Authority Packs
  • Live Compliance Adaptation tracking six regulatory feeds
  • 4-hour critical-priority review for regulatory changes
  • Compliance Posture Timeline for board reporting

Continuous compliance posture, not quarterly snapshots.

§4 Cross-Firm Convergence

Five analyst firms. Six concerns. One unified architecture.

Gartner, McKinsey, PwC, Deloitte, and Forrester — five firms with different methodologies, different surveys, different audiences, and different revenue models — all converge on the same six concerns about enterprise AI and autonomous systems. The convergence is itself the procurement signal: when five firms with different incentives identify the same six concerns, the concerns are real.

Concern #1

Authority failure

Fragmented controls, inadequate oversight, no enterprise-wide policy enforcement.

Five planes plus Authority Constraints API plus twenty Foundation standards plus Compliance Posture Timeline.

Concern #2

Shadow AI

Unauthorized AI use outside IT control, data exposure, compliance incidents.

Agent Registry plus Bypass Detection plus Drift Detection plus Provenance Layer with Tag Conservation Rules.

Concern #3

Weak employee readiness

Low AI fluency, siloed adoption, missing skills for handling autonomous systems.

Six pre-configured Industry Authority Packs plus Customer Adaptive Authority plus Dashboard for non-technical buyers.

Concern #4

Poor ROI and scale

Pilot purgatory, no enterprise financial impact, fragmented tactical projects.

30-second Industry Authority Pack deployment plus Wallet Plane Decision Economics plus decision-class-tiered latency SLAs.

Concern #5

Security and privacy exposure

Data leakage, IP loss, regulatory compliance gaps, model explainability.

Data Plane with seven detectors plus VEX-1 voice authentication plus ARRS-v1.2 hardware-bound runtime authentication shipped.

Concern #6

Autonomous-agent control problems

Agent-specific controls missing, weak authority maturity, runtime credential risks, voice-clone threats.

Four AI-native modules plus HCES-1 plus VEX-1 plus WorkforceRail clearance integration plus the AuthorityRail Standards Foundation as customer-owned platform-agnostic guardian agent layer.

The Gartner Guardian Agent Market Guide explicitly calls for "enterprise-owned guardian agent layers that sit above individual platforms." AuthorityRail is that layer.

Sources: Gartner Top Cybersecurity Trends for 2026, Hype Cycle for Agentic AI 2026, Guardian Agent Market Guide. McKinsey State of AI Trust 2026, Securing the Agentic Enterprise. PwC 2026 AI Business Predictions, Risk Agenda for Assurance Functions 2026. Deloitte State of AI in the Enterprise 2026. Forrester 2026 Technology and Security Predictions.

§5 The Architecture

The architecture

Five planes. Four AI-native modules. Voice Execution Gateway. Six pre-configured industry packs. Seventeen Foundation standards. Seven trust domains with operational separation.

/v1/execute
Guardidentity, intent, policy, compliance
Walletspend, exposure, insurance
Contextmemory, routing, coordination
Dataprovenance, exposure, egress
Proofsigning, audit, verification
Certified Action Record
  • Guard Plane

    identity, intent, policy, compliance

    Should this action ever execute?

  • Wallet Plane

    spend, exposure, insurance

    What does this action cost?

  • Context Plane

    memory, routing, coordination

    What context does this action need?

  • Data Plane

    provenance, exposure, egress

    Should data leave the actor’s boundary?

  • Proof Plane

    signing, audit, verification

    What evidence proves the decision?

Four AI-native modules

Customer Adaptive Authority (AAAS-v1)

observe-recommend-explain-approve-deploy-CAR loop. Seven pattern classes. Customer-controlled adaptation.

Industry Authority Packs (IAPS-v1)

Six pre-configured packs covering 105 regulatory citations. 30-second deployment.

Live Compliance Adaptation (CMAS-v1)

Six regulatory feed adapters, 4-hour critical review.

Agent Registry (ARS-v1)

Proactive registration with declared scope, four-state lifecycle, seven drift classes.

VEX-1 Voice Execution Gateway

AuthorityRail is the only execution authority infrastructure with a voice gateway at v1.0. VEX-1 implements three-class clone detection running in parallel, each class under a 200ms hard timeout with fail-closed semantics — the timeout is an enforced ceiling, not a benchmark. Voice credential enrollment with privacy-by-design — raw audio is NEVER persisted, only 256-dimensional embeddings and signed transcripts. Phone numbers stored hashed not plaintext. HCES-1 escalation via the existing Twilio mobile_approval flow. Voice attack surface closed at the architectural layer.

Seven trust domains

Different operational ownership per the cryptographic separation pattern. Compromise of one key does not compromise the others.

ARES-v1.3Proof Planesee manifest
ADES-v1Provenance Layer439ff70dc8c4283a6a7bbe7d42306737
AAAS-v1Adaptive Layersee manifest
IAPS-v1Pack Vendor7941754e078ab6d484bb814526ed2b21
CMAS-v1Compliance Monitorsee manifest
ARS-v1Agent Registry08b96e87772ec9c22d420aaaac3a9f22
VEX-1VEX-1 Voice62fc42210367cdd7cddbdd2e6a1e6003

Twenty Foundation standards

All twenty Foundation standards reuse ARES-v1.1 cryptographic primitives: pure Ed25519 over COSE_Sign1, length-prefixed canonical inputs. No parallel cryptosystem. Single primitive surface to migrate when post-quantum cryptography becomes operational. Foundation governance under ASFC-v1 with three external reviewers per standard advancement.

Read the standards
§5a Why Five Planes Wins

Why five planes wins

Each plane is a peer evaluation surface inside the Authority Gateway. Together they evaluate every /v1/execute request before it reaches its destination. No named competitor — Microsoft Agent Governance Toolkit, Zenity, OpenBox, Sekuire OAGS, Bifrost, Virtue AI, OpenAI Frontier, Microsoft Agent 365 — ships all five as first-class peers under one cryptographic chain.

Guard Plane

Should this action ever execute?

identity, intent, policy, compliance

Wallet Plane

What does this action cost?

spend, exposure, insurance, risk multipliers

Context Plane

What context does this action need?

memory, routing, coordination, clearance ceiling

Data Plane

Should data leave the actor’s boundary?

provenance, exposure, egress, detection

Proof Plane

What evidence proves the decision?

signing, audit, verification, federation manifest

The five planes plus the four AI-native modules (Adaptive, Packs, Compliance Monitor, Registry) plus the Voice Execution Gateway plus the six Industry Authority Packs plus the twenty Foundation standards plus the seven trust domains under independent Foundation governance — that is the architecture procurement-grade buyers verify against the AuthorityRail module inventory in five minutes.

Source of truth: standards/audits/empire-module-inventory-2026-04.md §4 documents all five planes with service paths, plane contracts, and homepage references.

§6 Six Packs — The Regulated-Vertical Wedge

Six packs. 105 regulatory citations. The regulated-vertical wedge.

AuthorityRail’s six pre-configured Industry Authority Packs cover 105 regulatory citations across Healthcare (HCP-v1), Financial Services (FSP-v1), Defense (DEP-v1), Legal (LGP-v1), Insurance (INP-v1), and Enterprise SaaS (ESP-v1). Each pack ships vertical-specific defaults, regulatory citation indexes, never-allow action classes, and voice channel trust scores. Deploy in 30 seconds via /v1/packs/apply. No named competitor — Microsoft AGT, Zenity, OpenBox, Sekuire OAGS, Bifrost, Virtue AI, OpenAI Frontier, Microsoft Agent 365 — ships vertical Authority Packs.

Every autonomous system requires authority before execution. The regulatory landscape your enterprise navigates is the regulatory landscape AuthorityRail’s Industry Authority Packs are built to address. Deploy in 30 seconds. Audit cryptographically.

§7 How We Compare

How AuthorityRail compares

The AI agent authority category contains eight named competitors as of April 2026 — Microsoft Agent Governance Toolkit, Zenity (Gartner Company to Beat), OpenBox, Sekuire OAGS, Bifrost, Virtue AI, OpenAI Frontier (Promptfoo acquisition), Microsoft Agent 365. Each addresses a subset of enterprise AI authority. None ships all five planes (Guard, Wallet, Context, Data, Proof) as first-class peers under one cryptographic chain governed by twenty open standards under independent AuthorityRail Standards Foundation governance with six vertical Authority Packs covering 105 regulatory citations.

ConcernMicrosoft AGTZenityOpenBoxSekuire OAGSBifrostVirtue AIOpenAI FrontierMicrosoft Agent 365AuthorityRail
Authority failureEU AI Act + HIPAA + SOC 2 + OWASP mappingMulti-cloud authoritySingle-SDK runtimeOpen spec onlyPartialReactiveVulnerability testingMicrosoft onlyFive planes + 20 standards + 10/10 rails
Shadow AIAgent Mesh cryptographic identity (Microsoft deploy)Multi-cloud detectionCryptographic verificationSpec onlyLimitedNoneNoneMicrosoft onlyAgent Registry + Bypass + Drift
Employee readinessMicrosoft-stack focusGenericGenericGenericGenericGenericGenericMicrosoft only6 packs + Adaptive + Dashboard
Poor ROI / scaleMicrosoft-stack onlyPilot to productionPilot-gradeSpec onlyPilot-gradeReactivePilot-gradeMicrosoft only30-second pack + Wallet Plane
Security / privacyAgent Mesh + Ed25519 (Microsoft)Multi-cloud monitoringSingle SDKSpec onlyLimitedPost-executionVulnerability testingMicrosoft onlyData Plane + VEX-1 + ARRS-v1.2 (6 hardware surfaces)
Autonomous-agent controlExecution rings (Microsoft)Multi-cloud detectionCryptographic verificationSpec onlyPartialPost-executionVulnerability testingMicrosoft only4 AI-native modules + HCES-1

Hover any competitor name for the public-materials summary. Each cell is rendered honestly per public materials — no unfair characterization, no hiding of strengths.

With Microsoft AGT + Zenity + OpenBox + an audit firm + custom voice + custom Compliance Monitor

  • Five separate vendors
  • Five separate contracts
  • Five separate audit trails
  • No unified policy surface
  • No cryptographic chain of custody across surfaces
  • Integration complexity at every boundary
  • Compounding security review obligations
  • Six-to-twelve-month enterprise deployment
  • No cross-vendor regulatory feed coverage
  • No unified board-presentable maturity report

With AuthorityRail

  • One vendor
  • One contract
  • One audit trail
  • Unified policy surface (Authority Constraints API)
  • Cryptographic chain of custody across all surfaces (Decision Lineage with Provenance Tag conservation)
  • Single integration point (Authority Gateway)
  • Single security review
  • 30-second pack deployment to vertical-specific baseline
  • Continuous regulatory feed coverage across six adapters with 4-hour critical review
  • Compliance Posture Timeline as continuous board-presentable maturity report

This is the procurement-stage value proposition that justifies seven-figure ACVs in regulated verticals.

→ Read the full Competitive Honesty page (every competitor named, public-materials summary, where AuthorityRail is deeper or narrower)
§8 The Foundation

The AuthorityRail Standards Foundation — Independent Governance

AuthorityRail’s twenty open standards are administered by the AuthorityRail Standards Foundation (ASFC-v1) — an independent public governance body with cryptographic primitive consistency rules, a 12-month compatibility window, three-external-reviewer engagement requirements per standard advancement, and the no-duplicate-primitive rule added per Path B Resolution Execution Report 2026-04-30. The independence matters at procurement: Microsoft Agent Governance Toolkit is open-source-but-Microsoft-owned. AuthorityRail Standards Foundation is independent. Customers in regulated verticals procurement-evaluate the difference. Foundation portfolio advanced from seventeen to nineteen standards on 2026-04-30 (SRI-v1 + DRI-v1 from Draft to Tier 2 Published per ASFC-v1 §3.1) and from nineteen to twenty on 2026-05-01 with WARS-v1.2 (human-vs-agent identity boundary) and ARES-v1.3 (economic_records sealed-field block on the CAR).

Open standards portfolio

  • Twenty Foundation standards (advanced from seventeen on 2026-04-30 with SRI-v1 + DRI-v1; to twenty on 2026-05-01 with WARS-v1.2, ARES-v1.3, ARRS-v1.2 (Token Rail Fully Built), and ARSS-v1 (Risk Rail Fully Built))
  • ARES-v1.3 as the canonical Certified Action Record format (with the economic_records sealed-field block)
  • ARRS-v1.2 hardware-bound runtime authentication across six attestation surfaces (TPM 2.0, AWS Nitro, GCP Confidential, Azure Confidential, Apple Secure Enclave, Android StrongBox)
  • ARSS-v1 deterministic Authority Risk Scoring with 74-vector executable conformance suite
  • 10 of 10 industry rails Fully Built — Authority, Identity, Workforce, Voice, Verifier, Compliance, Standards Foundation, Observability, Token, Risk
  • Seven trust domains with operational separation
  • Cryptographic primitive consistency: Ed25519 over COSE_Sign1
  • 12-month compatibility window per ASFC-v1 §3.3
  • All standards published at authorityrail.com/standards
  • Reproducible test vectors for ARES-v1.3 + ADES-v1 (other eighteen ship in v1.0.1)

Independent Foundation governance

  • Foundation Charter at standards/asfc-v1/SPEC.md
  • Three external reviewers per standard advancement
  • Cryptographer review engagement target: Trail of Bits, NCC Group, Cure53, or Filippo Valsorda (engagement pending)
  • Foundation reviewer engagement under ASFC-v1 §3 (engagement pending)
  • Independent of any single vendor — Microsoft Agent Governance Toolkit is open-source-but-Microsoft-owned; AuthorityRail Standards Foundation is independent
  • Public administration of standards portfolio + federation manifests
  • Public reproducibility commitments

Independent verification

  • Verification console runs entirely client-side
  • Customers can verify any CAR without involving AuthorityRail’s servers
  • Federation manifest verification for all seven trust domains
  • Reproducibility Guide with clean-install verification commands
  • Mapped, not yet third-party audited (honest disclosure)
  • Foundation transparency commitment
  • Empire module inventory at standards/audits/empire-module-inventory-2026-04.md is the canonical evidence document
Read the Foundation Charter
§9 Reproducibility

Verify it yourself

AuthorityRail’s architectural quality posture is procurement-grade: every claim is verifiable independently. Clone the repo, run the canonical reproduction commands, verify any CAR against the federation manifest. The Standards Site verification console runs entirely client-side — no trust required in AuthorityRail’s servers.

Step 1 — Clone the repo
git clone https://github.com/AuthorityRail-ai/authorityrail.git
cd authorityrail
npm install --include=dev
Step 2 — Run the test vectors
npx tsx packages/axap/scripts/verify-test-vectors.ts ares-v1.2
npx tsx packages/axap/scripts/verify-test-vectors.ts ades-v1
Step 3 — Verify any CAR
curl -s https://[customer-gateway]/v1/cars/[car_id] \
  | npx tsx packages/axap/scripts/verify-car.ts

Honest engagement status

Cryptographic primitive reviewPending — engagement target Trail of Bits / NCC Group / Cure53 / Filippo Valsorda
Foundation reviewer engagementPending per ASFC-v1 §3
Production-shape benchmarksShipping post-launch per PRODUCTION_SHAPE_ROADMAP.md
Test vectors for fifteen standardsShipping in v1.0.1
First three pilot customersIn deployment phase
False-positive telemetryShipping after first 90 days of pilot deployment

None of these engagements is hidden. All are surfaced openly, with honest timelines. AuthorityRail’s architectural quality posture is the procurement signal that distinguishes the Foundation from vendors making category claims without substance.

Read the Reproducibility Guide
§10 Pricing

Pricing

Four tiers. Volume-based, with included CARs per month and per-CAR overage. Built for procurement-stage enterprise pricing.

AuthorityRail Starter

$99/mo

For: teams piloting AuthorityRail on a single autonomous workflow.

  • 100,000 included CARs/month
  • $0.0008 per CAR over the included quota
  • Authority Gate, Decision Engine (MAACS), Canonical Authority Records
  • Single-region production deployment
  • Dashboard + Control Tower read access
  • Email support, 1 business day SLA
  • @authorityrail/axap SDK + LangGraph / CrewAI plugins
  • 12-month compatibility window per ASFC-v1 §3.3
Start with Starter

AuthorityRail Growth

$499/mo

For: production deployments running multiple autonomous workflows.

  • Everything in Starter, plus:
  • 1,000,000 included CARs/month
  • $0.0006 per CAR over the included quota
  • Multi-region read replicas
  • Authority Constraints API + scoped API keys
  • Six Industry Authority Packs (FSP-v1, HCP-v1, DEP-v1, INP-v1, LGP-v1, ESP-v1)
  • Priority email + Slack Connect support, 4-hour SLA
Move to Growth

AuthorityRail Scale

$1,999/mo

For: large agent fleets and regulated-vertical production volume.

  • Everything in Growth, plus:
  • 10,000,000 included CARs/month
  • $0.0004 per CAR over the included quota
  • Multi-region active-active deployment
  • Per-customer signing key isolation
  • Compliance Posture Timeline + audit export
  • Dedicated Solutions Engineer
  • 24×7 on-call support, 1-hour SLA
Scale up

AuthorityRail Enterprise

Contact Sales

For: regulated, custom-volume, or sovereign-deployment enterprises.

  • Everything in Scale, plus:
  • Custom CAR volume + custom overage pricing
  • Custom Industry Authority Pack development
  • Named-cryptographer review (Trail of Bits, NCC Group, Cure53, or Filippo Valsorda)
  • VEX-1 Voice Execution Gateway add-on (post-launch)
  • Custom Data Plane detectors + destination classifications
  • Dedicated implementation support and production-shape benchmark partnership
  • Standalone Master Service Agreement and DPA
Contact Sales

Pricing is denominated in Certified Action Records (CARs) — the cryptographically signed authority record produced for every execution decision. Included quotas reset monthly. Overage bills via metered usage at the rates below. Customer-tier rates are the only thing on the customer invoice; internal Decision SKU classification is a metering primitive and never appears on a bill.

§11 Call To Action

Pilot AuthorityRail

AI agents are deploying at machine speed. The cross-firm consensus is that 2026 is the year enterprise AI moves from pilot to production — and the year authority failures will produce publicly disclosed breaches. AuthorityRail is the unified architecture that prevents catastrophic loss while enabling the regulated-vertical deployment your enterprise needs.

Procurement-stage pilot

For: CISO, General Counsel, Chief Risk Officer in regulated verticals.

We deploy AuthorityRail with your security and compliance teams in a 90-day pilot. Industry Authority Pack pre-configured for your vertical. Cryptographic audit trail from day one. Compliance Posture Timeline for board reporting. Voice-clone fraud prevention for executive approval flows. Mapped to your specific regulatory landscape.

Foundation reviewer engagement

For: Cryptographers, security researchers, AI safety researchers, policy/governance scholars, standards developers.

We engage external reviewers per ASFC-v1 §3 — three reviewers per standard advancement. The Foundation publishes reviewer reports openly. Cryptographer review engagement target: Trail of Bits, NCC Group, Cure53, or Filippo Valsorda. Currently pending engagement.

Journalist briefing

For: Technical journalists covering AI authority infrastructure, regulated verticals, or enterprise infrastructure.

We brief technical journalists on AuthorityRail’s open-standards architecture, the cross-firm analyst-firm convergence, and the unified-architecture claim. Journalist Briefing at apps/standards-site/docs/JOURNALIST_BRIEFING.md.

Every autonomous system requires authority before execution. AI agents are the leading edge.