Trust infrastructure for the agentic web

High-stakes agent actions, approved by a named human.

DC ESCRYPT is the company behind Raposa Aval: one API call pauses an agent's payment, deploy or email until an authorized person approves it, and every decision is written to a hash-chained audit log. Signed agent identity (Web Bot Auth) and verified delegation of authority are in development.

» Human approval API» Hash-chained audit» Web Bot Auth keys published» KYC/KYB: roadmap» EU hosting
/01

Agent Identity · in development

Planned: end users pass KYC/KYB verification and sign a delegation of authority; their agents then identify themselves with HTTP Message Signatures (RFC 9421). Today our Ed25519 key directory is published; identity verification and the signed agent service are not available yet.

/02

Human-in-the-Loop

Live today as Raposa Aval: an agent pauses a payment, deploy or email and waits for the named approver. Silence is never consent — a timeout is not an approval.

/03

Audit & Accountability

Every approval request and decision is written to a hash-chained audit log with the approver's name. Customers export their own entries; editing any past entry breaks verification. Attribution to verified end users arrives with agent identity (in development).

How it works
01

Verify · planned

The end user — individual or business — will complete identity verification.

02

Delegate · planned

They will sign a scoped delegation: what their agent may do, within which limits.

03

Sign · in development

Agent traffic will carry signatures tied to our published key directory. The directory is live; the signing agent is not running yet.

04

Approve · live

Human-in-the-loop checkpoints for actions that need a person's decision — live today in Raposa Aval.

05

Audit · live

A hash-chained log records who approved what, and when.

About

DC ESCRYPT is a European company building trust infrastructure for autonomous agents. Our signed agent, DCEscryptAgent, is in development: its public key directory is already published so site owners can verify its requests once it runs.