Authority
Bind the AI agent identity, permitted action, resource, value, destination, time window and required approval.
Once compromised, it can use your permissions to reach money, data, credentials and systems.
Fidacy is the Authority Firewall for AI Agents. Stop unauthorized payments, emails and data operations before connected systems execute them. Independent authority before action. Exportable signed evidence after the decision. Cryptographic verification in your browser.
Works with the AI agents and frameworks your teams already run.
Select an AI agent and a consequential action. Fidacy verifies identity, mandate, policy and request integrity before the connected executor receives permission to act.
Bind the AI agent identity, permitted action, resource, value, destination, time window and required approval.
Require a matching signed grant at the executor. No valid grant means no payment, email, export, refund or production change.
Export signed decisions and audit history. Verify decision signatures in your browser. Check external checkpoints independently of the system that acted.
Show which AI agent actions are gated, observed, incomplete or outside control so security, legal and insurance teams see the real exposure.
Payments, supplier changes, data exports, credentials and production systems become attack paths when AI agent intent reaches them without an independent authority check.
Change the payee, amount, invoice or currency inside a workflow that already has payment access.
Export records, expose credentials or call production tools through permissions the organization granted itself.
Issue refunds, send commitments or change critical records before a human sees the consequence.
Start with the AI agent actions that put your business at risk. Agree the integration, test the controls and define who operates them.

Identify AI agents, executors, actions, owners, approval thresholds and the consequences that require hard enforcement.

Require one matching grant before the protected system acts.

Track coverage, policy versions, approvals, evidence gaps and incident records.
Your AI agent can propose an action. Fidacy checks its identity and signed permissions before the connected executor acts. Authorized work proceeds. Out-of-scope actions are refused. Signed records make enforcement verifiable.

Fidacy Firewall and Spend Guard refuse altered payees, excessive amounts, replayed grants and unauthorized side effects before the connected system is called.

KYA binds the workload identity. A signed mandate fixes the action, resource, amount, destination and duration. One matching request receives one executable grant.

Every ALLOW and DENY is signed. Continuous Control Monitoring shows whether the path was gated, merely observed, incomplete or outside current evidence.

Signed records form hash-linked audit history and Merkle checkpoints. OpenTimestamps anchors those checkpoints to Bitcoin, so confirmed timestamps can be verified outside the operator's system.
The action is only half the risk. Fidacy preserves neutral evidence of what moved, what was said and which exact artifact existed, without taking custody of the payment, transcript or file.
Bind payee, amount, invoice, currency and expiry. Where the payment rail is connected through Fidacy, an altered, excessive or replayed request is refused before settlement.
Hash each message locally, anchor the final session digest through Fidacy and give both sides a receipt they can verify. The transcript stays inside your infrastructure.
Anchor the hash of a prescription, insurance claim, contract, invoice, image or recording. Fidacy receives the digest, never the source file.
Give underwriters evidence they can verify, not just the operator's account of an incident. Export signed records of decisions, authority and control coverage, with external checkpoint references. Fidacy supplies the evidence, not the insurance policy.
Current boundaries, policy versions, connector state and evidence gaps.
Require hard-gated actions and current evidence for protected workflows.
Identity, mandate, signed decision, receipt, chain position and checkpoint.
Courts and regulators in three jurisdictions reached the same practical conclusion: an organization remains responsible for the automated action it deploys.
CONTROL COVERAGE · LIVE BOUNDARIESFidacy separates a hard gate from a heartbeat, current coverage from historical proof and a complete trail from a telemetry gap.
Fidacy separates authorization from the agent and anchors evidence outside the operational system. No custody of funds. No percentage of payment value. Verify the record, not the operator's version of events.
Signed audit exports and portable evidence packages preserve decisions and their authority context for independent review. Give auditors, insurers and counterparties records they can check, not screenshots they must trust.
Verify your evidence package →Start through an SDK, MCP host or API. One compact layer fits the stack you already run while private prompts, files and tool arguments remain inside your environment.
One local server for agent tools and action boundaries.
npx -y @fidacy/mcpWrap the tool so a denied call never executes.
@fidacy/langchainEnforce between model intent and the external action.
@fidacy/openai-agentsObserve sessions, gate actions and export independent proof.
@fidacy/openclaw-pluginFidacy already implements the core authority chain in software: identity, signed mandates, pre-action decisions, enforceable grants, revocation and independently verifiable evidence.
Money · data · communications · enterprise systems
Already implemented at the software authority layer.
Gateway · device identity · local enforcement · safety validation
Mission-level authority for robots, drones, vehicles and safety-critical autonomous infrastructure, without entering the motor-control loop.
≈90% is an architecture-reuse estimate, not physical-product readiness or safety certification.
Intelligence decides what to do.Authority decides whether it may happen.
Fidacy submitted a production-backed enforcement case study to Singapore's Model AI Governance Framework for Agentic AI consultation.
Read the technical contribution →Fidacy has joined Pillar I, contributing implementation practices for trustworthy AI and AI Act readiness.
View the AI Pact →Bring an email, data or payment workflow. Together, scope a controlled test of permitted actions, blocked requests and verifiable evidence before production.