THE AI AGENT ATTACK SURFACE

Hackers can hijack
the AI agent you already gave access to.

Once compromised, it can use your permissions to reach money, data, credentials and systems.

Fidacy is the Authority Firewall for AI Agents. Stop unauthorized payments, emails and data operations before connected systems execute them. Independent authority before action. Exportable signed evidence after the decision. Cryptographic verification in your browser.

DEPLOYED TODAYAI AGENTSIN DEVELOPMENTPHYSICAL AI
ONE BOUNDARY · EVERY AI AGENT STACK

Works with the AI agents and frameworks your teams already run.

Native integrations where available. Universal coverage through MCP, SDK and API — without moving private prompts, files or tool arguments outside your environment.
Native integrationMCP hostSDK / API
Claude CodeNative plugin
OpenClawNative plugin
LangChainNative · JS + Python
OpenAI AgentsNative adapter
Vercel AI SDKNative middleware
MCPFidacy MCPUniversal server
CodexMCP host
CursorMCP host
Gemini CLIMCP host
GitHub CopilotMCP host
WindsurfMCP host
Hermes AgentMCP + hooks
OpenCodeMCP host
ClineMCP host
CrewAISDK / API
PydanticAISDK / API
Cloudflare AgentsSDK / API
Strands AgentsSDK / API
Microsoft Agent FrameworkSDK / API
Google ADKSDK / API
GrokBotAPI agent
ANY CUSTOM AGENTSDKAPIMCPUCPAP2A2ASTRIPEBREXGITHUBBITCOINPAYMENTSREFUNDSCRMEMAILFILESINFRASTRUCTURE
Authority Firewall for AI Agents

Watch the action stop before it becomes an incident.

Select an AI agent and a consequential action. Fidacy verifies identity, mandate, policy and request integrity before the connected executor receives permission to act.

1 / CHOOSE THE AI AGENT
2 / CHOOSE THE ACTION
FIDACYINTERACTIVE ENFORCEMENT REPLAY
AUTHORITY FIREWALL CONNECTED
01IDENTITYWorkload verified
02MANDATEScope resolved
03DECISIONPolicy evaluated
04EXECUTORGrant required
05EVIDENCEDecision signed
06ANCHORCheckpoint verifiable
Representative connected-enforcement replay. The payment path is available as a live signed verdict; every surface shown uses the same executor-side grant contract.Run a live signed verdict →
01 / DEFINE

Authority

Bind the AI agent identity, permitted action, resource, value, destination, time window and required approval.

02 / ENFORCE

Firewall

Require a matching signed grant at the executor. No valid grant means no payment, email, export, refund or production change.

03 / PROVE

Evidence

Export signed decisions and audit history. Verify decision signatures in your browser. Check external checkpoints independently of the system that acted.

04 / OPERATE

Coverage

Show which AI agent actions are gated, observed, incomplete or outside control so security, legal and insurance teams see the real exposure.

If the AI agent is compromised

What can the attacker execute with the access you already granted?

Payments, supplier changes, data exports, credentials and production systems become attack paths when AI agent intent reaches them without an independent authority check.

Enterprise team working confidently with AI in a calm, collaborative workplace
Access is not authority.The executor must know the difference.
01 / MONEY

Redirect the payment.

Change the payee, amount, invoice or currency inside a workflow that already has payment access.

02 / DATA AND SYSTEMS

Use the AI agent as the way in.

Export records, expose credentials or call production tools through permissions the organization granted itself.

03 / BINDING ACTIONS

Act in the company’s name.

Issue refunds, send commitments or change critical records before a human sees the consequence.

Your production deployment

Choose the workflow. Prove the block. Go live.

Start with the AI agent actions that put your business at risk. Agree the integration, test the controls and define who operates them.

Operations leader working calmly while an AI agent handles routine tasks
01 / Map

Define the action surface.

Identify AI agents, executors, actions, owners, approval thresholds and the consequences that require hard enforcement.

Finance team reviewing a supplier payment handled by an agent
02 / Enforce

Connect the real executor.

Require one matching grant before the protected system acts.

Insurance and security leaders reviewing verifiable AI evidence
03 / Operate

Monitor control and preserve proof.

Track coverage, policy versions, approvals, evidence gaps and incident records.

AI agent authority. Enforced at execution.

Block. Allow. Record. Anchor.

Your AI agent can propose an action. Fidacy checks its identity and signed permissions before the connected executor acts. Authorized work proceeds. Out-of-scope actions are refused. Signed records make enforcement verifiable.

IDENTIFYAUTHORIZEDECIDEENFORCERECORDANCHOR
A protected agent action stopped at the Fidacy execution boundary
01BLOCK

Stop what exceeds the mandate.

Fidacy Firewall and Spend Guard refuse altered payees, excessive amounts, replayed grants and unauthorized side effects before the connected system is called.

FIREWALLSPEND GUARDHARD GATE
Inspect enforcement →
An agent action passing through an exact Fidacy authority boundary
02ALLOW

Release exactly what was authorized.

KYA binds the workload identity. A signed mandate fixes the action, resource, amount, destination and duration. One matching request receives one executable grant.

KYAMANDATESONE-TIME GRANTS
Build authority →
A sequence of agent decisions preserved as ordered evidence
03RECORD

Preserve the decision and its coverage.

Every ALLOW and DENY is signed. Continuous Control Monitoring shows whether the path was gated, merely observed, incomplete or outside current evidence.

SIGNED JWSCONTROL COVERAGEINCIDENT PACK
See Control Coverage →
Fidacy evidence fixed to an external cryptographic checkpoint
04ANCHOR

Put the evidence outside the argument.

Signed records form hash-linked audit history and Merkle checkpoints. OpenTimestamps anchors those checkpoints to Bitcoin, so confirmed timestamps can be verified outside the operator's system.

HASH CHAINMERKLEBITCOIN
Verify the proof →
Three consequences. Three verifiable records.

Prove the money, the message and the document.

The action is only half the risk. Fidacy preserves neutral evidence of what moved, what was said and which exact artifact existed, without taking custody of the payment, transcript or file.

01 / PAYMENT AUTHORITYHARD GATE

No valid grant.
No money moves.

Bind payee, amount, invoice, currency and expiry. Where the payment rail is connected through Fidacy, an altered, excessive or replayed request is refused before settlement.

REQUESTUS$4,280
MANDATEPAYEE + CAP MATCH
ALLOW · ONE USE
Explore Spend Guard and Firewall →
02 / CONVERSATION RECEIPTSLOCAL HASHING

Prove exactly what the chatbot said.

Hash each message locally, anchor the final session digest through Fidacy and give both sides a receipt they can verify. The transcript stays inside your infrastructure.

AS
Acme SupportAI support agent · online
14:02
CUSTOMER

My card was charged twice. Can you refund the second US$900 payment?

ACME SUPPORT

Yes. I approved the full US$900 refund. You’ll see it within two business days.

SESSION DIGEST SEALED
2 verifiable receipts issuedTranscript retained by Acme
See conversation receipts →
03 / ARTIFACT RECEIPTSBITCOIN CHECKPOINT

Prove the file has not changed.

Anchor the hash of a prescription, insurance claim, contract, invoice, image or recording. Fidacy receives the digest, never the source file.

MEDICAL PRESCRIPTIONSHA-2568d8c3f…a217
VERIFIED
See artifact receipts →
Insurance infrastructure

The evidence layer that makes AI agent risk insurable.

Give underwriters evidence they can verify, not just the operator's account of an incident. Export signed records of decisions, authority and control coverage, with external checkpoint references. Fidacy supplies the evidence, not the insurance policy.

01UNDERWRITEControl Coverage

Current boundaries, policy versions, connector state and evidence gaps.

02CONDITIONVerified controls

Require hard-gated actions and current evidence for protected workflows.

03ADJUDICATEIncident Pack

Identity, mandate, signed decision, receipt, chain position and checkpoint.

NEUTRAL RECORDVerifiable without trusting the model, insured or Fidacy.
Primary sources, not predictions

The liability is not a thesis anymore. It is on the record.

Courts and regulators in three jurisdictions reached the same practical conclusion: an organization remains responsible for the automated action it deploys.

THE VERIFIABLE RECORD4 CONTROL LAYERS
ONE EVENT · FOUR LAYERSChange the record and the public verification fails.
Risk leaders reviewing AI control evidenceCONTROL COVERAGE · LIVE BOUNDARIES
Continuous control monitoring

Know where the control is real, and where the evidence stops.

Fidacy separates a hard gate from a heartbeat, current coverage from historical proof and a complete trail from a telemetry gap.

GATEDA verified execution boundary enforced the grant.
OBSERVEDA current authenticated connector is reporting.
LIMITEDThe latest evidence trail is incomplete.
NO EVIDENCEFidacy will not claim protection it cannot prove.
Neutral authority. Independent verification.

The system that acts should not control the only proof.

Fidacy separates authorization from the agent and anchors evidence outside the operational system. No custody of funds. No percentage of payment value. Verify the record, not the operator's version of events.

FIDACY INCIDENT PACK

Export the evidence. Keep the proof.

Signed audit exports and portable evidence packages preserve decisions and their authority context for independent review. Give auditors, insurers and counterparties records they can check, not screenshots they must trust.

Verify your evidence package →
SIGNEDVerify Ed25519 decision signatures in your browser against published public keys.
CHAINEDRecompute exported audit history to detect altered entries or broken links.
ANCHOREDVerify confirmed Bitcoin timestamps with OpenTimestamps, outside the operator's system.
PORTABLEExport the evidence. Recompute package integrity locally. Keep verification in your hands.
Agent-agnostic by design

The Authority Firewall for AI Agents. Simple to deploy. Difficult to bypass.

Start through an SDK, MCP host or API. One compact layer fits the stack you already run while private prompts, files and tool arguments remain inside your environment.

MCP HOSTS

Claude, Cursor, Codex and more

One local server for agent tools and action boundaries.

npx -y @fidacy/mcp
LANGCHAIN

JavaScript and Python

Wrap the tool so a denied call never executes.

@fidacy/langchain
OPENAI AGENTS

Gate the tool call

Enforce between model intent and the external action.

@fidacy/openai-agents
OPENCLAW

Native agent hooks

Observe sessions, gate actions and export independent proof.

@fidacy/openclaw-plugin
From AI agents to autonomous systems

One authority architecture.From AI agents to autonomous machines.

Fidacy already implements the core authority chain in software: identity, signed mandates, pre-action decisions, enforceable grants, revocation and independently verifiable evidence.

DEPLOYED TODAY

AI AGENT ACTIONS

Money · data · communications · enterprise systems

CORE ARCHITECTURE REUSE≈90%

Already implemented at the software authority layer.

IN DEVELOPMENT NOW

EDGE AUTHORITY

Gateway · device identity · local enforcement · safety validation

Fidacy authority gateway connecting an AI system to a robot, drone and autonomous vehicle
NEXT PRODUCT LAYERFIDACY EDGE AUTHORITY GATEWAY

Mission-level authority for robots, drones, vehicles and safety-critical autonomous infrastructure, without entering the motor-control loop.

≈90% is an architecture-reuse estimate, not physical-product readiness or safety certification.

Intelligence decides what to do.Authority decides whether it may happen.

Test a company workflow

See what your AI agent can do. Prove where it stops.

Bring an email, data or payment workflow. Together, scope a controlled test of permitted actions, blocked requests and verifiable evidence before production.