Investor briefing · August 2026

The firewall between AI agents and the real world.

Fidacy lets a company know its agent, give it narrow authority, stop what falls outside that authority and prove what happened later.

Every ALLOW and DENY is signed. No custody. No percentage of the transaction. Independent evidence by design.

The category

Agentic systems can act before anyone has built the authority layer.

The agent ecosystem is building identity and payment rails. The hard question in every consequential action sits above both: was this exact action inside what a human or company authorized, and can an independent party verify it later?

40%of enterprise applications are forecast to feature task-specific AI agents by the end of 2026.
60%of brands are forecast to use agentic AI for one-to-one interactions by 2028.

Sources: Gartner, August 2025 and Gartner, January 2026.

Where the opportunity begins

Trust is the missing control at the point of action.

The opportunity is not every agent or every chat. It is the consequential work companies are beginning to delegate: refunding a customer, changing a CRM record, sending an external email, exporting data or touching a system of record. Each action has an owner, a policy and a liability question.

Premium illustration of a Fidacy control boundary between an AI agent and enterprise systems
THE PRODUCT

Automation that can prove its limits.

At a connected execution boundary, Fidacy turns a model request into a signed decision before a payment, customer-data export or production change reaches the world.

CONTROL EVIDENCE
AT RUNTIME
THE BUYER

Owners of consequential workflows

Operations, finance, security and risk teams accountable for the action, loss and explanation.

4 STATES

Visible control coverage

GATED, OBSERVED ONLY, LIMITED or NO CURRENT EVIDENCE. The buyer sees where the control is actually active.

1 PACK

Evidence for an insurer or auditor

An Incident Pack brings the identity, authority, decision, execution state and proof together for independent review.

The opportunity is measured by consequential workflows an enterprise is prepared to delegate, not by a market-share forecast. Control Coverage and Incident Packs are live Fidacy product capabilities.

The missing layer

Every agent economy needs three layers of trust.

IDENTITY

Who is the agent?

Keys, credentials and provenance identify the software that is requesting access.

EXECUTION

Can it move value?

Payment rails, tools and systems execute actions across money, data and customer operations.

FIDACY

Was it authorized?

Authority before action and proof after it. This is the layer that decides a dispute.

The market is assembling the rails

Identity and execution are being built. Authority is still missing.

The agent economy is not waiting for one platform to win. It is forming through interoperable layers. Fidacy occupies the layer that must remain independent from the agent and the rail when accountability matters.

IDENTITY

Who is asking?

Agent identity is becoming an explicit category across the ecosystem.

VISA TRUSTED AGENT PROTOCOL
SKYFIRE · CROSSMINT
EXECUTION

What can move?

New rails are allowing agents to trigger payments and external-system actions.

STRIPE MPP · AWS AGENTCORE
X402 AND OTHER RAILS
FIDACY

Was it authorized?

A signed authority boundary and a neutral receipt, available before and after a consequential action.

AUTHORITY BEFORE ACTION
PROOF AFTER ACTION
The product platform

One boundary. Six operating layers.

The firewall is the moment an unsafe action stops. Fidacy is the platform that makes that moment defensible: it knows the agent, binds its authority, enforces the boundary, exposes control coverage and leaves evidence that an outside party can verify.

FIDACY CONTROL PLANECONTROL ACTIVE
01 · KNOW YOUR AGENT

Verified identity

The workload arrives with an agent identity, registered key and provenance that Fidacy can bind to the request.

did:web:acme/support
key possession verified
02 · AUTHORITY + ENFORCEMENT

Decision before execution

A mandate checks action, system, amount, expiry and delegation. Only an exact match receives one execution grant.

ALLOW · JWS signed
grant: single use
03 · REAL-WORLD ACTION

Controlled side effect

Payment rails, CRM, email, files and production systems receive only the action that passed the boundary.

stripe.refund.create
US$24.00 · executed once
CONTROL COVERAGEGATED, OBSERVED ONLY, LIMITED or NO CURRENT EVIDENCE
DECISION RECEIPTSigned ALLOW, REVIEW or DENY bound to the policy in force
INCIDENT PACKOne export for an auditor, insurer or opposing counsel
INDEPENDENT PROOFAppend-only audit, Merkle checkpoint and Bitcoin anchor
01 · KYA

Know Your Agent

Register and verify the agent identity, its public keys, DID and workload provenance. Identity is an input to the decision, not a vague label in a log.

02 · AUTHORITY

Mandates and policy

Set exactly what an agent may do, to which resource, for how long, within which budget and whether it may delegate authority.

03 · FIREWALL

Hard execution gate

Fidacy issues a short-lived, single-use grant only after the action passes. A DENY creates no executable permission.

04 · COVERAGE

Continuous control monitoring

Show which agent hosts are connected, which workflows are hard-gated, when the last valid signal arrived and where coverage is limited.

05 · ASSURANCE

Evidence for a third party

Export the authority, decision, execution status and receipt in an Incident Pack. The same evidence serves the operator, auditor and insurer.

06 · INTEGRATIONS

Where agents already run

MCP, OpenClaw, LangChain, OpenAI Agents and CrabTrap connectors let Fidacy meet agents at their actual execution boundary.

The market is already asking for it

Five signals. One unresolved question.

The point is not that these companies agree with Fidacy. Their public work independently identifies the same primitives: identity, authority, provenance and transitive trust.

01 · BREX

Auditing is already a product surface.

CrabTrap validates the need to inspect agent behavior. Fidacy extends local control into an externally verifiable signed verdict.

02 · MICROSOFT SECURITY

Agent identity is still unresolved.

Agent identity has emerged as a core unsolved security question. Fidacy pairs cryptographic identity with an explicit signed mandate.

03 · GOOGLE SECURITY

Excessive agency is a real risk.

Agent-security guidance treats excessive agency, provenance and auditability as first-order problems, not product polish.

04 · IBM

Trust must cross organizations.

On-behalf-of action and transitive trust matter when the party verifying the action is not the party that ran the agent.

05 · WORLD / A16Z

Identity alone is not enough.

The agentic internet needs to distinguish a human, an agent acting for a human and an autonomous agent. Fidacy provides the mandate and provenance layer.

THE GAP

Who proves the authorization?

Identity and payment execution cannot resolve a dispute on their own. A neutral party has to verify the boundary.

US$9.5MSkyfireUS$18MCatena LabsVISA + AMEXNekuda backingUS$33MBasis Theory Series BAWSAgentCore Payments
Why now, why Fidacy

We win as agents, rails and systems multiply.

Fidacy does not compete to own the payment, the model or the agent. It sits between agents and real-world systems as a neutral control plane. Every new rail, model and agent framework becomes another surface that needs authority and proof.

AGENT-AGNOSTICDesigned for local agents, hosted agents and multi-agent systems.
RAIL-AGNOSTICAuthority can govern payments, CRM changes, messages and sensitive tools.
OPEN PATHPublished work on UCP and A2A trust-verdict bindings.
INDEPENDENTFidacy cannot be judge, rail and beneficiary of the same transaction.
Go-to-market and business model

Start with one accountable workflow.

Fidacy is independent of rails and agent frameworks. It verifies the agent, binds narrow authority, gates the action where connected and leaves evidence a third party can independently inspect.

BEACHHEAD

Agentic customer operations

Refunds, credits, account changes and customer messages. The buyer owns the workflow, the loss and the explanation.

EXPANSION

Control for consequential actions

Finance, marketplaces, insurance, CRM, ERP, enterprise software and sensitive systems.

PLATFORM

Common authority and evidence layer

One product surface for identity, mandates, enforcement, Control Coverage and independently verifiable proof.

PAID DESIGN PARTNEROne workflow, a named owner, hard-gated execution and a verifiable evidence package.
ENTERPRISE PLATFORMRecurring authority, enforcement, coverage and proof across protected actions and connected systems.

The next commercial proof point is a paid deployment with repeatable value in a consequential workflow.

Stage and go to market

Production product. Commercial proof is next.

PRODUCTEngine, firewall, receipts, Control Room and authority builder are live.
INTEGRATIONPublished packages for MCP, OpenClaw, LangChain, OpenAI Agents and CrabTrap.
COMMERCIAL WEDGEOne agent, one high-consequence workflow, one accountable owner.
IMMEDIATE MILESTONEThree paid design partners and repeatable 14-day deployments.
The founders

Built by operators who have already worked where trust, identity and money meet.

Lucas De Lima and Bianca Brandalise, Fidacy founders
LUCAS DE LIMA · CEO    /    BIANCA BRANDALISE · COO

First people, now agents.

The founders previously built and exited a regulated cross-border business. Fidacy carries the same operating questions into the agent economy: who is this party, what may it do, and can the answer be proved later?

Fidacy is built under ZeepCode Group LLC, a Florida company formed in 2023, with the US expansion anchored in Florida and a cross-border operating base across the Americas and Europe.

Lucas De LimaCEO. Product and engineering. Builds the core authority, proof and agent-integration layers.
Bianca BrandaliseCOO. Banking background, regulated-industry discipline and commercial operations.
The company being built

Make consequential AI safe enough to deploy, then verifiable enough to scale.

Fidacy starts by protecting a single real-world agent action. The company it can become is the neutral authority standard that the entire agent economy relies on.

Continue the conversation