MC-1 TRUST · CONTROLLED PRODUCTION PILOT

Trust infrastructure
for autonomous intelligence.

Every AI should be identifiable. Every agent should be accountable. Every action should be authorized. Every AI system should be continuously verifiable.

Explore AATS ↗Verify a certificate →Discuss an assessment →
The tenant-scoped Trust API and encrypted evidence vault are live for a controlled pilot. The September 13, 2026 production acceptance snapshot recorded ColomboAI's own Trust tenant as NOT_ASSESSED. Independent certification and Agent Guard enforcement are not enabled.
THE DEPLOYMENT GAP

The trust boundary
extends beyond the model.

Deployed agents gain memory, tools, credentials, data access, providers, and delegated authority. Each connection can change after a point-in-time evaluation.

MODELHARNESS · MEMORY · TOOLSIDENTITY + GUARDAATS CONTROLSCONTINUOUS ASSURANCE
CONTINUOUS AI TRUST INFRASTRUCTURE

Establish trust.
Keep checking it.

MC-1 Trust is being designed as an implementation of the ColomboAI-led, implementation-neutral AATS working draft, linking identity, runtime policy, evidence, assessment, and revocation.

IDENTITY

Know who is acting

Link each AI system and agent to an organization, accountable owner, version, and revocable identity.

AUTHORIZATION

Bound what it may do

Scope tools, data, resources, delegated authority, and expiry before actions are attempted.

ENFORCEMENT

Control execution

Agent Guard and Guard Edge are intended to apply policy at tool and runtime boundaries.

EVIDENCE

Retain what happened

Collect source, timestamp, control, owner, and integrity proof for each assessment input.

ASSURANCE

Reassess as systems change

Model, provider, prompt, tool, permission, and memory changes should trigger fresh review.

VERIFICATION

Make trust inspectable

The Trust API and exact-ID registry expose scoped status without disclosing private evidence.

VERIFIED RELEASE BOUNDARY

Production evidence.
Explicit assurance gates.

Production supports tenant-scoped agent registration, AES-GCM encrypted evidence, assessment records, advisory decisions, state events, and exact certificate lookup. Authentication, cross-tenant denial, ciphertext storage, decryption, and audit-chain integrity have been tested. No independent certificate has been issued. Automated connectors, broad inventory discovery, data maps, permission graphs, and execution-boundary Guard integration remain in development.

PARTICIPATION

For enterprises

Map systems, owners, data paths, authority, and changes.

PARTICIPATION

For developers

Use the public SDK source, CLI, Action, and reference verification flows.

PARTICIPATION

For evaluators

Review scoped evidence under an authorized, logged assessment process once evaluator governance is established.

OPEN DEVELOPER DISTRIBUTION

Inspect the standard.
Build against the trust layer.

The specification, clients, CI readiness check, and reference verification flows are public. Readiness results cover a declared subset of AATS and never confer certification.

PUBLIC SOURCE

AATS v0.9

Public working draft, controls, schemas, examples, governance, and assurance protocol.

View repository ↗
PUBLIC SOURCE

Trust SDK + CLI

Python and TypeScript fail-closed clients with the mc1 trust command suite.

View repository ↗
PUBLIC SOURCE

AATS Action

Static CI checks across 11 of 25 AATS domains, with explicit subset semantics.

View repository ↗
PUBLIC SOURCE

Reference applications

Continuous assurance and pinned-key registry/Passport verification examples.

View repository ↗
AATS · AI & AGENTIC TRUST STANDARD

A standard usable beyond MC-1.

AATS defines proposed control requirements for AI applications and agents. Independent implementations and public review are central to its design.

Read about AATS ↗
MC-1 TRUST · PRICING PREVIEW

Easy to start.
Built to expand.

Proposed launch pricing, subject to infrastructure and commercial review. Preview access is arranged directly; paid checkout is not yet available. Inference and paid third-party evaluations remain separately attributable.

DEVELOPER

$49/month

$490/year

  • 50,000 assurance events/month
  • 10 agents / applications
  • 30 days of history
  • $1 per 10,000 additional units
Discuss preview access →
PRO

$199/month

$1,990/year

  • 500,000 assurance events/month
  • 50 agents / applications
  • 90 days of history
  • $0.75 per 10,000 additional units
Discuss preview access →
BUSINESS

$999/month

$9,990/year

  • 5,000,000 assurance events/month
  • 250 agents / applications
  • 365 days of history
  • $0.5 per 10,000 additional units
Discuss preview access →

Enterprise proposals from $50,000/year, scoped to deployment, retention, capacity, and support.

Usage definitions and release gates →
MC-1 Trust | ColomboAI