Skip to content
Metamynd
Platform

The Trust Fabric for the Agentic Economy

A modular, API-first infrastructure for AI trust — verifiable DIDs, VC-issued mandates, a deterministic allow / observe / block / escalate policy engine, Hedera-anchored signed evidence and the HCS-28 Trust Index, exposed as composable engines.

Platform Overview

Trust as programmable infrastructure

Metamynd turns identity, authority, governance, evidence, audit, risk, certification and trust into reusable platform services — composable through one API-first Trust Fabric.

IdentityAuthorityCredentialsPolicyEvidenceAuditTrustRiskCertificationRegistryFederationTrustOps
Core Engines

One platform, composable engines

Each engine is independently useful and works together across the Trust Fabric.

Trust Fabric

The substrate that links identity, policy, evidence and the trust index into one consistent, on-chain view.

  • Deterministic policy-core
  • Identity (DIDs)
  • Signed evidence on Hedera
  • The Trust Index
View engine

Identity Engine

Issues each agent a verifiable, self-certifying DID and proves control of its key — the root every other engine trusts.

  • did:hedera / did:key
  • Key proof (verify-key / BYOK)
  • Public DID resolver
  • HCS registry anchoring
View engine

Ownership & Delegation

Binds an agent to its owner and to a VC-issued mandate — with instant revocation.

  • Verified principal (KYC/KYB), or a disclosed free-tier allowance
  • VC-issued mandate (scope, caps, merchants)
  • Resource scope — which systems and data
  • Sub-delegation that can only narrow
  • Delegated issuance
View engine

Agent Passport

A signed, portable snapshot of an agent's identity, ownership, declared purpose and current capabilities — composed from data the platform already tracks.

  • Signed identity + capability snapshot
  • Composed from existing identity/version/assurance data
  • Independently revocable from containment
  • Reissued as the agent's profile changes
View engine

Credential Authority

Issues, presents and verifies W3C Verifiable Credentials — with selective disclosure and on-chain anchoring.

  • Verifiable Credentials (identity, entity, mandate)
  • BBS selective disclosure
  • Ed25519 platform issuer
  • Anchoring & revocation
View engine

Policy Engine

The deterministic core: composes Standards & SOPs from atoms and returns allow / observe / block / escalate — no LLM in the decision.

  • Atom → molecule → SOP/Standard
  • allow / observe / block / escalate
  • Deterministic & re-derivable
  • Live edits, no redeploy
View engine

Governance Engine

The authorize gate that runs the policy on every signed action, in cooperative or trustless mode, with human-in-the-loop escalation.

  • The authorize gate (MAGP)
  • Escalation → owner approval
  • Standards compliance check
  • Cooperative & trustless modes
View engine

Action Passport

A signed, single-use proof that one exact action was authorized — bound to that authorization alone, carrying no raw payload content.

  • Issued only on allow / observe
  • Bound 1:1 to a single authorization
  • No amount, merchant or payload data
  • Paired Execution Receipt proves payloadMatch
View engine

Credential Vault

Encrypted-at-rest storage for the upstream credentials your agents need — released just-in-time, only to a gateway, only against a currently-active Action Passport.

  • AES-256-GCM at rest
  • One release path, gated on two factors
  • Tenant derived from the passport, never the caller
  • Every attempt audited, plaintext never logged
View engine

Evidence Engine

Signs every decision, batches them into a Merkle root, anchors it on Hedera, and lets anyone verify a record offline.

  • Ed25519-signed receipts
  • Merkle batching
  • HCS anchoring
  • Offline verification (magp-evidence)
View engine

Audit Engine

Turns the signed evidence into a reconstructable, regulator-ready record — with inclusion proofs against an anchored root.

  • Immutable audit / regulator log
  • Merkle inclusion proofs
  • Reason-code decision trail
  • Downloadable, offline-verifiable
View engine

Supervisory Access

A scoped, revocable seat for a regulator or supervisor — with a hash-chained log of everything they read.

  • Grant-based, time-bounded access
  • Scoped to decisions, controls or proofs
  • Hash-chained access log
  • Readable by the supervised organisation
View engine

Trust Engine

Computes a signed, HCS-28 trust score per agent from its verified identity and governance track record.

  • HCS-28 Trust Index
  • Weighted adapters + coverage
  • Drift monitoring
  • Signed, publishable records
View engine

Risk Engine

Routes risk in proportion to impact — high-risk actions and low-trust counterparties escalate to a human, they don't fail silently.

  • Risk-tiered escalation
  • Policy thresholds (atoms)
  • Trust-guidance routing
  • Incident & near-miss reporting
  • Proportional, not binary
View engine

Registry Services

Authoritative, federatable on-chain registries for agent identities and published trust records.

  • HCS-2 identity registry
  • Agent DID registry
  • HCS-28 trust registry
  • Federatable / discoverable
View engine

Certification Authority

Issues living certifications backed by assurance-graded verification, continuous evidence and the Trust Index.

  • Assurance-graded KYC/KYB
  • Living certificates
  • Digital trust marks
  • Auto-revoke on drift
View engine

AI Sandbox

A public, no-KYB environment that hands you a governed agent — first allow / observe / block / escalate in minutes.

  • Public no-KYB endpoint
  • Shared, pre-issued test agent
  • Live allow / observe / block / escalate
  • Same code to production
View engine

Incident Management

Contains a misbehaving agent immediately — revoke its mandate, fail closed, and keep the signed record.

  • Instant mandate revocation
  • Fail-closed containment
  • Escalation queues
  • Post-incident evidence
View engine

Event Fabric

The signal backbone — verification and status webhooks, escalation polling and evidence-flush events.

  • Verification / contact webhooks
  • Escalation status polling
  • Evidence batch flush
  • Real-time trust signals
View engine

Security Architecture

Security-by-design: signed, fail-closed, PII encrypted at rest, only commitments on-chain, and quantum-resistant channels.

  • Ed25519 + hybrid post-quantum
  • Encryption at rest (AES-256-GCM)
  • On-chain commitments, not PII
  • Fail-closed by default
View engine

Deployment Architecture

Runs on Hedera (testnet or mainnet), self-hostable, with configurable, sovereign HCS topics.

  • Hedera testnet / mainnet
  • Self-hostable / sovereign
  • Configurable HCS topics
  • Cloud / on-prem / federated
View engine

Build on the Trust Fabric

See how Metamynd establishes identity, evidence, governance and continuous trust across your AI estate.