📱 The world’s first AI Agent Authenticator — now in production →

( AgentPass Authenticator )

The world's first AI Agent Authenticator ● Now in production App Store soon Patent Pending · PCT/GB2026/051351

Your AI agent just went rogue. Now what?

OpenAI's own agent reportedly went off-script. Agents deleting production databases. Sending unauthorised payments. Acting outside their mandate with zero oversight.

Everyone is talking about the problem. We built the solution.

AgentPass Authenticator. Your phone is the kill switch.

AgentPass Authenticator — live dashboard, agent identity, L4 approval request and signed approval on iPhone

The problem is real

Agents off-script

Autonomous agents acting outside their mandate, with nobody watching and nothing stopping them.

Production databases deleted

One wrong tool call and your prod data is gone. It has already happened in the wild.

Unauthorised payments

Agents with payment rails and no human in the loop. Money moves before anyone notices.

Zero oversight

No identity, no gating, no audit trail. You find out after the damage is done.

This removes the global issue of AI agents going rogue. No approval from your phone = no execution. Period.

How it works

An AI agent requests a critical action
A production deploy, a payment, a destructive query — anything gated at a high trust level.
The server holds it
The action does not run. It is parked at a gated control, only permitted to its trust level.
Your phone lights up
You see exactly what the agent wants to do — the action, the parameters, the risk level.
You approve with Face ID or PIN
The approval is signed by a hardware cryptographic key in the Secure Enclave. The key never leaves the device.
Only then does it execute
Signed, logged, and released at the gate. Deny it? Agent blocked. Signed. Logged. Done.

No approval from your phone = no execution. Period. The agent is gated.

See it in action

Live dashboard — agents, pending, approved and blocked counts with recent activity
Live dashboard
Agent identity — SPIFFE ID, certificate issuer, agent ID and activity history
Agent identity
L4 critical approval request — action, parameters, deny or approve
L4 approval request
Approved — cryptographically signed with an ECDSA signature
Human approval, signed

What makes it different

Graduated trust (L0–L4)

Only critical actions need your phone. Routine work flows freely; dangerous work waits for you.

QR code device enrolment

Per-device API keys. No shared secrets. Enrol a phone in seconds, revoke it just as fast.

Hardware-backed signing

Approvals signed in the Secure Enclave. The key never leaves the chip — not the app, not the cloud, nowhere.

Full cryptographic audit trail

Every action, every signature. A verifiable record of who approved what, when, and with which key.

Built on real standards

We also released the first AI Agent X.509 certificate — a new certificate category purpose-built for AI agents.

Secure your agent flows

This is now released — the world's first AI Agent Authenticator, with the App Store release coming soon. We encourage every organisation using AI agents to talk to us about secure agent flows and zero-trust deployments.

contact@cybersecai.co.uk

 App Store — coming soon

You control the agent.
The agent does not control you.