🔑 CyberSecAI is now an official AI Agent Certificate Authority — issuing SPIFFE-enabled agent certificates →
NOW LIVE · Official AI Agent Certificate Authority

( Certificate Authority )

CyberSecAI is now an AI Agent Certificate Authority.

AgentPass now issues short-lived, SPIFFE-enabled X.509 certificates for AI agents directly from our own Certificate Authority. One platform takes you the whole way — from the certificate that proves an agent's identity, to the enforcement that controls what that agent is actually allowed to do.

The full end-to-end trust model, fully compliant, with zero-friction deployment. No sidecars. No proxies. One API call. We continue to work with our CA partners worldwide.

( The complete model )

From certificate to control.

A certificate proves who an agent is. It does not stop the agent doing something it should not. AgentPass closes that gap. The same identity that is issued at the certificate is enforced on every action the agent takes — in real time, with a signed, permanent record.

01

Certificate issued

A short-lived X.509 cert from the AgentPass CA. SPIFFE identity, auto-rotating, instantly revocable.

02

Trust level assigned

The L0-L4 trust level is signed into the certificate. Earned sequentially, never self-granted.

03

Every action signed

MCPS signs each action with ECDSA P-256 — the action itself, not the channel. Court-admissible.

04

Policy enforced

The gateway allows or blocks in real time. Payments sanctions-screened, criticals need human approval.

05

Evidence recorded

Every decision lands in a SHA-256 hash-chained ledger. Tamper-evident, exportable for auditors.

06

Kill switch

Detect, revoke, preserve. Instant containment the moment an agent steps out of line.

( Issued from the AgentPass CA )

A real certificate, purpose-built for agents.

Every AI agent receives an ephemeral certificate at creation, automatically issued and rotated by the AgentPass Certificate Authority. No manual provisioning. No long-lived credentials. No shared secrets.

Algorithm
ECDSA P-256FIPS 186-5 · SHA-256 signatures
Format
X.509 Version 3RFC 5280 compliant
Validity
1-day ephemeralAuto-rotating, instantly revocable
Identity
SPIFFE v1.0Workload identity in the URI SAN
Signed into the cert
Trust level + jurisdictionL0-L4 and region carried as signed X.509 extensions
Chain
Agent → Intermediate → RootAgentPass Root CA (CyberSecAI Ltd)

Zero-friction deployment. Drop it into any framework — the certificate, the trust level and the enforcement arrive together, from one API call.

( Trust and jurisdiction )

Trust is built into the certificate.

The agent's authority is not a policy sitting somewhere else — it travels inside the certificate. Any relying party reads the trust level straight from the cert.

L0
Identity only
Agent exists, cryptographic identity issued.
L1
Read / Query
Agent can read data and query systems.
L2
Write / API
Agent can call APIs and modify data.
L3
Financial
Agent can execute payments — sanctions screened.
L4
Critical
Agent requires hardware-backed human approval.

Sovereign AI. Jurisdiction is signed into the certificate under OID 1.3.6.1.4.1.66339.2.*, so an agent is region-locked at issuance and operates only within its authorised region. Each region carries its own trust anchor and legal standing.

EUUKLATAMAPACUSMEA

( Standards & compliance )

Standards-based, not proprietary.

Built on published standards and an IANA-registered namespace, mapped to the regulation that matters.

RFC 5280FIPS 186-5SPIFFE v1.0RFC 6125 IANA PEN 66339OWASP AISVSEU AI ActeIDAS 2.0 LGPDPCT/GB2026/051351
Technical sheet · AIC

CyberSecAI AI Agent Certificate Technical Sheet

The full specification of the AgentPass Agent Identity Certificate — CA hierarchy, cert profile, trust levels, per-action signing, sanctions screening, evidence ledger and standards mapping. PDF, one click.

Download PDF

( CA Partners )

We still work with CA partners worldwide.

AgentPass issues from its own CA by default. For regulated industries that need local legal standing, we also partner with regional Certificate Authorities to issue Agent Identity Certificates — the same X.509v3 certificate category, under your trust anchor. Regional exclusivity available.

New revenue stream

Offer your enterprise customers a certificate product nobody else has.

Standards-based

AIC is defined in IETF Internet-Draft draft-sharif-x509-agent-identity-profile.

Registered namespace

IANA OID 1.3.6.1.4.1.66339 — 19 sub-arcs defined.

Patent pending

PCT/GB2026/051351, 157 countries, priority date 5 March 2026.

Issue under your anchor

Your CA issues the identity; AgentPass enforces the trust.

What is an AIC?

An Agent Identity Certificate is a standard X.509v3 certificate with a custom extension (OID 1.3.6.1.4.1.66339.2.1) that carries:

  • Agent trust level (L0–L4)
  • Agent capabilities
  • Agent class (13 defined categories)
  • Owner attribution
  • Kill switch URI
  • Delegation constraints
  • Cryptographic workload identity

The certificate is verified by any relying party, portable across any cloud or platform, and revocable in real time.

Certificate validation levels

Four policy OIDs define the level of validation performed:

AV
Agent-Validated
CA verified the agent name and key binding.
OAV
Organization-Agent-Validated
CA verified the agent and operating organization.
EAV
Extended-Agent-Validated
Extended due diligence on agent, operator, and context.
AA
Autonomous-Agent
Agent operates without human operator; CA verified deploying organization.

Partner integration

Your CA platform issues AICs using our registered OID. We provide the integration playbook, certificate profile configuration, CSR pipeline setup, and ongoing support.

Works with:

EJBCADigiCertSectigoEntrust AWS Private CAGCP CASHashiCorp Vaultstep-ca Any CA platform supporting custom X.509v3 extensions

Put a verifiable identity on every agent.

Talk to us about issuing AgentPass certificates for your agents, or becoming a regional CA partner. We will get you from zero to signed, enforced agents fast.