AgenTrust Research
Identity, enforcement,
and evidence for AI agents.
Technical reports with open source, recorded experiments, and explicit limits. Read the work, inspect the evidence, and cite a specific version.
Research collection7 reports / Not peer reviewed
Runtime evidence
A portable format for runtime claims, with recorded measurements of signing, verification, record size, and conformance fixtures.
Rishabh Poddar, Aaron Fulkerson, Imran Siddique
Version 2 / September 28, 2026 / Technical report
Read the report →Tool-call enforcement
A gateway design combining policy evaluation, session sensitivity, tool-catalog pinning, and signed tool-call records.
Rishabh Poddar, Aaron Fulkerson, Imran Siddique
Version 1 / September 27, 2026 / Technical report
Read the report →Agent identity
A signed baseline for agent artifacts, with recorded Ed25519 benchmarks, delegation checks, and tamper probes.
Imran Siddique
Version 1 / September 27, 2026 / Technical report
Read the report →Model weight custody
A portable custody contract binding exact weights, measured workload, fresh channel-bound release, renewable authority, terminal evidence and derivative lineage.
Imran Siddique
Version 1 / September 27, 2026 / Technical report
Read the report →Delegation evidence
A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.
Rishabh Poddar, Aaron Fulkerson, Imran Siddique
Version 1 / September 27, 2026 / Technical report
Read the report →Governance telemetry
A backend-neutral contract for six governance event families that keeps lossy operational telemetry separate from evidence whose completeness is stated.
Imran Siddique
Version 1 / September 27, 2026 / Technical report
Read the report →Confidential handoffs
A conditional composition argument and proposed handoff contract for when tool calls and delegations preserve an authorized plaintext-holder boundary.
Imran Siddique
Version 1 / September 27, 2026 / Technical report
Read the report →
Read the evidence with the claim
These reports preserve historical designs and software evaluations. A signature, an attestation result, and an execution-completeness claim establish different properties. Each paper page identifies the evidence evaluated and the limits that remain.
For implementation, follow the current project specifications linked from each report. Paper text is available under CC BY 4.0; code retains its project license.