Innerlock

Identity, attribution, and fraud detection for AI agent traffic.

1.Problem

AI agents are becoming a large share of automated traffic. Existing bot detection assumes automation is adversarial, and that assumption breaks down when a legitimate agent is acting on a user’s behalf. Identity standards for agents are emerging, but the trust, reputation, and policy layers above them are unsolved.

2.What we’re building

2.1.Attribution

Determining which agent sent a request, who operates it, and whether a person delegated it — building on emerging identity and delegation standards rather than competing with them.

2.2.Reputation

A verified identity says who is asking, not whether the request should be trusted. Reputation built from behavioral signals over time lets a service separate agents acting within their stated purpose from fraudulent traffic, including traffic that presents valid credentials.

2.3.Policy

A way for a service to decide what an agent may do based on attribution and reputation — which actions, at what volume, on whose behalf — and to apply that decision consistently.

3.Research

We publish responsible-disclosure writeups and analysis of the protocols agents use for identity and authorization. Entries will be listed here as they are published.

4.Contact

General
hello@innerlock.ai
Security and disclosure
security@innerlock.ai
/.well-known/security.txt