1.Problem
AI agents are becoming a large share of automated traffic. Existing bot detection assumes automation is adversarial, and that assumption breaks down when a legitimate agent is acting on a user’s behalf. Identity standards for agents are emerging, but the trust, reputation, and policy layers above them are unsolved.
2.What we’re building
2.1.Attribution
Determining which agent sent a request, who operates it, and whether a person delegated it — building on emerging identity and delegation standards rather than competing with them.
2.2.Reputation
A verified identity says who is asking, not whether the request should be trusted. Reputation built from behavioral signals over time lets a service separate agents acting within their stated purpose from fraudulent traffic, including traffic that presents valid credentials.
2.3.Policy
A way for a service to decide what an agent may do based on attribution and reputation — which actions, at what volume, on whose behalf — and to apply that decision consistently.
3.Research
We publish responsible-disclosure writeups and analysis of the protocols agents use for identity and authorization. Entries will be listed here as they are published.
4.Contact
- General
- hello@innerlock.ai
- Security and disclosure
- security@innerlock.ai
/.well-known/security.txt