Trustworthy Autonomy™Beta · Q3 2026
An agent that runs your compliance program — and proves every move.
Most compliance AI asks you to trust a black box. Trustworthy Autonomy™ works your posture continuously, gates what matters to you, and leaves a signed, traceable record of every action. You trust it because you can check it — not because we said so.
What it looks like
It proposes. You approve. Nothing moves until you say so.
Your daily surface is an approval queue: every action the agent wants to take — with its reasoning and a signed record — waiting on one click.
Open finding — S3 bucket made public
- The
prod-evidencebucket ACL changed topublic-readat 14:02 UTC. - CC6.1 requires least-privilege access to customer data stores.
- Public read on a customer data store violates the control → finding opened.
- Proposed fix drafted below: restore the private ACL (bucket-policy v3).
Apply fix — restore private bucket policy
Refresh evidence — re-run the access scan after the fix
The difference
Everyone is optimizing for speed. We’re optimizing for proof.
Autonomous analysis is everywhere now. Autonomous action you can trustis the harder problem — the one that matters when it’s your audit on the line. So we built for a different question: not how fast the agent moves, but whether you can prove it moved correctly.
Move fast, ask later
- Optimized for how fast the agent moves.
- Trust is a single switch — on or off.
- The work is a black box; you take the output on faith.
Move provably, every time
- Optimized for whether the action was right.
- Trust is a dial you widen one category at a time.
- Every action is gated to your comfort, and signed for the record.
How trust accrues
Trust isn’t a switch you flip. It’s a ladder you climb.
The same event — a storage bucket goes public, dinging a SOC 2 control — handled at each rung of autonomy. The gate slides only as the track record earns it, and you decide how far.
Human in the loop
It watches. Everything else waits for you — you review the reasoning trace and approve each action.
Scoped autonomy
You pre-trust the low-risk categories. It acts inside those lines and logs everything; consequential changes still gate.
Goal-oriented
You set the objective — “maintain SOC 2 readiness.” It plans and acts inside the lanes you opened, and reports progress.
Provable by design · the evidence graph
Every step the agent takes becomes a link you can trace.
As the same event matriculates through the agent’s lifecycle, each step drops a signed, hash-chained node into your evidence graph — wired to the control it proves.
Evidence graph — what each step proves
Logical Access
(signed)
fresh <5 min
Agent lifecycle — the task matriculating
Audit trail — signed & hash-chained (tamper-evident)
Trace any compliance claim back through the exact action, the agent’s reasoning, who approved it, and the control it satisfies — then prove the chain was never altered. The hourly anchor to a third-party timestamp authority freezes history, so a claim made today can be proven untouched tomorrow.
Measured, not promised
Before you trust an agent, you should see its track record.
We hold Trustworthy Autonomy™ to a published evaluation harness — the same way we put cyber risk in dollars instead of heat-map colors. You see how accurately it performs, by task category, before you widen a single autonomy lane. An agent you can’t measure is one you shouldn’t trust.
What it costs
An Enterprise add-on, priced like the work it replaces.
Trustworthy Autonomy™ turns APRI on for an Enterprise tenant. It is not a separate plan and it cannot be bought without an active Enterprise subscription. The fee replaces the slack you’d otherwise carry as a fractional CISO — not the seat-time of a SaaS dashboard you keep logging into.
Enterprise required
APRI ships only inside the Enterprise plan — alongside MCP access, vendor monitoring, and dedicated support. Trustworthy Autonomy™ is the add-on that turns the agent loose under the gate.
Flat monthly subscription
One predictable monthly fee per org. No per-action metering, no surprise bills when the agent works through a busy quarter. You’re paying for a program owner that runs while you’re asleep — not a meter that ticks every time it does its job.
Actions that don’t verify
The substrate refuses to dispatch any action whose chain integrity or canary equivalence won’t hold up — and an action that doesn’t execute never reaches your invoice. Demote a category and forward-looking actions stop until you re-promote.
Already on Enterprise? Get on the design-partner list ↓. Not on Enterprise yet? Talk to us about Enterprise →.
Get in
Trustworthy Autonomy™ opens to design partners in Q3 2026.
Help shape how an autonomous agent earns trust in compliance — or get in line for general availability.
Apply to be a design partner
Three to five teams shape the action taxonomy and approval experience. Reduced pricing, co-marketing rights, and a direct line into the roadmap.
Get early access at GA
General availability is Q4 2026. Leave your email and we’ll tell you the moment it opens.
Or read the methodology paper first.