Trustworthy Autonomy™Beta · Q3 2026

An agent that runs your compliance program — and proves every move.

Most compliance AI asks you to trust a black box. Trustworthy Autonomy™ works your posture continuously, gates what matters to you, and leaves a signed, traceable record of every action. You trust it because you can check it — not because we said so.

78Catalyst
Pt
PlatinumRuns the work for you

What it looks like

It proposes. You approve. Nothing moves until you say so.

Your daily surface is an approval queue: every action the agent wants to take — with its reasoning and a signed record — waiting on one click.

Approval queue3 pending

Open finding — S3 bucket made public

Detected 2 min ago · maps to SOC 2 CC6.1 (Logical Access)

signed · Ed25519confidence 0.94verify: fresh <5 min
Reasoning trace
  • The prod-evidence bucket ACL changed to public-read at 14:02 UTC.
  • CC6.1 requires least-privilege access to customer data stores.
  • Public read on a customer data store violates the control → finding opened.
  • Proposed fix drafted below: restore the private ACL (bucket-policy v3).

Apply fix — restore private bucket policy

Reversible · 1 change · queued behind the finding above

signed · Ed25519needs your approval

Refresh evidence — re-run the access scan after the fix

Confirms the control is back in effect · updates your maturity score

signed · Ed25519

The difference

Everyone is optimizing for speed. We’re optimizing for proof.

Autonomous analysis is everywhere now. Autonomous action you can trustis the harder problem — the one that matters when it’s your audit on the line. So we built for a different question: not how fast the agent moves, but whether you can prove it moved correctly.

Speed-first

Move fast, ask later

  • Optimized for how fast the agent moves.
  • Trust is a single switch — on or off.
  • The work is a black box; you take the output on faith.
Integrity-first · Trustworthy Autonomy™

Move provably, every time

  • Optimized for whether the action was right.
  • Trust is a dial you widen one category at a time.
  • Every action is gated to your comfort, and signed for the record.

How trust accrues

Trust isn’t a switch you flip. It’s a ladder you climb.

The same event — a storage bucket goes public, dinging a SOC 2 control — handled at each rung of autonomy. The gate slides only as the track record earns it, and you decide how far.

01

Human in the loop

1.0 · GA Q4 2026
agentDetect the drift
your approval
youOpen the finding
youDraft the fix
youApply the change
youRe-verify & log evidence

It watches. Everything else waits for you — you review the reasoning trace and approve each action.

02

Scoped autonomy

1.5 · H1 2027
agentDetect the drift
agentOpen the finding
agentDraft the fix
your approval
youApply the change
youRe-verify & log evidence

You pre-trust the low-risk categories. It acts inside those lines and logs everything; consequential changes still gate.

03

Goal-oriented

2.0 · H2 2027+
agentDetect the drift
agentOpen the finding
agentDraft the fix
agentApply the change
agentRe-verify & log evidence
gate only if outside your lanes

You set the objective — “maintain SOC 2 readiness.” It plans and acts inside the lanes you opened, and reports progress.

trust accrues →
approve everything
pre-trust categories
set objectives
Agent acts autonomously Waits for your approval the gate — it slides as trust grows

Provable by design · the evidence graph

Every step the agent takes becomes a link you can trace.

As the same event matriculates through the agent’s lifecycle, each step drops a signed, hash-chained node into your evidence graph — wired to the control it proves.

Evidence graph — what each step proves

Control
SOC 2 CC6.1
Logical Access
Artifact
bucket-policy v3
(signed)
Evidence
re-scan = PASS
fresh <5 min

Agent lifecycle — the task matriculating

agentObserve
agentReason
agentPropose
youApprove
agentAct
agentVerify

Audit trail — signed & hash-chained (tamper-evident)

Ed25519
9f2a…c1
Ed25519
4c71…8d
Ed25519
b8e0…2f
Ed25519
1d55…a0
Ed25519
7af3…9b
Ed25519
e60c…44
Anchor
chain head → RFC-3161 timestamp authority
hourly · history frozen

Trace any compliance claim back through the exact action, the agent’s reasoning, who approved it, and the control it satisfies — then prove the chain was never altered. The hourly anchor to a third-party timestamp authority freezes history, so a claim made today can be proven untouched tomorrow.

Measured, not promised

Before you trust an agent, you should see its track record.

We hold Trustworthy Autonomy™ to a published evaluation harness — the same way we put cyber risk in dollars instead of heat-map colors. You see how accurately it performs, by task category, before you widen a single autonomy lane. An agent you can’t measure is one you shouldn’t trust.

What it costs

An Enterprise add-on, priced like the work it replaces.

Trustworthy Autonomy™ turns APRI on for an Enterprise tenant. It is not a separate plan and it cannot be bought without an active Enterprise subscription. The fee replaces the slack you’d otherwise carry as a fractional CISO — not the seat-time of a SaaS dashboard you keep logging into.

Plan tier

Enterprise required

APRI ships only inside the Enterprise plan — alongside MCP access, vendor monitoring, and dedicated support. Trustworthy Autonomy™ is the add-on that turns the agent loose under the gate.

Pricing model

Flat monthly subscription

One predictable monthly fee per org. No per-action metering, no surprise bills when the agent works through a busy quarter. You’re paying for a program owner that runs while you’re asleep — not a meter that ticks every time it does its job.

What you do not pay for

Actions that don’t verify

The substrate refuses to dispatch any action whose chain integrity or canary equivalence won’t hold up — and an action that doesn’t execute never reaches your invoice. Demote a category and forward-looking actions stop until you re-promote.

Already on Enterprise? Get on the design-partner list ↓. Not on Enterprise yet? Talk to us about Enterprise →.

Get in

Trustworthy Autonomy™ opens to design partners in Q3 2026.

Help shape how an autonomous agent earns trust in compliance — or get in line for general availability.

Design-partner beta · Q3 2026

Apply to be a design partner

Three to five teams shape the action taxonomy and approval experience. Reduced pricing, co-marketing rights, and a direct line into the roadmap.

Not ready for beta?

Get early access at GA

General availability is Q4 2026. Leave your email and we’ll tell you the moment it opens.

Or read the methodology paper first.