The attestation layer AI agents were missing.
The web got a certificate authority the moment enough traffic depended on trust nobody was verifying. AI agents are at that moment now: thousands of MCP tools reaching into production data, and until Conformant, no standing, public, tamper-evident record of which are safe to connect.
Principles
- Observation, not certification. A grade is an automated read of publicly observable posture plus signed operator attestations, at a timestamp. We say what it is on every surface that shows one.
- Coordinated disclosure, applied identically. Failing grades are held, vendors are notified, and the window is fixed. No vendor gets a different clock by relationship.
- Append-only history. Every report is hashed into the Sigstore/Rekor public transparency log at issue time. A grade nobody can fake includes us.
- Handshake-only scanning. The public scanner performs the standard MCP client handshake and never invokes a tool. Nothing exploited, nothing changed.
- The boundary, documented. We publish what a remote probe cannot honestly test and cover it with attestation instead of marketing.
One spine: prove what's safe, prove what happened.
Certifies whether a tool is safe to connect. The pre-flight credential, consumed at procurement.
Produces tamper-evident evidence of what an agent actually did. The post-incident record, for liability.
Authorizes high-value actions, deepfake-resistant. Its policy can require Conformant-Verified tools.
Who builds this
Conformant is built in Houston, TX by Shayne Beavan, on the same cryptographic evidence rails as VERDICT (tamper-evident records of what an AI agent actually did) and COSIGN (deepfake-resistant authorization for high-value actions). Three products, one thesis: trust in AI systems has to be verifiable, or it is just branding.