Agentic Transaction Control
One agent transaction now touches models, tools, other agents and queues. Every handoff is a disclosure decision.
ZTroven governs each one, and signs a record of what was sent.
The problem
Identity says which agent may connect. It never says which facts this one should receive.
every arrow is a disclosure decision
How it works
01
Identity, purpose and lineage attach before anything leaves.
02
The recipient's permitted view is determined.
03
Facts are removed or tokenized locally, in your process.
04
Only the evaluated bytes go out.
05
A signed, value-free record links to the hop before it.
Fail-closed. If policy cannot be enforced, the hop stops.
Selective disclosure
Sensitivity is destination-relative. One rule for the whole payload gets it wrong in both directions.
the same record, a different view per recipient
The evidence
A record explains the transaction without exposing it — categories and actions, never values.
Why ZTroven
Five layers already guard how agents connect and what they may touch. None of them reaches the moment the payload leaves.
keep all five — this is the one they don't cover
Not "does this contain PII?" — but may this recipient receive this fact.
Agents, tools, webhooks, queues. And nothing centralizes through us.
Tied to the bytes dispatched. Logs are mutable and keep the originals.
Work with us
Pick the workflow that worries you most — sensitive data, more than one recipient. We start there and scope from what we find.
Engagements run in your environment, on your stack. We don't need access to your code or your data.
We work with a small number of teams at a time.