Agentic Security | GaraTrust by Garantir

Let agents act. Never give them the keys.

Agentic security at scale, through cryptographic enforcement. GaraTrust governs what an AI agent can read and what it can do, binding every privileged operation to the user who requested it. Keys stay non-exportable inside the HSM, and the agent receives the authorized result.

Identity

Authenticated user

Each privileged operation is bound to the user requesting it.

Authorization

Key-boundary enforcement

GaraTrust authorizes the operation before the protected key is used.

Key handling

Authorized result only

Non-exportable keys remain inside the HSM. The agent receives the result.

Supported Use Cases
Delegated Authentication Delegated Decryption Signed MCP Audit Dynamic Agent Identity Ask about your use case

Cryptographic governance for the data agents reach and the actions agents take.

Authenticated user User
Prompt Decrypt tokenized card record 8f2…19c
authenticates
Enterprise identity Identity provider
Microsoft Google Okta Auth0
delegated user authority
Untrusted runtime AI agent
ChatGPT Claude Gemini
Requests an operation on the user's behalf
AES DECRYPT request
GaraTrust key-use policy
ALLOW
Approved data scopeWorkload policyPurpose of use
Evaluates delegated authority, the requested operation, and key-use policy
HSM / KMS
Performed inside AES DECRYPT

Payment-data AES key

ABI Research

The analyst view on Garantir's agentic security.

ABI Research calls Garantir “a breakout star in digital trust,” and frames agentic security not as a new product but as the natural evolution of what GaraTrust already does – the same cryptographic platform, applied to a new use case: autonomous AI agents. Agents are registered as non-human identities and held to the same step-up controls, including a human-in-the-loop model that inserts a required human approval at the point of key access before higher-risk agentic actions can proceed. Read ABI’s full analysis of Garantir’s agentic security and the broader cryptographic services market.

Get the report
ABI Research report: Agent Registries and Agentic AI as Garantir's Fifth Pillar of Digital Trust
Integration

Different integration points. One enforcement model.

Models, agent frameworks, and deployment patterns will keep changing. GaraTrust provides an independent policy and cryptographic control point for agent-initiated use of protected keys and credentials. This enforcement model can integrate at the protected-data boundary, inside the agent harness, or at the tool and MCP layer.

AI runtime

Model + agent harness

Chooses tools and coordinates work across the enterprise stack.

Harness-native policy adapter

Inside the agent's execution environment
Where it lives

Inside the agent's execution environment.

How it connects

The harness passes authenticated user authority and operation context directly into the GaraTrust integration.

Why this layer

Choose this layer when the harness is the common control point across the agent's tools and workflows.

Tool gateway or MCP server

At the tool-execution boundary
Where it lives

At the tool-execution boundary.

How it connects

A gateway can use a GaraTrust-managed, non-exportable client certificate to authenticate the workload over mTLS and, where supported, obtain short-lived service credentials. Sensitive tool calls can also require delegated user identity and an approved policy decision.

Why this layer

Use this layer when workload identity and execution authorization must be enforced at the API or tool boundary.

Encrypted context store

Prompts, responses, and agent state retained by the enterprise
Where it lives

Between customer-controlled encrypted context storage and the OpenAI ZDR endpoint.

How it connects

A customer-controlled AI gateway uses GaraTrust-managed AES keys to decrypt only the context authorized for a request. It sends that context to an eligible OpenAI ZDR endpoint, then encrypts the returned response into customer-controlled storage. OpenAI's ZDR announcement

Why this layer

Use this layer when the enterprise must retain and control conversation history, agent state, and encryption keys. GaraTrust governs encryption and decryption; OpenAI ZDR ensures eligible prompts and responses are not retained after processing.

The fifth pillar

The same GaraTrust platform. A new class of caller.

Agentic Security is GaraTrust's fifth pillar. It applies the same proven architecture already supporting Data Security, Passwordless Authentication, Certificate Lifecycle Management (CLM) & PKI, and Software Supply Chain Security to a new class of caller: AI agents. The same delegated access, policy engine, and HSM-backed cryptographic operations govern agent-initiated requests without creating a separate key silo.

01Register

Dynamic agent identity

Enroll each agent with ephemeral attestation and short-lived credentials issued per session.

02Bind

User-scoped authority

Bind every protected request to the authenticated user – not the agent's service account.

03Gate

Step-up, JIT, and quorum

Require MFA, just-in-time grants, or quorum approval when policy and risk demand it.

04Sign

Per-action integrity

Sign approved actions inside the HSM with a nonce, freshness window, and parameter hash.

05Prove

Signed evidence

Emit a signed, SIEM-verifiable record with the user, agent, scope, and operation.

Non-exportable keys. Policy at every use. Agents come under the same key, identity, and compliance governance the enterprise already applies to its people and machines.

Ready to talk?

Make your agents governable.

See GaraTrust against your environment in a technical demo: agent registration, delegated authority, key-use policy, and your MCP and HSM connectivity.