Authenticated user
Each privileged operation is bound to the user requesting it.
Agentic security at scale, through cryptographic enforcement. GaraTrust governs what an AI agent can read and what it can do, binding every privileged operation to the user who requested it. Keys stay non-exportable inside the HSM, and the agent receives the authorized result.
Each privileged operation is bound to the user requesting it.
GaraTrust authorizes the operation before the protected key is used.
Non-exportable keys remain inside the HSM. The agent receives the result.
Decrypt tokenized card record 8f2…19c
A copied standing credential can be replayed anywhere that continues to accept it.
Payment-data AES key
ABI Research calls Garantir “a breakout star in digital trust,” and frames agentic security not as a new product but as the natural evolution of what GaraTrust already does – the same cryptographic platform, applied to a new use case: autonomous AI agents. Agents are registered as non-human identities and held to the same step-up controls, including a human-in-the-loop model that inserts a required human approval at the point of key access before higher-risk agentic actions can proceed. Read ABI’s full analysis of Garantir’s agentic security and the broader cryptographic services market.
Get the report →
Models, agent frameworks, and deployment patterns will keep changing. GaraTrust provides an independent policy and cryptographic control point for agent-initiated use of protected keys and credentials. This enforcement model can integrate at the protected-data boundary, inside the agent harness, or at the tool and MCP layer.
Chooses tools and coordinates work across the enterprise stack.
Inside the agent's execution environment.
The harness passes authenticated user authority and operation context directly into the GaraTrust integration.
Choose this layer when the harness is the common control point across the agent's tools and workflows.
At the tool-execution boundary.
A gateway can use a GaraTrust-managed, non-exportable client certificate to authenticate the workload over mTLS and, where supported, obtain short-lived service credentials. Sensitive tool calls can also require delegated user identity and an approved policy decision.
Use this layer when workload identity and execution authorization must be enforced at the API or tool boundary.
Between customer-controlled encrypted context storage and the OpenAI ZDR endpoint.
A customer-controlled AI gateway uses GaraTrust-managed AES keys to decrypt only the context authorized for a request. It sends that context to an eligible OpenAI ZDR endpoint, then encrypts the returned response into customer-controlled storage. OpenAI's ZDR announcement ↗
Use this layer when the enterprise must retain and control conversation history, agent state, and encryption keys. GaraTrust governs encryption and decryption; OpenAI ZDR ensures eligible prompts and responses are not retained after processing.
Agentic Security is GaraTrust's fifth pillar. It applies the same proven architecture already supporting Data Security, Passwordless Authentication, Certificate Lifecycle Management (CLM) & PKI, and Software Supply Chain Security to a new class of caller: AI agents. The same delegated access, policy engine, and HSM-backed cryptographic operations govern agent-initiated requests without creating a separate key silo.
Enroll each agent with ephemeral attestation and short-lived credentials issued per session.
Bind every protected request to the authenticated user – not the agent's service account.
Require MFA, just-in-time grants, or quorum approval when policy and risk demand it.
Sign approved actions inside the HSM with a nonce, freshness window, and parameter hash.
Emit a signed, SIEM-verifiable record with the user, agent, scope, and operation.
Non-exportable keys. Policy at every use. Agents come under the same key, identity, and compliance governance the enterprise already applies to its people and machines.
See GaraTrust against your environment in a technical demo: agent registration, delegated authority, key-use policy, and your MCP and HSM connectivity.