Radar / Ideas / VendorPassport: runtime attestation…

VendorPassport: runtime attestation that gets agent vendors through enterprise procurement

daily ideaambitiousJEV confidence 0.532026-09-25
OutcomeAgent vendors close enterprise deals 3x faster: security review in days, not months.

The problem

Enterprise procurement chokes on AI tools because no vendor can answer the security questionnaire with evidence, only marketing claims. EU AI Act Article 12 record-keeping has been enforceable since Aug 2026, and Vanta just shipped 65 agent-specific controls covering gaps ISO leaves open, so buyers now explicitly ask for agent-level evidence. Most agent vendors have nothing an auditor can verify.

The idea

An embeddable runtime-attestation SDK plus one-click compliance dossier for agent platform vendors. Each agent gets a signed persistent identity; every action is hash-chained and optionally gated by an enforcement runtime before sending; every trace is scored against the customer's policy via a cheap typed decision. The vendor exports a signed evidence pack mapped to SOC 2, ISO 27001/42001, and EU AI Act Article 12 that drops straight into the buyer's Vanta or Drata workflow. Sold to the vendor, verified by the buyer's auditors.

Why now

Vanta's Agentic Trust Controls went GA in late Aug 2026 with 65 open controls for agent identity, authority, guardrails, and runtime instrumentation, which means buyer demand is now explicit. Anchor 3.0 enforcement runtimes and enclawed-style signed manifests make the runtime side buildable, and jevals makes per-trace policy evaluation cost ~$0.00006 so 100% trace coverage is affordable.

What it combines

known-dnsid + anchor-3-0 + enclawed + jevals. Identity (who is responsible for this agent) plus enforcement (actions checked against rules before sending) plus audit (signed, hash-chained manifests) plus trace eval (was this run policy-clean, as a typed decision). Any one alone is incomplete: identity without enforcement is a badge, enforcement without audit is unverifiable, audit without per-trace eval cannot say what actually happened. The combination is a complete agent passport.

MVP

Weekend MVP: wrap one existing agent framework with signed run identities, a hash-chained action log, and a jevals policy check per trace, exporting a one-page Markdown evidence pack mapped to 6 SOC 2 criteria. Deliberately skip: the enforcement runtime, EU AI Act Annex IV doc generation, and Drata/Vanta integrations.

Distribution

B2B2C through agent platform vendors (agent builders, support-agent platforms, RPA vendors) that need the dossier to win enterprise logos. Vendors pay $500-2,000/mo per platform tier; free tier for open-source projects seeds adoption and auditor familiarity.

Why it wins

Vanta and Drata verify organization posture, not what an agent does at runtime. Relicta attests release decisions in CI, not runtime behavior. VendorPassport is runtime attestation for the agent itself: identity, enforcement, and per-trace evidence that plugs into the GRC tools buyers already use.

Risks

Biggest risk is vendors treating attestation as a checkbox badge and auditors not trusting a vendor-generated pack. The MVP de-risks this by anchoring to verifiable artifacts (signed chains, per-trace typed decisions) and starting with one design-partner vendor whose buyer's security team validates the dossier.

Build it with

Repo to start from

vendorpassport: SDK for signed agent identities, hash-chained action logs, per-trace policy checks, and a SOC 2 / EU AI Act-mapped evidence pack exporter.

Evidence

Get the week's best AI launches, plus 3 ideas worth building

One email every Saturday. Ranked by traction, not hype. Free.