Prove what your agents actually did.
Kessa is a self-hostable, independent verifier for AI agent delegation and attestation. It re-derives the authorization history of any agent action from exported evidence alone, trusting no running service, no database, and specifically not the enforcement point that produced the log.
Any consequential agent action, provably traceable to an authorizing human.
Autonomous agents increasingly act under a delegation chain: a human authorizes an org, an org authorizes an agent, an agent authorizes a sub-agent. Kessa records every consequential action in a tamper-evident audit log, and lets an independent verifier re-check that record without trusting anyone who wrote it, including the system that enforced it.
did:web, verifiable credentials, and standard cryptographic primitives, inheriting the web's own trust model.
The repository is public. kessa verify runs offline, with no dependency on
anything Kessa operates: clone it, cut the network, and it re-derives every verdict from
signed evidence alone.
The codebase has been through multiple rounds of self-run AI red-team review, not a third-party audit. Every finding, and where each one stands, is recorded in a public register. Room for two design partners.
AGPL-3.0-only core. Apache-2.0 verifier.
The enforcement engine, proxy, issuer, and agent are AGPL-3.0-only. The independent verifier and designated plugin interfaces are Apache-2.0, so the part whose entire value is running trusted by no one, including us, isn't the part you need our permission to use. Organizations that cannot meet the AGPL's terms are welcome to discuss a separate commercial licence: sales@gneiss-group.com.
Get in touch
Whether you're evaluating Kessa as a design partner, thinking about agent governance for your own org, or just want to know more, reach out.
info@gneiss-group.com →