PERSISTENT
HARNESS
Critical Infrastructure for an Agentic Future

Identity, Delegation and Non-Repudiation

In February 2026, NIST launched the AI Agent Standards Initiative, asking industry to develop standards for agent identity, non-repudiation, and traceable delegation.

The UNS protocol specified exactly those mechanisms in 2019 — the trilateral handshake, signed receipts, federated policy enforcement. ANS extends that protocol with an implementation built for the agent ecosystem that actually exists now: serverless, edge-distributed on Cloudflare, and MCP-native by design rather than retrofit.

I gave up on UNS in 2022 after Google, Apple, Facebook and Microsoft Embraced FIDO, convinced we were 3 years too late.

NIST just told me i was 5 years too early.

Binary decisions for agents that act.

Every tool your agent touches gets a risk-appropriate approval flow — from auto-approve to hardware key. Not probabilistic guardrails. Binary permissions, signed and enforced.

Your agent, anywhere.

Change your environment without changing your agent. Portable Context, ANS Vault, and private relay keep your credentials, your context, and your privacy portable across every host, model, and network.

Three parties sign. Nobody forges.

A cryptographic ceremony between your Guardian, the Service Gateway, and the Coordination Node — every action produces a signed, verifiable receipt that three independent keys stand behind.

Performance

99% of actions are instant.

The full handshake happens at session start and for high-risk escalations. Everything in between is a local credential check.

<1msLocal credential check
~300msFull trilateral handshake
1Handshake per session start
3Signatures per receipt

Open beta

Join a Guardian. Spin up a Gateway. Hold the receipt.

ANS is in open beta. Three live integrations, no vendor lock-in, free to use — help us find the edges and shape what the protocol becomes.

Test Drive