PERSISTENT
HARNESS
Critical Infrastructure for an Agentic Future

Agent Continuity

Your agent, anywhere.

Change your environment without changing your agent. Portable identity, portable context, portable credentials, portable privacy — across every host, model, and network.

Service DomainUser DomainPersistent HarnessTrilateral Handshakesign_token_requesttrustsMCP PROTOCOL LAYERkey lookupkey lookupREST API LAYER/api/* portals/api/* dashboardscallback👤UserHuman Principal🤖AgentUntrusted Transport🚪GatewayService AnchorCoordinationNodeTrust Registry🛡️GuardianIdentity Provider☁️ServiceAPI / ApplicationMCP Protocol LayerAgent relays signed tokens via MCP tools.MCP protocolKey verificationDelegationCallback
IDENTITYMEMORYCREDENTIALSPRIVACY

Four core elements of Persistent Agent

IDENTITY

You own your agent.

Every layer underneath — host, network, model, credentials — wants to own you. Persistent Harness prevents them from locking you in

Your agent’s address persists across hosts, models, and networks.

Move your agent anywhere — its address and service relationships follow.

  • Service relationships preserved — no reconfiguration, no broken integrations, no lost history.

A durable, portable identity

One address that follows your agent across hosts, models, and networks.

MEMORY

You built a sandcastle

Your agent is built on top of a model whose memory is a context window. Everything it works out, decides, or commits to lives there — until it doesn’t.

Context resets on session close, crash, timeout, rate limit, or overflow and the model’s working state, decisions, and reasoning don’t survive the session. Switching models means starting from scratch.

With Persistent Harness, a structured checkpoint prompt is periodically injected into the conversation stream, capturing the models working state, decisions, open threads, facts, and commitments. MCP tool traffic is logged continuously, creating durable, model-independent record of everything the model knew about your agent at every checkpoint. This gives you the ability to replay agent history and recover lost information. Your archive lives in your own Cloudflare R2 bucket, encrypted with a key derived from your Guardian passkey.

CREDENTIALS

You gave your agent your keys without a keychain.

To give your agent real service access, you pasted API tokens into .env files, system prompts, and config.

Those credentials now live wherever the agent runs — in plaintext, in logs, in stack traces.

  • Every framework looks in a different place: OPENAI_API_KEY here, .env.local there, wrangler secrets somewhere else.
  • Pasted tokens live forever and carry full scope — no log of which agent used which credential at 3 a.m.
  • Anything in the agent’s context — a stack trace, a prompt injection, a log — can exfiltrate the credential.

Persistent Harness Credential Vault — a password manager for agents

Your agent proves who it is through ANS; the Vault proves what it’s allowed to do with your real credentials — without ever handing those credentials to the agent, to ANS, or to anyone else.

  • The agent asks the Vault to act. The Vault acts on the authorized scope. The token never leaves.
  • Every access cryptographically signed, scope-limited, rate-limited, and logged.
  • Revoke anytime. Rotate upstream credentials without touching a single agent config.

PRIVACY

A private relay

Deploying autonomous agents through fixed endpoints leaves network footprints that severely compromises operational security and allows external observers to correlate agent queries, map behavioral routines, and backend orchestration over time. These traffic patterns expose agent workflows to passive surveillance and cross-session tracking while leaking strategy and competitive intelligence.

Agent Traffic in your Persistent Harness is proxied through Cloudflare to hide your origin IP addresses and server fingerprints behind a shared edge network, preventing observers from tracking your physical hosting or linking distinct agent interactions. It safeguards operational strategy by allowing you to silently migrate backend infrastructure, enforce security policies, and switch AI models without changing public endpoints. Furthermore, it protects competitive intelligence by blending request volumes and burst patterns into shared traffic pools, making it nearly impossible for anyone to profile your tool integrations, usage spikes, or orchestration topology.

Open beta

Move your agent. Keep everything.

Portable identity, portable context, portable credentials, portable privacy. One open protocol, federated by design. Your users carry their trust between agents — and you stop building it from scratch.

Test Drive