The control plane for autonomous AI
Every consequential AI action answers to ALEETH first.
PROVEN.
ALEETH is the authority your AI answers to.
It sits beneath the model, decides what an agent may do, and fails closed on the act that crosses the line. Every governed call is sealed to a signed record your board, your auditor, and any regulator can verify without taking our word, and without a login.
Shipped. Not a roadmap.
Five things the plane actually does.
Policy before the act. A signed receipt after. A kill switch in the path. Continuous rating. A governed MCP. That is the product. Everything else is a page.
-
The call is denied until the plane says otherwise.
Rail Guard sits in the path, not beside it. Identity, purpose, tool, and arguments resolve before anything runs. Allow is earned, one act at a time.
The control plane -
A live agent that crosses the line is stopped mid-action.
Quarantine latches until a person releases it. There is no timeout that talks the agent out of containment. The halt is sealed before the stop completes.
Containment -
Every decision writes a receipt you can check without us.
Ed25519. Append-only. Hash-chained. Anchored to a public ledger ALEETH cannot rewrite. Allow and deny both leave a record. No receipt, no result.
Verify a receipt -
Continuous rating, not an annual snapshot.
Compass Real Estate of Northwest Iowa holds ICA-2026-0003, score 94, re-rated as it runs. The credential is public. The math is the authority.
The proof surface -
The first MCP that cannot act without permission.
ALEETH Authority. Fifty-one tools. Fail closed. Every call risk-checked by Rail Guard and sealed with a signed L7 receipt. Live at mcp.aleeth.com.
Authority MCP
A control layer you have to trust
is not proof.
Any AI control plane can show you a decision and a dashboard. An auditor, a regulator, and a court ask a harder question: can I verify it myself, without trusting you? With ICA the answer is yes. Every governed action becomes a signed, append-only receipt, anchored to Bitcoin, that anyone can re-check.
- A record you have to trust.
- Editable by whoever holds it.
- Meaningful only inside their system.
- Signed with a key held in hardware, not in the open.
- Append-only, hash-chained, Merkle-anchored.
- Verifiable by anyone, without us in the loop.
The gateway's core invariants are machine-checked in TLA+ - deny-by-default, no authority for a revoked agent, tenant isolation, fail-closed, single-use capabilities - proven over every input, not sampled by tests, and re-checked on every change. No AI-gateway competitor ships machine-checked proofs of its enforcement.
The Relationship Trust engine proves a second, harder claim. It scores the trust between two parties from communication metadata alone - never the content - into a 0 to 100 score. Four safety properties hold by construction: spoofing has a hard ceiling, an untrusted signal cannot inflate trust, no single event can race the score up, and no black-box model sits in the path. You do not have to take that on faith. Send a spoofed stream yourself and watch the ceiling hold.
A claim is a slide. A refusal you can trigger yourself is a demonstration. Six run live on /verify.
Doctrine
We do not propose principles.
We enforce them.
ALEETH writes the rules autonomous systems answer to, and it answers to them itself. The ICA control plane holds to the same constitution it enforces on the systems it governs. Article XI, Self-Governance, makes that boundary structural. The systems ICA governs cannot quietly rewrite the framework that governs them.
LAW II · THE ZERO LAW
The absence of architecture is itself an architecture.
INSTRUMENT
Used before the wave arrives, it functions as governance. Used after, it functions as forensics.
ARTICLE XI · SELF-GOVERNANCE
The system itself operates within the same constitution it enforces.
The product
One plane. Five doors.
01 · CONTROL PLANE
Beneath the model. In the path.
Intercept. Resolve. Decide. Seal. Deny by default. Halt, gate, or quarantine while the act is still preventable.
→02 · AUTHORITY MCP
Fifty-one tools. Every call governed.
The first MCP governed by ICA. Rail Guard before the act. A signed L7 receipt after. Fail closed. Live at mcp.aleeth.com.
→03 · COVERAGE
Every jurisdiction. Every standard.
284 frameworks governed live, from NIST AI RMF and ISO 42001 to the EU AI Act, SOC 2, HIPAA, and enacted state laws. Sentinel Packs span US federal, state, and EU.
→04 · PROVENANCE
Cryptographically proven, public-ledger anchored
Every credential state writes to an Ed25519-signed, append-only chain. The chain is anchored via OpenTimestamps to an independent public ledger that ALEETH cannot rewrite. Verify any credential from any browser, at any time, forever.
→05 · PROOF
Do not trust us. Check it yourself.
Receipts, credentials, and the live halt. No login. No account. No call to us for permission.
→AI Governance Readiness Check
Where does your AI governance actually stand?
Answer six questions. Get an indicative Control Readiness Score and the gap between policy and proof, on the spot, with no login. The paid Control Readiness Assessment confirms the score by testing.
Indicative Control Readiness Score
Projected with ICA in place:
Your widest gaps
This is an indicative score from your profile, not a tested result. The paid Control Readiness Assessment confirms it by testing enforcement and evidence, the two hardest to reach without a control plane.