Secure every action your Agent takes.
Three products, one security platform — from credential custody to policy execution to compliant payments.
Platform architecture
Wallet / Console
AI Agent / Orchestrator
Immutable audit logs
APIs / DEX / On-chain Protocols
From a developer's perspective, focus on two flows: Agent ⇄ Vault/Control/Facilitate (operations within policy), and Audit/Monitoring (observing and verifying execution).
Three core execution capabilities.
toani Vault
Zero-trust credential vault — keys never leave the hardware boundary.
How do Agents securely perform authentication and key operations?
- All credential operations isolated inside Intel SGX enclaves
- Four-layer key hierarchy with per-credential encryption
- TEE Sandbox Browser for secure web interactions
- Immutable audit logs with Merkle tree verification
toani Control
Enterprise-grade policy engine — define exactly what Agents are allowed to do.
What is the Agent allowed to do, and within which boundaries?
- Policy Engine with tenant, namespace, and action-level rules
- Risk tiering with automatic human-in-the-loop escalation
- Dual-TEE model: SGX for keys, SEV-SNP + gVisor for execution
- Exportable compliance proof and execution receipts
toani Facilitate
Agentic Commerce security layer — compliant, authorized, auditable transactions.
Is this Agent-initiated transaction compliant and authorized?
- Dual KYC/AML: both payer and payee verified before each transaction
- Google AP2 cryptographic trust chain with Intent Mandates
- Atomic USDC settlement via x402 protocol on Base
- Fail-closed design — rejects payments when any check fails
Core capabilities at a glance.
| Dimension | toani Vault | toani Control | toani Facilitate |
|---|---|---|---|
| Core Scenario | Securely hold and use credentials | Define and enforce Agent execution boundaries | Ensure transactions are compliant and authorized |
| Security Foundation | Intel SGX + AES-256-GCM + immudb | SGX + SEV-SNP + gVisor + Policy Engine | zkKYC + KYT + Google AP2 + x402 |
| Integration | Dashboard / CLI | Dashboard / CLI | Dashboard / MCP Server / REST API |
| Audit | Immutable logs + screenshot traceability | Compliance proof + Execution Receipt | Transaction logs + txHash on-chain |
| Status | Available | Coming Soon | Available |
Find the right product for your use case.
Developers & Startups
Let Agents securely log in to websites and call services requiring passwords or API keys.
Start with Vault — Credential security in minutes
Ready to get started?
Explore our products or jump straight into the docs.
Not sure where to begin? Start with Vault — it takes 5 minutes to secure your first credential.