Founding design-partner beta

No receipt.
No execution.

GoldKey Guard puts operator-controlled policy in the real execution path of an AI agent. Install a config-driven local MCP, AgentCash, or Base-wallet enforcer; the exact proposed call runs only after it verifies a signed, short-lived ALLOW receipt.

Apply privately below. No payment is collected with your application.

illustrative receipt shape
decisionALLOW
policyoperator-signed / pinned
callsha256:8c9a…e41f
expiresshort-lived
key_idpublished Ed25519 key
Exact call bound to a signed decision
Execution-path enforcementThe local component controls forwarding.
Operator-owned policyThe guarded agent cannot rewrite authority.
Config-driven launchersGuard MCP, AgentCash, or Base without customer code.
Credentials stay localThe hosted authorizer never receives them.

The control point

Make every action earn permission.

A policy recommendation beside the agent is easy to ignore. GoldKey Guard is built for the last mile: the local process holding the real credential or signer refuses to forward until authorization is verified.

01 / ENFORCE

Sit in the real execution path

Route the connector or wallet signer through the customer-controlled enforcer. Packaged launchers cover stdio MCP, operator-pinned AgentCash operations, and constrained Base-wallet actions.

02 / AUTHORIZE

Keep policy outside the agent

The operator signs immutable, monotonically versioned policy. Hosted evaluation checks the exact proposal against authoritative state, not instructions the agent can edit.

03 / PROVE

Verify before forwarding

Every ALLOW, REVIEW, or BLOCK result is returned in a signed short-lived receipt. The local enforcer pins the policy and verifies the receipt against the exact call.

Four-stage path

Authority stays with the operator.

The hosted service evaluates. Your local enforcer controls the credential and performs the action. That separation is the product boundary.

STEP

Propose

The agent submits the exact tool call, HTTPS operation, or supported EVM transaction to its local enforcer.

STEP

Evaluate

GoldKey verifies installation identity and operator-signed policy. HTTPS enforcement pins a verified public DNS answer to the TLS request to resist DNS rebinding; EVM actions are decoded and simulated where required.

STEP

Verify

The local enforcer verifies the signed receipt, exact request hash, pinned policy, decision, and expiry before committing to forward.

STEP

Execute

Only an unexpired ALLOW reaches the configured connector or signer. Completion evidence records success, failure, or an unknown outcome.

Founding offer

Pay for a real control point, not another dashboard.

Start with a bounded control-design sprint or take one staging workflow through a complete guarded integration. Authorization usage is metered from the first real call.

Control-design sprint
$1,000
A bounded paid scoping engagement
  • One workflow threat model
  • One connector and credential boundary
  • Draft operator policy and acceptance plan
  • One technical review session
Apply for the sprint  →
Guarded integration pilot
$10,000
Two independently accepted $5,000 milestones
  • Threat model and immutable policy
  • One customer-owned staging integration
  • Fail-closed adversarial A/B evidence
  • Runbook, walkthrough, and correction round
Apply for the integration  →

MCP or HTTPS authorization

One exact proposed tool call or network operation.

$0.05 USDC / decision

Supported EVM authorization

Decode, policy evaluation, and simulation when required.

$0.10 USDC / decision

ALLOW, REVIEW, and BLOCK decisions are billable. Exact unexpired idempotent replays are not billed again. Usage is paid through x402 on Base.

Private pilot application

Start with one action that matters.

Tell us where the agent acts, what it can reach, and the exact operation you need enforced. Start the action description with Design sprint: or Guarded integration: to identify the engagement. We use this only to assess and respond to your inquiry.

Name the runtime or framework that proposes the calls.

Do not include API keys, private keys, credentials, or confidential payloads.

Your application is sent directly to GoldKey and is not posted publicly. We use the contact details to respond about this pilot and retain applications for up to 90 days. Please do not submit secrets or regulated data.

Exact boundaries

Security claims stop where the execution path stops.

This is a founding beta, not a blanket guarantee. We would rather make the boundary explicit than sell theater.

Required

The guarded agent must have no direct credential, signer, or network route that bypasses the local enforcer. If a bypass exists, GoldKey cannot enforce that path.

Hosted boundary

GoldKey receives the proposed action needed for evaluation. It does not receive upstream credentials or private keys, and it never forwards, signs, or broadcasts the action.

Beta scope

Policy registration remains a guided design-partner step. Packaged launchers cover generic stdio MCP, fixed AgentCash operations, and constrained Base-wallet actions; AgentCash requires a vetted endpoint plus OS egress controls, while custom HTTPS uses the lower-level SDK.

No guarantee

A decision is only as strong as the signed policy, connector isolation, upstream data, and integration. Guard does not promise to detect every malicious or unintended action.

Outcome safety

Ambiguous execution outcomes are recorded as unknown and must not be retried automatically. Signed receipts prove the authorization decision, not downstream success.

Founding partners

Put one real agent action behind Guard.

Bring one environment, one connector, and the policy you need enforced. We will scope the path and acceptance criteria before the paid pilot begins.

Apply for pilot  →