Sit in the real execution path
Route the connector or wallet signer through the customer-controlled enforcer. Packaged launchers cover stdio MCP, operator-pinned AgentCash operations, and constrained Base-wallet actions.
Founding design-partner beta
GoldKey Guard puts operator-controlled policy in the real execution path of an AI agent. Install a config-driven local MCP, AgentCash, or Base-wallet enforcer; the exact proposed call runs only after it verifies a signed, short-lived ALLOW receipt.
Apply privately below. No payment is collected with your application.
The control point
A policy recommendation beside the agent is easy to ignore. GoldKey Guard is built for the last mile: the local process holding the real credential or signer refuses to forward until authorization is verified.
Route the connector or wallet signer through the customer-controlled enforcer. Packaged launchers cover stdio MCP, operator-pinned AgentCash operations, and constrained Base-wallet actions.
The operator signs immutable, monotonically versioned policy. Hosted evaluation checks the exact proposal against authoritative state, not instructions the agent can edit.
Every ALLOW, REVIEW, or BLOCK result is returned in a signed short-lived receipt. The local enforcer pins the policy and verifies the receipt against the exact call.
Four-stage path
The hosted service evaluates. Your local enforcer controls the credential and performs the action. That separation is the product boundary.
The agent submits the exact tool call, HTTPS operation, or supported EVM transaction to its local enforcer.
GoldKey verifies installation identity and operator-signed policy. HTTPS enforcement pins a verified public DNS answer to the TLS request to resist DNS rebinding; EVM actions are decoded and simulated where required.
The local enforcer verifies the signed receipt, exact request hash, pinned policy, decision, and expiry before committing to forward.
Only an unexpired ALLOW reaches the configured connector or signer. Completion evidence records success, failure, or an unknown outcome.
Founding offer
Start with a bounded control-design sprint or take one staging workflow through a complete guarded integration. Authorization usage is metered from the first real call.
One exact proposed tool call or network operation.
Decode, policy evaluation, and simulation when required.
ALLOW, REVIEW, and BLOCK decisions are billable. Exact unexpired idempotent replays are not billed again. Usage is paid through x402 on Base.
Private pilot application
Tell us where the agent acts, what it can reach, and the exact operation you need enforced. Start the action description with Design sprint: or Guarded integration: to identify the engagement. We use this only to assess and respond to your inquiry.
Exact boundaries
This is a founding beta, not a blanket guarantee. We would rather make the boundary explicit than sell theater.
The guarded agent must have no direct credential, signer, or network route that bypasses the local enforcer. If a bypass exists, GoldKey cannot enforce that path.
GoldKey receives the proposed action needed for evaluation. It does not receive upstream credentials or private keys, and it never forwards, signs, or broadcasts the action.
Policy registration remains a guided design-partner step. Packaged launchers cover generic stdio MCP, fixed AgentCash operations, and constrained Base-wallet actions; AgentCash requires a vetted endpoint plus OS egress controls, while custom HTTPS uses the lower-level SDK.
A decision is only as strong as the signed policy, connector isolation, upstream data, and integration. Guard does not promise to detect every malicious or unintended action.
Ambiguous execution outcomes are recorded as unknown and must not be retried automatically. Signed receipts prove the authorization decision, not downstream success.
Founding partners
Bring one environment, one connector, and the policy you need enforced. We will scope the path and acceptance criteria before the paid pilot begins.