Insurance
Agents negotiate specialty coverage with reinsurers
Each side proves identity + authority cryptographically
Billions in premium with complete audit trail
Let AI agents transact across company boundaries—without merging directories
Trust crosses the boundary as cryptographic proof—no VPN, no directory merge, complete audit trail.
Enforceable runtime agent controls for financial institutions
With no clean way to prove which agent acted for which org
Independent regulatory frameworks converge on identical agent identity primitives
Auditor-ready proof of cross-org agent activity
No VPN, no directory merge, no custom IAM per partner
DIDComm + TRQP + W3C VCs, open standards
"Which agent acted? Were they authorised?" — We don't know.
Cryptographic proof of who acted, and under whose authority.
When your AI agent needs to negotiate with another company’s system, that system has no reliable way to verify:
This isn’t a future problem. Insurance companies underwrote $1.6 billion in specialty premium via agentic AI with no clean way to prove which agent acted for which organization. When agents cross company boundaries today, trust relies on out-of-band verification, VPN tunnels, or simply hoping the other side is who they claim to be.
The status quo:
Regulators aren’t waiting:
MAS SAFR (Singapore Monetary Authority, Jul 2026): Mandates runtime controls for inter-institutional agent workflows. Co-authored with HSBC, JPMorgan, Mastercard, Visa, and OCBC—this isn’t a proposal, it’s an enforceable requirement.
eIDAS 2.0 (EU, 2027): Requires verifiable digital identity for automated systems across member states. ~450 million wallets will need agent identity infrastructure that works cross-border.
Four independent jurisdictions (Singapore, EU, US via Utah SEDI, China via AI-Agent Identity Framework) have converged on identical architectural primitives: self-owned agent identity + runtime authorization queries. When regulators in vastly different systems independently arrive at the same technical requirements, it signals consensus—not coincidence.
The shift: from trusting a shared infrastructure (VPN, directory federation) to trusting cryptographic proof that travels with every request.
Before Affinidi:
[Your Agent] → [Shared VPN or federated directory] → [Partner's System]
↓
Hope they're who they say they are
With Affinidi:
[Your Agent] → [Agent Gateway: assigns DID + signed mandate]
↓
[Trust Spanning Protocol: metadata-private routing]
↓
[Partner's System: verifies DID signature]
↓
[Trust Registry (TRQP): "Is this agent authorized RIGHT NOW?"]
↓
[Transaction proceeds with cryptographic proof logged]
Instead of trusting a shared VPN or federated directory, each agent carries cryptographic proof of its identity and authorization. The receiving system verifies this proof independently, in real time.
What makes this work:
Agent Gateway issues each agent a DID (Decentralized Identifier) based on did:webvh—tamper-evident, time-travelable identifiers with safe key rotation. No central registry required.
Every request carries a signed mandate (a W3C Verifiable Credential) stating:
Trust Registry responds to TRQP queries (Trust Registry Query Protocol):
Trust Spanning Protocol (TSP) routes agent messages across boundaries with metadata privacy—the message reaches the partner without revealing routing details to intermediaries. Affinidi ships the first production TSP integration in the wild.
This isn’t theory:
Affinidi is the only vendor shipping the full stack: agent identity + cryptographic mandates + runtime policy enforcement + cross-org trust registries + metadata-private routing—all in production.
Not a VPN replacement. VPNs secure the network layer; this secures the agent layer. You can use both, but VPNs alone can’t answer “which agent acted, and were they authorized?”
Not directory federation. You don’t merge directories or expose internal IAM schemas. Each org keeps its own trust registry; TRQP queries work across boundaries without data leakage.
Not a wallet alone. Wallet-only solutions give agents identity but don’t handle runtime policy enforcement, revocation checks, or cross-org authorization queries. You need the full stack.
Not an agent runtime. AWS AgentCore, Cloudflare Workers for AI, and similar platforms execute agents—they’re excellent at that. But they don’t solve inter-organizational trust. Affinidi sits alongside runtimes, not replacing them.
Whether you’re a developer prototyping agent workflows, a security team evaluating compliance, or an enterprise planning cross-org automation—there’s a path in.
New to the underlying standards? Start with Decentralized Identifiers, then explore Trust Registries (TRQP) and DIDComm Messaging.
These Affinidi products power this solution. Products as enablers, not the hero.
These are examples of the same solution applied across different industries—not new solutions.
Agents negotiate specialty coverage with reinsurers
Each side proves identity + authority cryptographically
Billions in premium with complete audit trail
Two banks' agents settle trades
TRQP confirms both agents authorized by institutions
Cross-institution workflows without merged directories
Hospital agent requests patient records from another provider
Proves HIPAA-compliant authorization before data release
PHI exchange with cryptographic proof of authorization
Manufacturer transfers bill of lading to logistics agent
Verifiable custody chain with cryptographic handoff signatures
Source-to-shelf transparency with zero trust gaps
| Capability | Affinidi | Legacy IAM Systems / Agent Runtime Only / Wallet-Only Providers |
|---|---|---|
| Cross-org trust | Native DIDComm + TRQP | VPN or directory federation required |
| Self-hostable | Full stack, your infrastructure | SaaS-only or partial control |
| Post-quantum ready | ML-DSA, SLH-DSA integrated | RSA/ECDSA only |
| Regulatory alignment | MAS SAFR, eIDAS 2.0, SEDI compliant | Compliance add-on or not addressed |
| Live in production | 18,500+ credentials across networks | Pilot or limited deployment |
Pick the entry point that matches where you are in your journey.
Start building with our Portal and documentation
Start buildingSee a live demo and explore use cases
Schedule demoCustom deployment and integration support
Talk to an expert