AI Security for Agentic Systems. Open source. Self-hostable.

Start Shipping AI Agents
You Can Trust

Verify Agent and MCP identity in <1ms. Block impostors at the boundary.

Think Let's Encrypt, but for AI.

Get Started

Know Who's Calling

Ed25519 signatures prove agent identity

Block Tampering

SHA-256 body hash detects modifications

Stop Replays

60-second window rejects stale requests

Addresses 6 of the OWASP Top 10 for Agentic Applications 2026

Direct coverage for AG01 (Identity Spoofing), AG06 (Communication Tampering), AG07 (Replay Attacks), AG10 (Audit Gaps). Partial coverage for AG02 (Tool Misuse), AG03 (Excessive Agency).

View full OWASP mapping →

Common Failure Modes We Help Prevent

These are real incidents from teams running agents in production

Schema Drift

Third-party agent changed their schema

No validation gate. 4 hours of errors before engineering noticed.

→ CLI validates agent cards in CI before they hit production

Validate before deploy →
Replay Attack

Valid request captured, replayed 100+ times overnight

No timestamp validation. Compute budget drained.

→ Guard enforces 60-second replay windows. Same request twice? Blocked.

Block replay attacks →
Attribution Gap

Logs showed an API call. But which agent?

Impersonation? Delegation? Unknown. Incident review stalled.

→ Guard logs verified agent identity on every request

View security guarantees →

The Difference

Two protection points for your AI stack

Without CapiscIO
LangChain
Agent A
--❓--
CrewAI
Agent B
--❓--
MCP
MCP Server
  • Agent B can't verify Agent A's identity
  • MCP server can't limit which agents call which tools
  • No audit trail of who did what
CapiscIO
With CapiscIO
LangChain
Agent DID:1
Agent Guard
-🔐-
CrewAI
Agent DID:2
MCP Guard
-🔐-
MCP
MCP Server
  • Agent Guard: Verified DID on every A2A call
  • MCP Guard: Scoped tool access per agent
  • Full chain logged with verified identities

Drop-in Protection

Two lines to protect your A2A endpoints. One package for MCP tool servers.

🐍
Agent Guard
A2A Protection
pip install capiscio-sdk
🔧
MCP Guard
Tool Server Protection
pip install capiscio-mcp
🔷
Go Sidecar
Any HTTP service, K8s
docker pull capiscio/guard
⚙️
CLI + CI
GitHub Actions, GitLab CI
npm install -g capiscio

Agent Guard: A2A Protection

from fastapi import FastAPI
from capiscio_sdk import SimpleGuard

app = FastAPI()

# Add a protocol aware guard in two lines.
guard = SimpleGuard(app)

CLI: Validate in CI

Terminal
capiscio validate ./agent-card.json --test-live
✅ A2A AGENT VALIDATION PASSED
Score: 95/100 • 12 checks passed
Completed in 245ms

SSL Trust Levels Meet Short-Lived Tokens

Five verification tiers (Self-Signed → Extended Validation) like SSL certificates, but with 5-minute TTLs like access tokens. Stolen credentials expire before they're useful.

Learn about trust levels →

Start Free. Scale When Ready.

Open source tools run locally. Hosted registry when you need managed infrastructure.

Open Source

Free
Apache 2.0 Licensed
  • CLI, SDK, MCP Guard — unlimited
  • Self-hosted trust store
  • Offline verification mode
View on GitHub

Hosted Registry

$79/mo
Up to 10 service identities
  • Managed badge issuance
  • Key rotation & revocation
  • 14-day free trial
Start Free Trial
Need hands-on deployment? Ask about our Agent Trust Sprint
Beon de Nood, Founder of CapiscIO

Building with AI Agents? Let's Talk.

I'm looking for design partners: teams running agents in production who want to co-develop the identity and governance features that matter most. No sales pitch—just problem-solving together.

— Beon de Nood, Founder

Become a Design Partner

Protocol-Agnostic Enforcement

A2A is the first standard. Your stack will be multi-standard.

CapiscIO started by enforcing the A2A Protocol (Google/Linux Foundation) and applies the same guard pattern to any agent traffic.

Same verification semantics work for A2A, MCP, custom protocols, and whatever emerges next.

Latest Insights

Learn about A2A Protocol, agent validation, and trust infrastructure

Your Agents Are Already in Production.
Give Them an Identity They Can Prove.

Start with the CLI. Validate your agent cards. Add Guard when you're ready for runtime enforcement.

pip install capiscio · pip install capiscio-sdk · pip install capiscio-mcp