Agentic Transaction Control

Govern every disclosure.Prove every hop.

One agent transaction now touches models, tools, other agents and queues. Every handoff is a disclosure decision.

ZTroven governs each one, and signs a record of what was sent.

Zero custodyTrustedProven records

The problem

Agents authenticate each other. Then they overshare.

Identity says which agent may connect. It never says which facts this one should receive.

your agent LLM APIsMCP tool calls Other agentsWebhooks & HTTP QueuesExports

every arrow is a disclosure decision

How it works

Bind. Decide. Minimize. Dispatch. Prove.

01

Bind

Identity, purpose and lineage attach before anything leaves.

02

Decide

The recipient's permitted view is determined.

03

Minimize

Facts are removed or tokenized locally, in your process.

04

Dispatch

Only the evaluated bytes go out.

05

Prove

A signed, value-free record links to the hop before it.

Fail-closed. If policy cannot be enforced, the hop stops.

Selective disclosure

One transaction. A different answer for every participant.

Sensitivity is destination-relative. One rule for the whole payload gets it wrong in both directions.

YOUR PROCESS EGRESS your agent full context ZTroven decide · minimize · record your vault values stay here Fraud agent risk signals · no identifiers Payment service the payment subset Shipping agent the address subset Analytics queue no direct identifiers Unrecognized recipient nothing · fail-closed

the same record, a different view per recipient

The evidence

Evidence, not certification.

A record explains the transaction without exposing it — categories and actions, never values.

What it proves

  • Sender, recipient and declared purpose
  • Which transforms were applied
  • That the bytes sent are the bytes recorded
  • Hop linkage, independently verifiable

What it does not claim

  • That every sensitive fact was detected
  • That no uninstrumented path bypassed it
  • That the recipient handled the data safely
  • Any compliance or legal verdict

Why ZTroven

Your stack controls the connection. Not the disclosure.

Five layers already guard how agents connect and what they may touch. None of them reaches the moment the payload leaves.

NO LAYER REACHES HERE EGRESS → RECIPIENT Identity & IAM who may connect Tool gateways which tool, which parameters Payload DLP the model path only Network where it may connect Logs after the fact, mutable ZTroven decides what this recipient may receive · records what was sent

keep all five — this is the one they don't cover

Beyond DLP

Not "does this contain PII?" — but may this recipient receive this fact.

Beyond a proxy

Agents, tools, webhooks, queues. And nothing centralizes through us.

Beyond logging

Tied to the bytes dispatched. Logs are mutable and keep the originals.

Work with us

Bring one transaction.

Pick the workflow that worries you most — sensitive data, more than one recipient. We start there and scope from what we find.

Engagements run in your environment, on your stack. We don't need access to your code or your data.

We work with a small number of teams at a time.

Request an invite

What it does, and who it sends to. For example: order resolution — our agent calls a fraud service, a payment provider and a shipping API.