Prove trust on one agent in six weeks
From an agent in any framework to a certified agent in production. We run the lifecycle with you the first time — Discover finds what you are running, Diamond scores the one that matters, Dome defends it — and you finish with a team that can run the next one without us.
Prove trust on one agent.
- An AI governance workshop with your risk owner
- Discover finds your shadow agents
- Diamond assesses vulnerability
- Dome defends the pilot agent
The hard part is not the software, it is the first time through
You can install the SDK this afternoon. What takes months is deciding which agent to prove first, turning a policy that lives in a PDF into one that runs in CI, and getting evidence into a shape the person who signs will actually accept. Every organization does that badly once. We would rather it was with us.
Twenty candidate agents and no shared basis for saying which one to prove trust on first, so the argument outlasts the quarter.
The rule exists in a document and in somebody’s head. Neither one runs in CI, and neither one blocks a bad release.
Engineering says it passed. Risk asks passed what. The evidence was never built in a form the signer accepts.
Register and baseline, harden and guard, certify and deploy
Three two-week phases. Each one ends with something you can show somebody: an inventory, a score that moved, an agent in production with its evidence attached. The first phase is a proof of concept — you see your real agents and their real scores before you commit to the rest.
- Discover the shadow agents already running
- Give each one a SPIFFE / SPIRE identity
- Score it on the standard taxonomy, with a harness built from your policy
- Rank the population by what each agent can reach and how exposed it is
- Specify your organization’s policies
- Enforce those policies inside every agent
- Re-test, and see the trust-score uplift
- Deploy the certified agent
- Monitor every policy-relevant event
- Detect policy violations as they happen
- Evolve the agent’s config, code and controls
You finish with a certified agent in production and a team that has run the loop once, which is the only reliable way to run it again.
Week one runs the commands you would run alone
This is a guided pass through the product, not a bespoke build. The engagement uses the same CLI that ships on the free tier, so nothing we do in six weeks becomes something only we can maintain.
Unstated obligations are how a six-week engagement becomes a fourteen-week one, so here is the list. An owner who can make decisions about the pilot agent. One agent, with a repository or an endpoint. Read access to one cloud account or one code org — the same access the week-one commands above need, and nothing writable. A risk owner who will attend the workshop rather than be represented at it. And an agreed definition of pass, which is the first thing we work out because the page’s own list of why pilots stall starts with not having one.
Start with a proof of value, scale to platform
Flat price for all your agents. No per-seat traps, no token-based blowouts, no per-agent novelties. These three are engagements — how you get there. The product itself has three tiers on a different axis, whose infrastructure it runs in, and they are priced separately.What the product itself costs →
Prove trust on one agent.
- Six-week guided engagement, fixed scope
- AI governance workshop
- Discover finds shadow agents
- Diamond assesses vulnerability
- Dome defends one pilot agent
Operationalize across a line of business.
- Every agent in that line of business, not a sample
- Trust gates in your CI/CD
- Custom harnesses and policies
- Priority support
Trust infrastructure for the whole population.
- Unmetered — your hardware is the only limit
- VPC, on-premise or air-gapped
- Darwin for continuous evolution
- SSO, SLAs and a named technical account manager
Meaning what exactly?
A certificate is an assertion we make to a third party: scoped, dated and expiring, carried on the agent card, produced from the trust score at one point in time. It says this agent, on this harness, against this policy, scored this on this date. It does not say the agent is safe, and it does not say it will still score that next quarter — our own argument is that it will not, which is why the certificate carries a date rather than a verdict.
It is an artifact, not a status. A lapsed certificate does not make an agent worse; it makes the claim stale. Re-certification is what the platform is for, and it is the honest reason the engagement ends in a subscription rather than a document.
Start with a proof of concept
Six weeks, one agent, from an unmeasured baseline to certified in production. Take the pilot if you have no agreed first target or nobody who will sign; start free if you only want a score on an agent you already know about. Write to contact@vijil.ai or book a time.