Commercial control plane

ZTI Core
The control plane for governed AI.

ZTAP defines the protocol. ZTI Core makes it real.

The operational system that turns protocol into enforcement. Policy engine, agent registry, execution receipts, and audit logs in one coherent platform.

Policy engine · Agent registry · Execution receipts · Audit logs

Get notified at launch Read the protocol first →
ZTI Core ● live

Agents

47

6 pending

Policies

238

12 envs

Recent

deploy_service ci-bot ALLOWED
read_secrets agent-42 DENIED
run_migration db-agent ALLOWED
modify_policy admin REVIEW
receipt signed

hash: a3f9...c7b2

registered agents

47 active

Reframe

Protocol vs. platform. Two different things.

ZTAP

The protocol.

ZTAP defines the format, the flow, and the standard. Envelope structure. Hash requirements. Receipt schema. Conformance rules.

What you have: a specification.

ZTI Core

The platform.

ZTI Core implements and enforces ZTAP. Policy evaluation. Agent identity. Receipt storage. Audit queries. The operational reality of governed AI.

What you get: enforcement.

"ZTAP without ZTI Core is like HTTP without a server. The standard exists. Nothing actually runs."

Without ZTI Core

Here is what breaks.

Implementing ZTAP without an operational platform means rebuilding these capabilities from scratch — for every team, every system, every deployment.

No policy engine

ZTAP envelopes arrive. Nothing evaluates them. Authorization is manual, inconsistent, or non-existent. Policy exists only as documentation.

No agent registry

AI agents operate without identity. You cannot scope their capabilities, bound their actions, or distinguish one agent from another in the audit log.

No receipt storage

ZTAP receipts are generated but written to… where? Log files? Databases owned by different teams? There is no single, queryable evidence store.

No identity layer

The "actor" field in the envelope is unverified. Any system can claim any identity. Authorization decisions are made against unverified claims.

No audit interface

Compliance asks "show me all actions taken by ai-agent-7 in Q3." There is no interface. Someone writes a script. The script is different every time.

Manual policy management

Policy updates are text file changes reviewed by engineers. No version control, no rollback, no testing, no enforcement at evaluation time.

ZTI Core capabilities

The system that makes governance operational.

Four core capabilities. One coherent platform. ZTAP-native from the ground up.

01 / Agent Registry

Define and bound every AI agent in your organization.

Register agents with defined identities, capability scopes, and operational boundaries. Each agent has a verifiable identity that the policy engine can reference during authorization. No unregistered agent can produce a valid ZTAP receipt.

Live

02 / Policy Engine

Write and enforce governance rules for every action type.

Define policies in a structured, auditable format. Policies reference action types, actor identities, target environments, and contextual constraints. The engine evaluates every ZTAP envelope in real time — before execution. Decisions are signed and stored.

Live

03 / Execution Receipts

Signed, verifiable evidence for every governed action.

Every action that passes through ZTI Core produces a ZTAP-conformant execution receipt. Signed by the control plane. Immutable. Queryable. References the original envelope hash, authorization decision, actor identity, and outcome. This is what compliance requires.

Live

04 / Audit Logs

Immutable, queryable evidence trail for compliance and forensics.

All receipts persist in an append-only, tamper-evident audit store. Query by agent, action type, policy, time range, or outcome. Export for compliance reports. Integrate with your existing SIEM or audit tooling. The evidence is always there.

Live

Platform preview

What governance looks like in production.

AI Agent

ZTAP

ZTI Core

Execution

Receipt

ZTI Core — Control Plane ● Connected

Actions (30d)

12,769

↑ 14% vs prev.

Policies Active

238

12 environments

Policy Denials

12

0.09% deny rate

Registered Agents

47

6 pending review

Recent Actions

deploy_service ci-bot ALLOWED
read_secrets agent-42 DENIED
run_migration db-agent ALLOWED
send_notification notify-bot ALLOWED
modify_policy admin-agent REVIEW

Action Volume (7d)

Mon Today

Preparing for launch

ZTI Core is preparing for launch.

If your organization is deploying AI agents in regulated environments and needs a governance answer, you can request to be notified when ZTI Core becomes available.

No sales process. No commitment. Just a notification when the system is ready.

We're validating this direction with a small group of practitioners. If this resonates, tell us how you'd use it.

Notify me at launch

No mailing list. Direct responses only.

Read the protocol →