One key, every product as a block. Each one shows its state and one next move.
with your key
Agent address
The Fabric address a partner connects to. The private key stays with you.
with your key
AI agents
Who may act, and what each agent may read.
with your key
Agent connections
Paste another agent’s address and connect. Deny by default, with expiry.
with your key
Invite a partner org
A one-time link. They see who you are and what you will share before signing up.
with your key
Policy board
Who may send to you (open · verified · closed) and what they see about you.
with your key
Capsules
Sealed information with its own access, members and AI grants.
with your key
Scan & seal a folder
Find what is sensitive and seal it, in your browser.
with your key
Safe file for any AI
Scan a doc, set what an agent may read, get the allowed slice with a proof.
with your key
Proofs
Every decision, signed. Verify any of them without us.
with your key
Terminal & API
Connect your terminal or agent (MCP) — approve in the browser, no key to copy.
with your key
The network
Organisations already connected, and what their agents do. Find the next partner.
One journey · two ways in
Five moves — Classify · Protect · Route · Retrieve · Prove. Start from a table (your database) or a folder (documents): same journey, same proof.
🗂️
ClassifyConnect your data
Register a table (or seal a document) — NoData gets the shape, never the values.
POST /api/v1/governance/tables
🔑
ProtectGrant an agent
Scoped, deny-by-default — only the columns you name. Mints an ndca- token.
POST /api/v1/governance/grant
🧭
RouteDecide before it reads
“May this agent reach X?” — a decision, a cost and a proof, with no data moving.
POST /api/access/decide
📥
RetrieveThe agent reads
Only granted columns decrypt; denied ones come back absent, not blanked.
POST /api/agents/<handle>/read
🧾
ProveShow it happened
A signed receipt on every read and every deny — verifiable without the data.
GET /decisions · /verify/ref/<ref>
We never hold your key; reads and grants are content-blind — every decision releases only the keys your grant allows, and a denied column’s key is never derived.
The same journey, starting from a folder or document (Capsule)
Each document is sealed to a key we cannot open — denied sections never decrypt.
Create a Capsule · seal a documentPOST /api/v1/capsules · …/documents
Add a memberPOST …/capsules/{id}/members
Grant an AI · the agent reads…/ai-grants · …/ai-read
Pull a proof · revoke (crypto-shred)…/audit · …/revoke