keysingate
Verifiable custody for people and AI agents

A history no one can rewrite. Not even us.

Keysingate issues sealed containers. Keys go in and never come out. Every action becomes a signed page in a journal, anchored to a public network. Anyone can check it — with open code, without asking us.

How it works

01

Issued and sealed

The issuer prints a container under a public release. It is sealed from the first byte and signed on the outside with a post-quantum key. The issuer keeps no master key.

02

Born at first use

The client's key is created in two halves — one inside the container, one on the client's device. The whole key never exists in any one place.

03

Every action, a page

Work is written page by page with an internal clock. Each page is signed inside and anchored to a public network, so pages cannot be removed, reordered or backdated.

04

Verified by anyone

Export one page or the whole journal. A third party checks signatures and anchors with the open verifier — no account, no trust in Keysingate required.

Why Keysingate

Nothing secret leaves

The container has no door for secrets. Only work results and proofs can be copied out.

No master key

Neither the issuer nor we can open, edit or replay a container.

Survives a change of hands

When a container passes to a new holder, the previous holder's secrets stay sealed.

Ready for what comes next

Ed25519 inside, ML-DSA-65 on the outside: classical speed with a post-quantum seal.

Built for AI agents

An AI agent's work is only as valuable as the proof of who did it and when. A Keysingate journal gives an agent, its owner, or both a timeline that holds up — page by page.

Register an AI agent
  • Provenance of every artifact the agent produces
  • Joint signatures: agent key plus owner key
  • Machine-readable site: llms.txt, JSON Schemas, agent card

An open standard

The core is specified in two Internet-Drafts and implemented as open source under the Apache 2.0 licence. Verification never depends on us.

Become a distribution agent

Agents bring containers to clients and hold the client's half of the key until hand-over. Apply to join the network.

Apply as an agent

Questions

What is a Keysingate container?

A sealed digital container that holds keys and a signed work journal. Secrets can go in but cannot come out; only work results and proofs can be exported.

Can Keysingate or the issuer read or change my container?

No. There is no master key. The container's key is created in two halves at first use, and the whole key never exists in one place.

How does anyone verify a journal?

Each page is signed and anchored to a public network. The open-source verifier checks the signatures, the page order and the anchors on its own.

Which network is used for anchoring?

The current implementation anchors to Solana. The format describes anchors generally, so other networks can be added.

Is it quantum-safe?

The container file is signed on the outside with ML-DSA-65, a post-quantum signature. Signatures inside use Ed25519.