498 days until EU AI Act high-risk obligations apply · Dec 02 2027vettd-cli is live today →
The trust layer for the agentic supply chain

Right now, your AI estate is a conspiracy board.

Agents wired to models wired to MCP tools, pinned across clouds nobody fully maps. Drag the cards; it won't untangle.

On file · registry producers
AnthropicmodelsOpenAImodelsGoogle GeminimodelsMistralmodelsMeta LlamamodelsxAI GrokmodelsMCP serverstoolsLangChainframeworksCursoragentsGitHub CopilotagentsAWShostingAzurehostingGoogle CloudhostingCloudflareedgeVerceldeployDockercontainers
Four questions. One record answers them.
question 01 / 04inventory
What's running?

Every agent, model, MCP server, prompt, and credential in your estate: named, versioned, and pinned in one signed AI-BOM. No asset off the board.

answered in section 02 →
question 02 / 04security
Is it safe?

A security grade per asset: credential scope, egress, injection surface, supply-chain posture, folded in from the tooling you already trust.

answered in section 03 →
question 03 / 04performance · cost
Is it worth it?

Performance and cost with a denominator: benchmarked against your workloads, metered per task, graded $ to $$$$ against the value delivered.

answered in section 03 →
question 04 / 04control
Can you prove it?

Signed evidence mapped to NIST AI RMF, ISO 42001, the EU AI Act, and OWASP — decisions your stack enforces natively, not a PDF.

answered in section 04 →
Every asset you run. Fully local.
stack layer01 / 05
prompts & data

The prompts, configs, and data every asset runs on, versioned and pinned.

stack layer02 / 05
workflows & skills

What's deployed, where it runs, and which skills it carries.

stack layer03 / 05
tools

Which tools each asset can call, what it can reach, and which calls actually leave the building.

stack layer04 / 05
mcp servers

Servers, scopes, and prompt configs: not just process lists.

stack layer05 / 05
model

Which foundation model each asset calls, and under what account.

vettd-cli walks your estate and writes one signed AI-BOM. Nothing leaves the host until you decide.

zero egressMIT · free foreverone signed artifact
GitHub
~/estate: vettd
$
▶ scan queued, runs as you arrive
zero egress: nothing leaves this page either
Three grades. One open schema.
grade axis · 01live today
SecuritySEC A

Credential scope, egress, injection surface, and supply-chain posture: findings from the security tooling you already trust fold into one grade per asset.

reads from: vettd scan · SAST & supply-chain scanners · red-team probes
grade axis · 02next up
PerformancePERF B

Does the agent actually do the job? Benchmarked against your workloads, not a public leaderboard, so the grade means something in your estate.

reads from: eval harnesses · benchmark suites · task-level evals you define
grade axis · 03live today
CostCOST $$

Token burn with a denominator: metered per asset and per task, graded $ to $$$$ against the value delivered.

reads from: usage meters · provider invoices · runtime telemetry

One inventory answers all four questions: what's running · is it safe · is it worth it · can you prove it.

how grading works →
Four words every enforcer understands.

A grade that can't reach the token, the socket, or the pull request is a PDF. A Vettd credential is enforced natively by your stack.

remediations: REDACT · REDUCE_SCOPE · REVOKE_CREDENTIAL · QUARANTINE · TERMINATE_PROCESS · ROLL_BACK_VERSION
support-pilot → stripe.refund($82)
Within approved purpose · under threshold · credential v3.2 current
ALLOW

Purpose matches and the evidence is current: the call proceeds untouched, logged end to end. ALLOW is the default state of a governed estate.

Agent & tool-call
runlayer · kong · hooks
gateway passes the call
Identity & entitlement
idp · oauth · pam
scoped token honored
Workload & OS
tetragon · kubearmor
no syscall anomalies
Attestation
receipts → credential
receipt signed → credential
↓ decision travels downevidence returns to the credential ↑
NIST AI RMFISO 42001EU AI ActOWASP
for the enterprise →
Get your estate on the record.
Vettd Cloud

Scans become a living inventory your security team can defend: private by default.

$ brew install vettd-cliGitHub, free forever
Talk to the team30 minutes

The scanner is free forever. Book a briefing to talk through cloud rollout, timelines, and what fits your estate.

Book a 30-min briefing →