ARKION
§ PlatformAI Agent Governance

Govern every agent.
From deploy to revoke.

Every AI agent that touches your production infrastructure deserves a cryptographic identity — not a shared secret, not a static API key in plaintext configuration.

01 · Certificate Identity

One agent.
One certificate.

Each certificate is uniquely scoped to a specific agent instance, tied to its deployment manifest, and bound to cryptographic attestations from your infrastructure layer.

X.509 CERTIFICATE · ACTIVE
SHA-256 · ECDSA P-384
SUBJECTpayment-agent-prod-01
ISSUERArkion Root CA
SERIAL7A:3F:B2:91:…:E4
NOT BEFORE2026-04-10T00:00:00Z
NOT AFTER2026-07-09T23:59:59Z
OWNERplatform-team@acme.com
ROTATIONAuto · 90-day TTL
DEPLOYMENT BINDINGS
k8s/prod/paymentsmanifest:v2.4.1mTLS:enforcedscope:payments-api
CRYPTOGRAPHIC ATTESTATIONSigned by infrastructure layer · TPM-backed · immutable audit chain
RISK: LOW·LIFECYCLE: GOVERNED
ARKION v1.0
02 · Lifecycle

Five states. Zero ambiguity.

Every agent moves through a governed path. No exceptions.

ProvisionedRisk: Low

Certificate generated. Manifest validated. Identity quarantined until first execution.

ActiveRisk: Monitored

Certificate valid. mTLS enforced. Behavior scored in real time.

ExpiringRisk: Elevated

Within rotation window. Replacement issued. Graceful overlap for zero downtime.

RotatedRisk: Clearing

New certificate active. Old credential archived. Full audit trail retained.

ArchivedRisk: None

No longer accepted for connections. Queryable in audit logs indefinitely.

03 · Capabilities

Beyond the certificate.

01

Orphaned Agent Detection

Passive scanning maps deployed agents against declared infrastructure. No owner, no purpose, no escalation path — flagged immediately.

02

Policy-Enforced mTLS

Communication restricted by certificate identity, not network topology. Unauthorized peer connections denied, logged, and escalated.

03

Real-Time Risk Scoring

Every state transition scored across four signals: certificate validity, ownership, last activity, behavioral anomaly. Immutable in the audit log.

See your agents. Govern them.

A read-only discovery scan surfaces every non-human identity in your estate. No agents installed. No credentials required.