MolTrust - Agent Identity and Article 12 Audit Evidence
MolTrust · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 2 captures on record
What the publisher says
As described on AWS Marketplace.
## The problem
A shared API key identifies the account, not the acting agent. It leaves no per-action record tied to a verifiable identity, and logs can be edited or rotated. When an auditor asks what an agent was authorized to do and what it actually did, there is no answer that holds up.
Show the rest of the publisher’s description (13 more lines)
## What MolTrust does
**Agent identity** *a W3C DID per agent: registered, signed, resolvable.
**Authorization** *the Agent Authorization Envelope (AAE) records MANDATE, CONSTRAINTS and VALIDITY as a signed credential. Published as IETF Internet-Draft draft-kroehl-agentic-trust-aae-00.
**Evidence** *SHA-256 evidence hashes anchored on Base L2. Tamper-evident by cryptographic proof, not by policy.
**Export** *signed audit bundle (PAdES-B-LT) covering any period, verifiable independently.
## Verification is free, always
Anyone can verify an agent's identity, credentials and behavioural score without an account, an API key, or a payment. Only agent operators pay. This is deliberate: a trust layer that charges the verifier does not get adopted.
## No lock-in, no custody
Every credential is a standards-compliant W3C Verifiable Credential. Auditors validate signatures with any DID-conformant tool, no MolTrust software or account in the verification path. MolTrust does not hold your evidence long-term: the on-chain anchor holds the proof, you hold the exported file. Operational retention is 12 months.
## Scope
MolTrust is a deterministic cryptographic protocol layer, comparable in role to TLS or PKI. It supports EU AI Act Article 12 logging requirements with cryptographic provenance. Full logging responsibility under Article 12(1), conformity assessment under Article 43, and compliance responsibility under Article 16 remain with the AI-system provider. MolTrust does not issue compliance certificates and does not provide legal advice.
## Standards
W3C DID Core and Verifiable Credentials v2, IETF Internet-Draft (AAE), DIF Universal Resolver driver , aligned with the Singapore IMDA Model AI Governance Framework for Agentic AI (2026), Circle Alliance member, technical paper: arXiv 2605.06738
Highlights
Highlighted by the publisher on AWS Marketplace.
Verifiable agent identity, a W3C DID per agent with a signed authorization envelope recording MANDATE, CONSTRAINTS and VALIDITY. Published as an IETF Internet-Draft, not a proprietary primitive. Any DID-conformant tool can resolve and verify it.
Audit evidence that outlives the vendor, SHA-256 hashes anchored on Base L2, exported as a signed PDF (PAdES-B-LT). Your auditor verifies it independently: no MolTrust account, software, or API call in the verification path. Supports Article 12 logging.
Verification is free for everyone, only agent operators pay. Any party can verify an agent's identity, credentials and score without an account, a key, or a payment. Standards-based on W3C DID, no vendor lock-in.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Plans and pricing as listed
1 listed- Units
Refund terms
As stated by the publisher on AWS Marketplace.
This product is offered free of charge through AWS Marketplace. No fees are collected, therefore no refunds apply. Questions regarding this policy can be directed to lars@moltrust.ch.
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

