Back to the registry
Agent passport

MolTrust - Agent Identity and Article 12 Audit Evidence

MolTrust · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 2 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

## The problem

A shared API key identifies the account, not the acting agent. It leaves no per-action record tied to a verifiable identity, and logs can be edited or rotated. When an auditor asks what an agent was authorized to do and what it actually did, there is no answer that holds up.

Show the rest of the publisher’s description (13 more lines)

## What MolTrust does

**Agent identity** *a W3C DID per agent: registered, signed, resolvable.

**Authorization** *the Agent Authorization Envelope (AAE) records MANDATE, CONSTRAINTS and VALIDITY as a signed credential. Published as IETF Internet-Draft draft-kroehl-agentic-trust-aae-00.

**Evidence** *SHA-256 evidence hashes anchored on Base L2. Tamper-evident by cryptographic proof, not by policy.

**Export** *signed audit bundle (PAdES-B-LT) covering any period, verifiable independently.

## Verification is free, always

Anyone can verify an agent's identity, credentials and behavioural score without an account, an API key, or a payment. Only agent operators pay. This is deliberate: a trust layer that charges the verifier does not get adopted.

## No lock-in, no custody

Every credential is a standards-compliant W3C Verifiable Credential. Auditors validate signatures with any DID-conformant tool, no MolTrust software or account in the verification path. MolTrust does not hold your evidence long-term: the on-chain anchor holds the proof, you hold the exported file. Operational retention is 12 months.

## Scope

MolTrust is a deterministic cryptographic protocol layer, comparable in role to TLS or PKI. It supports EU AI Act Article 12 logging requirements with cryptographic provenance. Full logging responsibility under Article 12(1), conformity assessment under Article 43, and compliance responsibility under Article 16 remain with the AI-system provider. MolTrust does not issue compliance certificates and does not provide legal advice.

## Standards

W3C DID Core and Verifiable Credentials v2, IETF Internet-Draft (AAE), DIF Universal Resolver driver , aligned with the Singapore IMDA Model AI Governance Framework for Agentic AI (2026), Circle Alliance member, technical paper: arXiv 2605.06738

Highlights

Highlighted by the publisher on AWS Marketplace.

Verifiable agent identity, a W3C DID per agent with a signed authorization envelope recording MANDATE, CONSTRAINTS and VALIDITY. Published as an IETF Internet-Draft, not a proprietary primitive. Any DID-conformant tool can resolve and verify it.

Audit evidence that outlives the vendor, SHA-256 hashes anchored on Base L2, exported as a signed PDF (PAdES-B-LT). Your auditor verifies it independently: no MolTrust account, software, or API call in the verification path. Supports Article 12 logging.

Verification is free for everyone, only agent operators pay. Any party can verify an agent's identity, credentials and score without an account, a key, or a payment. Standards-based on W3C DID, no vendor lock-in.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

1 listed
Free (default)
  • Units
$0.00

Refund terms

As stated by the publisher on AWS Marketplace.

This product is offered free of charge through AWS Marketplace. No fees are collected, therefore no refunds apply. Questions regarding this policy can be directed to lars@moltrust.ch.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Publisher resources

3 links
Technical paper (arXiv)arxiv.orgSource
EU AI Act fact sheet (PDF)moltrust.chSource
Sample audit evidence bundlemoltrust.chSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
SaaS
Technical paper (arXiv): https://arxiv.org/abs/2605.06738 EU AI Act fact sheet (PDF): https://moltrust.ch/assets/moltrust-factsheet-eu-ai-act.pdf Sample audit evidence bundle: https://moltrust.ch/sample-audit-evidence-bundle.html Support is provided by MolTrust (CryptoKRI GmbH, Zurich, Switzerland). **Contact** Web: https://moltrust.ch/contact.html Email: hello@moltrust.ch **Service status** https://status.moltrust.ch **Documentation** API reference: https://api.moltrust.ch/docs Developer quickstart: https://moltrust.ch/developers.html Compliance and Article 12 details: https://moltrust.ch/compliance.html **What to expect** Free tier is self-service and carries no SLA. Response to support requests on business days, Central European Time. Paid plans carry a 99.5% (Base) or 99.9% (Scale) service level agreement. See https://moltrust.ch/pricing.html
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.