Like phone permissions plus cloud memory: every AI device asks before it remembers, accesses, or acts — and your memory and rules follow you across homes, teams, and vendors.
It can't spend, read the family calendar, or call out unless you allow it. Revoke any permission in one tap.
Import what it should know on day one. The memory lives with you, not the device maker.
Your memory and rules follow you across devices, homes, teams, and vendors. No lock-in.
This is the real Agent Terrier app — tap through it. Switch the theme or language up top and it re-skins instantly.
Four steps. You confirm safe defaults — you don't configure.
Open the app and scan the QR code on the new device — it introduces itself to your control center.
Honest about enforcement: online revocation is immediate; offline or cached capabilities expire on a short timer — never “instant everywhere.” Sensitive actions are blocked when the device is offline.
Set per device — a kids' toy is nothing like a work assistant.
You confirm; you don't configure — the AI recommends safe defaults, you approve with a tap. Tap any permission to see and change it in the app.
The technical layer behind the consumer experience. Bring your own cloud; we provide only the control plane.
Permissions and memory together are your AI's context — see, question, and revoke all of it from one control center.
Every grant, every memory read, every revoke lands in one tamper-evident timeline — across every device you've paired. Nothing your AI does is off the books.
Online revocation is immediate; offline or cached capabilities expire on a short timer — never “instant everywhere.”
A real-time activity feed in the app, plus a ~2-minute on-chain anchor for tamper-evidence.
Every device is sandboxed on its own — one device can never reach another's memory.
Your agents' permissions live on a public chain that only your passkey can change — not in our database. We run the plumbing; we can't grant access you didn't sign for.
Every permission is granted by your own passkey and written on-chain. We can't grant your agents access you didn't sign for — we don't hold a key that can.
Don't take the broker's word for it. Every data request is re-checked against your on-chain grant by an independent worker — no single server can over-reach.
The infrastructure is stateless and replaceable — it reads your policy from the chain, never a database we own. A new node is correct the moment it starts.
AgentKeys maps cleanly to enterprise identity standards — then adds the part a platform-local IAM system cannot promise: user-owned authority across partners, clouds, and devices.
Agent identities map to the same mental model as SPIFFE-style workload identity: every AI runtime has a verifiable actor.
Short-lived cloud credentials replace long-lived keys, with resource access scoped by attributes instead of shared secrets.
Policy is decided by a deterministic gate and enforced at the action boundary, not left to the model to remember.
Every grant, read, denial, and revoke becomes operational evidence, with tamper-evident anchoring for proof.
Permissions are granted by the owner, not silently expanded from a vendor admin console.
Sensitive changes require a device key plus biometric user presence, giving agents a real hardware boundary.
Memory and rules can follow the user across devices and brands instead of staying trapped in one product.
We do not replace the partner app, agent, or MCP. We make those surfaces safe to authorize and easy to revoke.
The keys that control your AI never sit in one place. We split trust across independent boundaries, so no single break can take it all.
Request early access — we'll reach out as we open up.