Skip to content
Innovation

Built to be checked, not trusted.

Attesso's authorization and evidence layer ends in a provable record: append-only, checkpointed, time-anchored, and verifiable without asking us. Here is what is shipped, and what is still in the lab.

Append-only logRFC 6962 checkpointsRFC 3161 time anchorsVerify offline
Shipped

What is shipped, described plainly.

Everything in this section is in the product and documented. Nothing below depends on the research that follows.

01

User-signed authority

The end user approves an immutable, time-bounded mandate with a passkey on a hosted page. Attesso enforces those exact bounds, nothing wider.

02

Deterministic decisions

Each proposed action is evaluated against the exact mandate: ALLOW, DENY, or INDETERMINATE, with one reservation per ALLOW and one execution per reservation.

03

Verifiable evidence

Every step from the approval to the reported outcome is signed into one bundle that anyone can verify against published keys, without trusting Attesso.

Verify a sample bundle
04

The provable record

Every mandate event is appended to one tamper-evident log. Signed checkpoints chain and an independent RFC 3161 authority fixes their existence in time; hold a snapshot, and later prove nothing before it was rewritten or removed.

Check the record
In the lab

What is still in the lab.

Research here means exactly that: nothing in this section is shipped, certified, or claimed.

01

AP2 v0.2 adapter

In development

A human-not-present adapter so mandates issued in other systems could enter the same runtime, with Attesso as the verifier, not the merchant or payment-method provider. Conformance and production compatibility are not yet claimed.

Read the AP2 position
02

Agentic commerce interoperability

We track the emerging agentic payment and identity protocols as they settle, and keep the runtime source-neutral so a new mandate format can enter the same evaluation and evidence path.

03

Standards-first verification

Everything is designed to verify with ordinary tooling: WebAuthn, JWS with ES256, SHA-256, RFC 6962, RFC 3161, rather than novel cryptography a security team cannot assess.

No compatibility, certification, or delivery date is promised for anything on this list.

Principles

The rules we build by.

Neutral by design

PSP-agnostic and free of provider-shaped versions: the same proof has to hold whichever rail you run, or it is not proof.

Standards, not inventions

WebAuthn, JWS, SHA-256, RFC 6962, RFC 3161: primitives your security team can assess with tools it already has.

Smallest useful surface

Raw HTTP plus a quickstart. No SDK sprawl, no hidden client, no drift between the docs and the product.

Nothing ships on a claim

Every public statement is checkable: free test keys, a live playground, published keys, and verification guides that run on your machine.

Verify it. Then trust it.

Free test keys, a live playground, and guides that check the evidence and the record on your own machine.