Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

BifrostThe Autonomous Trust Center

The zero-trust gateway for agent-to-agent exchange.

Bifrost lets one company's AI agent get answers it can trust from another company's private data, without either side handing that data over. The requesting agent proves who it acts for, the owner's policy decides what may be disclosed, and the answer comes back cited and signed. The raw records never move.

In development. Bifrost is being built with a design-partner cohort and is not generally available. Security review is the first market. The other verticals on this page are planned, not built.

AI agents now work across company lines

A buyer's agent reviews a vendor. A payer's agent checks a prior authorization. An acquirer's agent works a diligence list. Every one of these exchanges needs four things today's infrastructure does not provide, so companies still choose between copying the data out and routing every question to a person. The first leaks, and the second cannot keep up with agents asking thousands of questions an hour.

  1. Who is askingNot just an API key: which organization the agent acts for, under what agreement, and proof the token was not stolen and replayed.
  2. What may be disclosedThe data owner's rules, enforced before anything is read, rather than a model asked to be careful.
  3. An answer, not a dumpThe requester needs a fact. The owner should not have to export a database to give one.
  4. Proof of what was saidA record both sides, and their auditors, can verify long after the exchange.

Questions come in. Signed answers go out.

Bifrost sits at the edge of the data owner's perimeter. Every inbound question passes through the same five steps, and only the answer and its receipt leave.

1. Prove the principal

Agents connect over OAuth 2.1 with PKCE, and every token is sender-constrained with DPoP, so a stolen token is useless without the agent's private key. Each request is bound to an organization and the agreement that governs it.

2. Policy before retrieval

The owner's rules, written in Cedar, decide what this principal may see for this purpose. Restricted material is excluded before retrieval, so the answer engine never reads what the requester is not entitled to.

3. Answers, not data

The answer is computed from the owner's records inside the owner's perimeter and cites its sources. If nothing approved supports it, Bifrost refuses and routes the question to a person instead of guessing.

4. Screen the output

Every answer is checked for prompt-injection effects and for content above the requester's tier before it is released.

5. Sign and record

The answer is signed with the owner's key against a hash of the exact evidence used and written to a hash-linked audit chain. The requester can verify it later, and so can their auditor.

Discoverable by any agent

A machine-readable trust manifest at a well-known URL tells any agent what the owner exposes, what terms apply and how to qualify. Agents connect over the Model Context Protocol (MCP).

One core, every regulated exchange

Swap "vendor" and "buyer" for any two organizations that must exchange sensitive facts and the pattern holds: one side needs an answer it can rely on, and the other cannot hand over the records because of law, contract or competitive risk. Each market runs on the same core. What changes is the data connector, the policy pack and the regulation the policy encodes.

Security reviewFirst market · in development

The buyer's AI runs the vendor security review end to end

Today
Hundreds of questions per deal, answered by hand by one security lead while sales waits. Trust centers moved the documents into a portal but not the work.
With Bifrost
A gated trust portal, autonomous SIG and CAIQ questionnaires, a freshness monitor, and a buyer agent that qualifies, asks and leaves with a signed review packet its own GRC tool can re-verify.
Never leaves
Restricted reports and documents above the reviewer's tier.
Why it matters
Reviews clear at agent speed, and every answer can be proven true on the day it was given.

Insurance underwritingPlanned

The insurer's agent verifies controls instead of reading a self-attestation

Today
Applicants self-attest to MFA, endpoint coverage and backups on long forms, and a wrong answer surfaces at claim time.
With Bifrost
The underwriter's agent asks the control questions directly and gets answers signed against the applicant's evidence on the day of binding.
Never leaves
Configurations, architecture diagrams and internal audit findings.
Why it matters
A signed, timestamped answer replaces a checkbox, so both sides know exactly what was represented.

Finance and M&APlanned

The acquirer's agent audits the ledger without receiving it

Today
Targets upload ledger, contract and cap-table exports to data rooms and lose control of them the moment they are downloaded.
With Bifrost
The acquirer's agent works the diligence list against the target's systems and gets computed, cited answers on revenue concentration, churn and covenants. The target's policy sets what can be asked at each deal stage.
Never leaves
The general ledger, customer names and contract terms, unless the deal stage allows it.
Why it matters
The receipts become the diligence record, and representations point to exactly what was disclosed and when.

HealthcarePlanned

Payer and provider agents settle a prior authorization from the record

Today
Staff assemble chart packets by hand, payers review them by hand, and more of the record moves than the decision needs.
With Bifrost
The payer's agent asks whether specific clinical criteria are met. Bifrost answers from the provider's record with citations to the supporting encounters, in an isolated, in-region deployment under a business associate agreement.
Never leaves
The full chart, unrelated encounters, and anything outside the minimum necessary for the request.
Why it matters
Faster decisions, less patient data in motion, and a verifiable record of what supported each one.

Legal and eDiscoveryPlanned

Opposing counsel's agents exchange discovery under the protective order

Today
Productions are bulk transfers, confidentiality is enforced by trust, and inadvertently produced privileged material is caught late.
With Bifrost
The protective order and ESI protocol become policy, confidential and attorneys'-eyes-only become access tiers, and privileged material is excluded before retrieval.
Never leaves
Privileged documents and anything outside the agreed custodians, date ranges and topics.
Why it matters
Each side holds a signed record of what was produced, to whom and under which designation, which supports clawback and privilege disputes.

Enterprise supply chainPlanned

Procurement and supplier agents negotiate without exposing margins

Today
Closing a deal over email and portals means sharing inventory, capacity and cost structure the other side can use against you.
With Bifrost
The procurement agent asks whether 10,000 units can ship in 30 days at a target price, and the supplier's policy answers yes, no or a counter from internal systems. Origin, certifications and SBOM questions are answered from evidence.
Never leaves
Unit costs, margins, inventory levels and other customers' pricing.
Why it matters
A signed quote is a record both sides can hold each other to, produced at agent speed.

Security review is the first vertical, not a separate product. Each further market adds a pack of connectors, policies and a regulatory overlay on the same core. Those packs are planned and will be built with design partners in each market.

Security model

Built for an adversarial front door

A gateway that answers outside agents from private data is itself an attack surface, so Bifrost treats every inbound question as hostile. Access is the intersection of the connection's scopes and the principal's tier. Tokens cannot be replayed. Standard tenants are isolated by row-level security; regulated data gets dedicated, in-region deployments with per-tenant and customer-managed keys. Inference is model-portable, and isolated deployments are designed to run self-hosted models such as NVIDIA NIM inside the owner's environment, so raw records never reach a third-party model provider. Every tenant has rate limits and a kill switch for agent access.

Read more

Your evidence, their decision

Bifrost is starting with a design-partner cohort of B2B software companies whose deals stall in security review, and talking with organizations in insurance, finance, healthcare, legal and supply chain about the packs that come next.