Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Developer and enterprise architecture

Built for enterprise systems. Designed for autonomous operations.

Bifrost implements the interoperability contracts and security controls enterprise systems already rely on. Cedar makes every authorization decision; the AuthZEN interface exposes those decisions to your identity provider or gateway, which remains the enforcement point.

Organization AEvidence owner · decides
  • Own identity and keys
  • Own evidence boundary
  • Own Cedar policy
Bifrost trust exchangeIdentify
Organization BRequesting agent · asks
  • Own identity and keys
  • Delegates bounded authority
  • Verifies independently

OAuth 2.1

Authorization-code flow with PKCE for agents and reviewers, per-tenant protected-resource metadata.

DPoP

Sender-constrained tokens (RFC 9449). Restricted material is never released without a DPoP-bound token, and owners can require DPoP workspace-wide.

MCP

Agents connect to a tenant trust center over the Model Context Protocol to ask, search and browse governed evidence.

A2A v1.0

A tenant Agent Card and a JSON-RPC SendMessage endpoint, sharing MCP’s token, policy, citation and receipt guarantees.

OpenID AuthZEN PDP

Access-evaluation endpoints (single and batch) backed by the real Cedar decision. A decision point, never an enforcement point.

Cedar authorization

The owner’s policy decides what each principal may see or do for a purpose, before retrieval and before any action decision.

Signed receipts

Ed25519 JWS receipts bound to a Merkle root of the cited evidence, logged in an RFC 6962 transparency log with witness cosignatures and OpenTimestamps anchors.

Independent verification

The Apache-2.0 @odingard/bifrost-verify package and CLI verify receipts, packets, credentials and action chains offline.

Tenant isolation

Row-level security forced on every tenant table, envelope-encrypted secrets, rate limits and a per-tenant kill switch for agent access.

Delegated authority

Recorded delegation chains up to three levels; each child can only narrow its parent’s actions, limits, purpose and expiry.

Revocation

Revoking a delegation blocks every later decision that depends on it. Earlier records stay verifiable and show when revocation happened.

Action-chain evidence

Proposal, decision, acceptance and execution report are linked by hash and exported as a single chain the verifier checks offline.

Bifrost does not execute purchases, move money or operate a customer’s ERP. The customer’s business systems perform the underlying operations. Bifrost governs and records the trust exchange.

Evaluations run on synthetic data. Deployment model, data residency and eligibility for regulated data are agreed during onboarding.

Technical documentation

Engage with Bifrost

Business buyer

Enterprises, software vendors, procurement teams, and trust and security leaders.

Request a Bifrost Demo

Consulting and channel partner

vCISOs, security consultants, GRC service providers, and technology partners.

Become a Bifrost Partner