Sovereignty Verification Protocol introduces the Agent Identity Token — a cryptographic credential that lets autonomous systems declare who they are, what they're authorized to do, and at what assurance level, before touching any resource.
Every inbound request is evaluated at the network edge. The routing decision is deterministic, stateless, and takes under 10ms. No user impact. No false positives for human traffic.
Autonomous systems presenting a valid, non-revoked AIT with authorized scope are routed to the VAZ. Every transaction is audited.
All undeclared traffic — humans, legacy software, unknown automation — routes to the GAZ. GAZ does not mean blocked. It means implementation-specific risk assessment applies.
Traffic Arrives
↓
X-Agent-Token header present?
/ \
YES NO
↓ ↓
Validate General Access Zone
Signature (risk assessment)
Revocation
Scope
↓
All pass?
↓
Verified Agent Zone
(governed, audited)
AIT Assurance Levels are designed to provide a structured assurance hierarchy informed by NIST SP 800-63 and relevant government identity and zero-trust concepts. Resource owners determine which assurance levels their resources require and remain responsible for their own identity, authorization, and compliance policies.
| Level | Designation | Verification | NIST Alignment | Use Case |
|---|---|---|---|---|
| AIT-0 | Self-Issued | Self-signed. No external verification. | IAL1 (self-asserted) | Development, testing, open APIs |
| AIT-1 | Registry Verified | Enrolled in AIR. Signing key registered. | IAL1 (verified) | Commercial APIs, developer access |
| AIT-2 | Organization Verified | Legal entity verification against official records. | IAL2 (remote) | Enterprise integrations, B2B agent access |
| AIT-3 | Government Validated | Identity verified against PIV, CAC, or Login.gov. | IAL2 (in-person eq.) | Federal contractors, defense industrial base |
| AIT-4 | High Assurance | Multi-factor verification, security review, ongoing compliance attestation. | IAL3 | DoD systems, IC, critical infrastructure, IL4/IL5 |
Every internet surface has a different vulnerability profile. Sovereignty Protocol addresses all three with the same underlying primitive — the Agent Identity Token.
Support applicable EO 14110, DoD Zero Trust, and federal identity and audit requirements through cryptographically verifiable agent identity, assurance levels, scoped authorization, revocation, and auditable routing.
Give your LangGraph, CrewAI, or AutoGen agents a declared identity. Route them cleanly through APIs without triggering bot detection. Full scope governance and revocation.
Differentiate search indexers from AI training crawlers for the first time. Gate training access behind licensing while maintaining search visibility. Reclaim control over your content's destiny.
Replace reactive bot detection with declarative identity. Composable with Cloudflare, Akamai, and HUMAN. GAZ risk scoring integrates with your existing SIEM infrastructure.
Audit records designed to support applicable CMMC 2.0 audit and traceability requirements. AIT-3 provides a government-validated assurance level within the SVP framework. Designed for AI agent governance across prime and subcontractor environments.
Implement the open AIT schema and join the ecosystem. Python, Rust, and JavaScript SDKs on GitHub. Composable with MCP, OpenAI Agents SDK, and any JWT-compatible infrastructure.
The AIT schema is free and open source (CC0). The validation infrastructure, registry, and enterprise features are proprietary SaaS. Same model as HashiCorp / FIDO Alliance.
We're onboarding design partners for the Hosted Gateway and Sovereign Registry. Tell us what you're building and we'll reach out within 48 hours.
Or email directly: contact@bravo-01-labs.com