ApexClaw
Evidence-Grade Agent Trust Layer

Govern every AI agent action before it happens. Prove every action afterward.

ApexClaw is an agent trust and governance platform. It decides whether an autonomous agent is allowed to act — checking identity, policy, scope, and human approval before execution — and emits a signed, tamper-evident receipt proving exactly what happened. You gave your agents tools and money. ApexClaw is how you prove who acted, why it was allowed, and how to stop it instantly.

IdentityEvery agent carries a passport and a human owner.
Policy & approvalDeny-by-default gates, payload-bound approvals.
ReceiptsSigned, hash-chained, replayable evidence.
RevocationKill switch and grant revocation, both tested.

Published · updated · reviewed by , founder

The problem

Most teams running AI agents cannot answer seven questions.

Gartner projects that more than 40% of agentic AI projects will be cancelled by the end of 2027, driven by escalating cost, unclear value, and inadequate risk controls. The controls are the gap. These are the questions a board, an auditor, or a regulator will ask — and the ones a trust layer answers.

Who acted? Which agent, under whose accountable ownership, took this action?
Why was it allowed? Under which policy version, and did it pass every gate?
Was it approved? If the action was consequential, who approved this exact payload, and had that approval expired?
Can you prove it? Is there a signed, tamper-evident receipt — not just a log line that could be edited?
Can you stop it? How fast can you revoke one agent, or halt all of them, right now?
Can you replay it? Can you reconstruct exactly what happened for an incident review?
Can it overspend? Is there a hard, fail-closed cap on what an agent with a wallet can do?
Can you show an auditor? Can you assemble evidence for a review without a month of forensics?
The platform

Five surfaces, one trust spine.

Each is a control that fires before an action, or an evidence object produced after it. Together they are the minimum trust spine for agents that touch revenue, procurement, and sensitive workflows.

Agent Passport

Every agent carries an identity: owner, mission, permissions, autonomy level, and lifecycle. No anonymous actors.

Agent identity →

Assurance Gateway

Deny-by-default policy gates and payload-bound, expiring approvals decide whether an action executes.

Policy enforcement →

Flight Recorder

Signed, hash-chained execution receipts you can replay to reconstruct any action, end to end.

Execution receipts →

MCP Governance

Identity, authorization and tool-exposure control for Model Context Protocol servers and tools.

MCP governance →

Agent Wallet Governance

Hard, fail-closed ceilings on actions, rate, and spend. A cap that refuses, not a throttle that slows.

Wallet governance →
Watch it decide

Three actions. Three correct outcomes.

The mechanism, shown rather than asserted. Full walkthrough on the demo page.

BLOCK

Out-of-scope action, refused.

An agent tries to send outside its mission scope. The gate refuses before execution and emits a signed refusal receipt naming the policy that denied it.

APPROVE

Payload-bound, expiring.

A consequential action is approved for one exact payload, once, with a deadline. Change the payload or miss the window and the same approval refuses.

TAMPER

Altered receipt, caught.

A receipt is modified after the fact. Chain verification fails and the evidence shows exactly where integrity broke.

▲ Synthetic demonstration, labeled as such. Sample structures: execution receipt · agent passport.

Proof, not assertion

ApexClaw runs the governance it sells.

Omega is a governed autonomous system operated under ApexClaw's own controls. On its record it has refused unauthorized external sends, emitted receipts, and made zero real sends across its entire history. That is the only credential a trust vendor can honestly self-issue: proof it governs itself.

A governed run, with receipts

The refusals, the gates, the evidence — published with failures visible, not a polished case study.

See the governed run →

Trust center & claims ledger

Material product and evidence claims, each with its basis, verification date and expiry. Stale claims show as stale.

Open the trust center →

Standards crosswalk

ApexClaw controls mapped to OWASP ASI01–10, NIST AI RMF, ISO 42001 and the EU AI Act.

See the crosswalk →

The Agent Readiness Registry

The same engine, pointed outward: 39 real organizations' public pages scored, evidence published, only scores 70+ named.

See the registry →
At a glance

How this differs, and the numbers behind it.

Facts already published elsewhere on this site, gathered in one place: how a trust layer differs from adjacent categories most teams already have, and the figures that motivate building one — each sourced and linked.

CategoryWhere an agent trust layer differs
Observability
Tells you what an agent did, after it did it.
Decides whether the action executes, before it does. Both are needed; only one prevents anything.
Guardrails / prompt filters
Inspect text going in and coming out.
Inspects the action and its authorization. A filter cannot tell you who approved a payment.
Audit logging
Records what the application chose to write down.
Records what was authorized, bound to the payload, chained so tampering is detectable.
GRC platforms
Track controls, policies and attestations as documents.
Enforces the control at runtime and produces the evidence the GRC platform is asking for.

Full comparison, all eight categories: /compare.

The numbers behind the case for governance

  • More than 40% of agentic AI projects are projected to be cancelled by the end of 2027 — Gartner.
  • ~88% of enterprise AI pilots fail to reach production, as circulated by Forrester in 2026 — see the caveat on the sourced statistics page.
  • ~46% of AI social citations are attributed to Reddit, per the third-party citation studies cited on the same page.
  • Omega, the system ApexClaw governs itself with, has produced 0% real external sends across its entire history — verified at the network layer, not inferred from logs, on the governed-run record.

Five platform surfaces, restated

  • Agent Passport — every agent carries an identity: owner, mission, permissions, autonomy level, and lifecycle.
  • Assurance Gateway — deny-by-default policy gates and payload-bound, expiring approvals decide whether an action executes.
  • Flight Recorder — signed, hash-chained execution receipts you can replay to reconstruct any action, end to end.
  • MCP Governance — identity, authorization and tool-exposure control for Model Context Protocol servers and tools.
  • Agent Wallet Governance — hard, fail-closed ceilings on actions, rate, and spend.
How we handle claims

Built to be cited without bluffing.

This site is written for buyers, auditors, and AI answer engines that will check our work. So we hold ourselves to one rule:

  • No fabricated numbers. Every statistic is sourced, first-party with methodology, or labeled TARGET, SYNTHETIC, or COLLECTING.
  • No certifications we do not hold. SOC 2 and ISO 27001 are roadmap items, never claimed as achieved.
  • No internal metric passed off as market proof. Our own system's numbers are labeled as our own system's numbers.
  • A past receipt is not proof of present health. Live claims carry an expiry and are re-verified on cadence.
Governance for agents is not a filter on prompts. It is a control between an agent's decision and its effect, with signed proof of what occurred.
Julian Joseph, founder of ApexClaw
Frequently asked questions

Answered here, in full in the schema below.

What is ApexClaw?

ApexClaw is an evidence-grade agent trust layer. It governs what autonomous AI agents are allowed to do before they act, and produces signed, verifiable receipts proving what they did afterward.

Is ApexClaw SOC 2 or ISO 27001 certified?

No. Both are roadmap items and are never claimed as achieved. ApexClaw's claim is narrower and provable: it makes autonomous agent actions governable before they happen and reviewable afterward through receipts, policy gates and evidence packages.

How is this different from AI observability or guardrails?

Observability tells you what an agent did after the fact. Guardrails filter prompts and outputs. A trust layer decides whether an action is authorized before it executes, binds that authorization to an exact payload, and emits a tamper-evident receipt.