Legit puts a verified human and a real, serveable entity behind every agent — so the gates that block them, and the buyers that vet you, get a cryptographic answer to “who's accountable?”
Private to the world. Accountable to the few who require it.
The gates the agent economy runs on all ask the same question — and an unaccountable agent can't answer it.
Cloudflare, Akamai, and the anti-bot stacks challenge or 403 your agent. A key gets you recognized — but only if there's something accountable behind it.
Visa and Mastercard's agentic checkout require a verified agent and proof a real human authorized the purchase. No proof, no payment.
“Who's accountable for this agent? Who's serveable if it acts wrong?” is now a standard line in enterprise vendor assessments. “It runs under our API key” stalls the deal.
We don't replace Cloudflare or Visa. We're the verifiable answer they — and your buyers — can point to: a real human and a real entity that can be held answerable.
Persona-grade KYC anchors every agent to an accountable person, behind a real, serveable legal entity the agent operates as. Shielded from the public; disclosed only on valid legal process.
For anything with weight, the agent prepares and a verified human approves out-of-band. Legit renders the consent and signs an offline-verifiable receipt — the agent can't show one thing and have another signed.
Revoke the credential and the agent is evicted from the recognized economy — re-blocked, unable to transact. The entity stays as the legal recourse. Recognition you can pull, and a party you can answer to.
Bind the agent to a KYC-verified human and a real, serveable entity it operates as.
The agent gets a verifiable operator credential (Ed25519 / Web Bot Auth) — recognized, not blocked.
High-stakes actions route to the human; Legit returns a signed “a named human approved this exact act” receipt.
Anyone checks it offline at /verify — entity, standing, accountable root — with no PII.
The agent-governance questions in a vendor assessment, mapped to a Legit artifact your buyer can check themselves.
| The question in the assessment | The Legit answer |
|---|---|
| Who is accountable for this agent? | A KYC'd human + serveable entity at its root. EU AI Act Art. 26 |
| How does a human authorize high-risk actions? | The relay + an offline-verifiable signed decision receipt. Art. 14 · NIST AI RMF |
| Is there a tamper-evident audit trail? | Hash-chained log; receipts verify offline. Art. 12 · SOC 2 CC7 |
| Can the agent's authority be revoked? | Revocable credential + standing flip on /verify. Treasury FS-AI RMF |
| Can we verify it without trusting you? | Yes — Ed25519-signed, offline, no PII, no callback. |
The boundaries are the brand. We say the true, un-hyped thing.
If a stalled deal or a blocked agent is hanging on “who's accountable?”, the answer takes one demo.
or email hello@getlegit.com · verify a credential
Public verification · no login · no PII · disclosed only on valid legal process