Magenta Canon puts a gate between your AI agents and the systems they touch: it allows what you delegated, blocks the rest before it executes, and records every decision as evidence anyone can independently verify. Agent capability becomes something you govern and can prove — not something you hope about.

  • Gate-first: authorized actions are allowed and over-authority actions are blocked before they reach the tool
  • Recorded: every allow and block becomes a signed, hash-chained receipt on a Merkle transparency log
  • Verifiable: a standalone verifier re-derives the cryptography and shares no code with the server

FOR CEO / FOUNDER

You are responsible for the company — including everything its AI agents do on its behalf.

Magenta Canon puts a gate between your AI agents and the systems they touch: it allows what you delegated, blocks the rest before it executes, and records every decision as evidence anyone can independently verify. Agent capability becomes something you govern and can prove — not something you hope about.

Your top questions, answered

What does this actually do for my business?

It converts AI-agent risk into governed, provable decisions. Every action an agent attempts is checked against the authority you delegated, over-authority actions are blocked before they happen, and both outcomes become verifiable evidence you can show a customer, a regulator, or your board.

Is this a real product or a demo?

It is a working single-tenant reference implementation with a runnable end-to-end proof loop — gate, witness, receipt, verify. Hosted, durable, multi-tenant operation is roadmap and is labeled as roadmap. Under-claiming is deliberate.

What is the fastest way to see the value?

The five-minute proof loop: an $89 refund is allowed, a $250 refund is blocked at the gate, the downstream system's own log shows the blocked call never arrived, the evidence verifies — and one flipped byte makes verification fail.

What is the risk of doing nothing?

Agents are already touching payments, deployments, and customer data. Without a gate and without evidence, every agent action is unbounded trust — and after an incident you would have no independently checkable record of what happened.

Who is this for today?

Design partners running agent workflows where a wrong action costs real money or compliance exposure. Evaluation is private and controlled — you get a granted checkout and a direct line to us.


The proof story

The same demo runs every time — five beats, each independently checkable.

  • Allowed

    An $89 refund, within the delegated ceiling, is forwarded to the downstream tool.

  • Blocked

    A $250 refund exceeds the ceiling and is blocked at the gate — before it reaches the tool.

  • Absent downstream

    The downstream tool's own log shows the blocked call never arrived.

  • Verified

    A standalone verifier — sharing no code with the server — returns ORIGIN AND INTEGRITY VERIFIED.

  • Tamper fails

    Flip one byte of the evidence and verification fails. Tampering is caught, not hidden.


Your proof path

Your proof path takes ten minutes and requires no engineering time:

  1. Read the proof loop on this site: allowed, blocked, absent downstream, verified, tamper-fails.
  2. Have one engineer run the demo from a granted private checkout and confirm the verifier verdicts.
  3. Bring us one workflow where a wrong agent action would hurt, and we walk it end to end with you.

Honest scope — what this is, and is not, today

Under-claiming is the brand. Here is the current posture, stated plainly:

  • Evaluation today is private-access and repo-source: a granted private checkout. There is no public npm/npx install path.
  • What runs today is a reference proof path — a single-tenant reference implementation you run yourself. This is not broad production SaaS.
  • The durable hosted witness is not activated in production; the hosted evidence surface is ephemeral unless it is.
  • No compliance certification is claimed — no SOC 2, HIPAA, or similar. Compliance determination and legal judgment remain with external reviewers.
  • Verification is server-independent — the standalone verifier shares no code with the server — and the security model documents its remaining trust assumptions (docs/SECURITY_MODEL.md).

Ready to look closer?

Evaluation is private and design-partner controlled — a granted checkout and a direct line to us.

Request a private evaluation