ApexClaw controls what your AI agents can do, and proves what they did.
The wedge: deterministic, rule-based measurement of agent systems — no model sits in the judgment seat. When we scan a customer's own source tree, the scan runs on their machine and never leaves it.
One request, followed end to end.
Not marketing shapes — the real control path. A deterministic gate decides before anything executes; a checksummed receipt is written after.
Static picture when motion is reduced: the same diagram, same labels, no animation.
Five surfaces, one trust spine.
Each is a control that fires before an action, or an evidence object produced after it — the canonical set, from /platform/.
Agent Passport
Every agent carries an identity: owner, mission, permissions, autonomy level, and lifecycle. No anonymous actors.
Agent identity →Assurance Gateway
Deny-by-default policy gates and payload-bound, expiring approvals decide whether an action executes.
Policy enforcement →Flight Recorder
Checksummed execution receipts you can replay to reconstruct any action, end to end.
Execution receipts →MCP Governance
Identity, authorization and tool-exposure control for Model Context Protocol servers and tools.
MCP governance →Agent Wallet Governance
Hard, fail-closed ceilings on actions, rate, and spend. A cap that refuses, not a throttle that slows.
Wallet governance →- Agent Passport — identity, owner, mission, permissions, autonomy level, lifecycle.
- Assurance Gateway — deny-by-default gate; payload-bound, expiring approvals.
- Flight Recorder — checksummed execution receipts, replayable end to end.
- MCP Governance — identity and tool-exposure control for MCP servers.
- Agent Wallet Governance — hard, fail-closed ceilings on actions, rate and spend.
Run the same engine against your own page.
The Agent Readiness Benchmark (ARB/1.1) fetches one public page and runs 49 deterministic checks across 9 pillars — machine access, structured data, extractability, evidence, entity clarity, agent surface, governance, off-site corroboration, and security surface. Free teaser scan; full findings, remediation and the standards crosswalk on unlock. Full rubric →
Verified live at audit.apexclawai.com — three-state verdicts, never a silent pass.
ApexClaw also runs the governance it sells: Omega, the autonomous system we operate ourselves under our own controls, has produced 0% real external sends across its entire history — verified at the network layer, not inferred from logs.
30-site public-homepage cohort — real scores, not a mockup
Only 26.7% of this cohort scores 70 or above — see the full cohort and methodology.
What's in the full report?
- Every check, three-state: VERIFIED, UNVERIFIED, or UNOBSERVABLE — never a silent pass.
- The evidence string each check actually observed, not just a score.
- A remediation note per finding, and the standards crosswalk mapped to your results.
- Where you sit against the 30-site cohort — percentile, not just a raw number.
Common questions
Does the audit tool see our source code?
The public-page benchmark only fetches the one page you give it. The governance audit's local scanner runs on your own machine against your own source tree and never leaves it.
Are execution receipts signed?
No. A receipt carries a SHA-256 integrity checksum — it detects an edited record but does not prove who produced it. Signing is planned, not shipped.
What do VERIFIED, UNVERIFIED and UNOBSERVABLE mean?
Evidence was observed and satisfies the check (VERIFIED); evidence was observed and does not (UNVERIFIED); or the evidence needed to decide is absent, which is never scored as a pass (UNOBSERVABLE).
The Agent Readiness Registry.
The same engine, pointed outward: 39 real organisations' public pages scored. The naming rule was fixed before any organisation was scored — only scores of 70 or above are named, so the page can't read as cherry-picking. 3 of the 39 currently clear it, under 8%: by cohort, that's 20% of AI Security and Governance Tools and 8.3% of AI Agent Vendors.
- Credo AI
- Arize AI
- Mistral AI
Mapped to the frameworks auditors actually ask about.
| Framework | Official reference | Mapped on this site |
|---|---|---|
| OWASP ASI Top 10 | genai.owasp.org | View mapping → |
| NIST AI RMF | nist.gov | View mapping → |
| ISO/IEC 42001 | iso.org | View mapping → |
| EU AI Act | eur-lex.europa.eu | View mapping → |
The rubric is published and versioned — methodology — and the vectors behind it are runnable by anyone with a Python interpreter, against a fixed clean/dirty fixture pair with a fixed expected outcome. Nothing here asks to be taken on faith.
See the full standards crosswalk → · Run the conformance vectors yourself →
A governance question, not a product claim.
Evidence about agent actions gets retained for years, so whatever eventually signs it has to be replaceable before that signature scheme is broken — algorithm agility is the requirement, decided long before the migration is urgent.
ApexClaw does not sign receipts today. Current integrity comes from a SHA-256 checksum only — it detects an edited record, it does not authenticate who produced it. Signing, when it ships, will be designed for algorithm agility from day one rather than retrofitted under deadline.
Assessment engagements, scoped and delivered directly.
For teams that want the audit run against their own estate, not just a public page — inventory, permissions, MCP exposure, evidence, revocation testing. ApexClaw is the company entity behind this site: ApexClaw on LinkedIn.