Sovereignty Verification Protocol introduces the Agent Identity Token — a cryptographic credential that lets autonomous systems declare who they are, what they're authorized to do, and at what assurance level, before touching any resource.
Every inbound request is evaluated at the network edge. The routing decision is deterministic, stateless, and takes under 10ms. No user impact. No false positives for human traffic.
Autonomous systems presenting a valid, non-revoked AIT with authorized scope are routed to the VAZ. Every transaction is audited.
All undeclared traffic — humans, legacy software, unknown automation — routes to the GAZ. GAZ does not mean blocked. It means implementation-specific risk assessment applies.
Traffic Arrives
↓
X-Agent-Token header present?
/ \
YES NO
↓ ↓
Validate General Access Zone
Signature (risk assessment)
Revocation
Scope
↓
All pass?
↓
Verified Agent Zone
(governed, audited)
AIT Assurance Levels map directly to NIST SP 800-63 IAL, DoD Zero Trust Pillar 1, and CMMC 2.0. Declare the right level and get the right access — no separate identity review process.
| Level | Designation | Verification | NIST Alignment | Use Case |
|---|---|---|---|---|
| AIT-0 | Self-Issued | Self-signed. No external verification. | IAL1 (self-asserted) | Development, testing, open APIs |
| AIT-1 | Registry Verified | Enrolled in AIR. Signing key registered. | IAL1 (verified) | Commercial APIs, developer access |
| AIT-2 | Organization Verified | Legal entity verification against official records. | IAL2 (remote) | Enterprise integrations, B2B agent access |
| AIT-3 | Government Validated | Identity verified against PIV, CAC, or Login.gov. | IAL2 (in-person eq.) | Federal contractors, defense industrial base |
| AIT-4 | High Assurance | Multi-factor verification, security review, ongoing compliance attestation. | IAL3 | DoD systems, IC, critical infrastructure, IL4/IL5 |
Every internet surface has a different vulnerability profile. Sovereignty Protocol addresses all three with the same underlying primitive — the Agent Identity Token.
Satisfy EO 14110 and DoD Zero Trust agent identity requirements. AIT-3/AIT-4 tokens with PIV/CAC validation. Immutable audit trail for compliance reporting.
Give your LangGraph, CrewAI, or AutoGen agents a declared identity. Route them cleanly through APIs without triggering bot detection. Full scope governance and revocation.
Differentiate search indexers from AI training crawlers for the first time. Gate training access behind licensing while maintaining search visibility. Reclaim control over your content's destiny.
Replace reactive bot detection with declarative identity. Composable with Cloudflare, Akamai, and HUMAN. GAZ risk scoring integrates with your existing SIEM infrastructure.
CMMC 2.0-ready audit logs. AIT-3 government-validated assurance. Supply chain AI agent governance for prime and sub-contractor environments.
Implement the open AIT schema and join the ecosystem. Python, Rust, and JavaScript SDKs on GitHub. Composable with MCP, OpenAI Agents SDK, and any JWT-compatible infrastructure.
The AIT schema is free and open source (CC0). The validation infrastructure, registry, and enterprise features are proprietary SaaS. Same model as HashiCorp / FIDO Alliance.
We're onboarding design partners for the Hosted Gateway and Sovereign Registry. Tell us what you're building and we'll reach out within 48 hours.
Or email directly: contact@bravo-01-labs.com