Ship AI agentsyour security teamcan prove.
Your guardrails read what your agent says. We attack what it does— then sign proof your customer’s security team can verify without trusting us.
Most vendors sign a claim about your agent.
Here the agent signs for itself.
An agent that can act needs an identity it actually controls — one that survives compromise, survives a lost key, and can be checked by a counterparty who trusts neither of you. Don't take that on faith: your browser is about to become the agent. It generates a real Ed25519 key we never see, signs its own identity, revokes itself, and verifies both — with no server in the loop.
While it still holds the key, the agent designates recovery keys and a threshold. Retiring a lost primary then needs k-of-n signatures from those designated keys — not a support ticket, and not a vendor with a master override.
A log you can only read from one source still asks you to trust that source. So checkpoints are co-signed by independent witnesses, and the verifier only trusts a revocation’s place in history when its inclusion proof folds into a witnessed checkpoint. The code and endpoints ship today; the guarantee lands as independent operators come online — and we’ll say so plainly until they do.
Everything above is for you.
This part is for your agent.
Governance only a human can drive isn't governance for an autonomous system — it's a dashboard someone checks on Monday. OmegaEngine ships as an MCP server, so the agent itself asks permission before it acts, tests its own defences, and verifies proofs it was handed. Three of those tools need no key at all — so this page just called them, for real, from your browser.
$ npx -y @omegaengine/mcpget_pricingverify_proofscan_agentcheck_actiongate a risky action BEFORE it runs — returns allow · block · escalate, plus a one-use capability bound to that exact callclaim_approvalcollect the capability after a human approves an escalation, without a human re-driving the UIget_usageread its own consumption and throttle itself before it hits a limitThe loop a human drives through the dashboard, an agent drives through six tool calls — and the receipt it gets at the end is the same signed artifact, verifiable by anyone, offline.
You just watched an agent prove its own identity, and three tools verify themselves — no account, no API key, nothing to take on trust. That is the thing you hand a security team that is sitting on your deal. They check it themselves, without calling us and without believing us.
A larger customer wants to buy — and their security team froze the deal.
We produce signed, offline-verifiable audit evidence your enterprise counterparty can check themselves — delivered by the team, not a self-serve PDF. Two ways in: a one-time pack for the review in front of you, or a founder-led engagement.
Your guardrails check what the agent says.
We check what it does.
An agent is dangerous when it takes an action — wires money, emails data out, deletes records. We attack the tool calls, auto-generate the fix, prove it works by re-running the attack, and sign the proof. To our knowledge, nobody else owns both the red-team and the enforcement gate.
Measured over 50 taxonomy-grounded attacks (OWASP + MITRE ATLAS). Even a hardened gpt-4o-mini still leaks via tool-call injection — and even gpt-4o falls to SSRF & spoofed approvals. The gap between 98% and a breach is one attack; only enforcement outside the model closes it, with a signed proof.
Text guardrails are structurally blind to this — the harm is in the tool call, not the words.
One call in. A signed verdict out.
Request queued
Free to scan. Pay to prove.
Scan your agent for free. Request a signed attestation when you need to prove it's safe — or subscribe for continuous governance. Not tokens, not seats; you pay for judgment.
Self-assessed, auditor-ready evidence that unblocks an enterprise security review — mapped to OWASP LLM Top 10, MITRE ATLAS, EU AI Act Art. 15 & NIST AI RMF. Cryptographically signed, offline-verifiable.
Developer
1,000 decisions/mo
Includes
- 1,000 decisions/month
- Agent red-team CI gate
- Fix-proof + 1 protected agent
- Full safety system
- Webhooks
- 30-day log retention
Pro
Popular5,000 decisions/mo
Includes
- 5,000 decisions/month
- 9 processing steps
- Governance dashboard
- Posture dashboard
- CI/CD quick-scan
- 90-day retention
Business
25,000 decisions/mo
Includes
- 25,000 decisions/month
- All 12 processing steps
- Auto-remediation
- Ensemble (3 models)
- All model tiers
- 365-day retention
Enterprise
Unlimited decisions/mo
Includes
- Unlimited decisions
- All 12 processing steps
- Multi-model arbitration
- Enterprise SLA
- Custom integrations
- Unlimited retention
Concierge-assembled, offline-verifiable evidence for one enterprise security review. Scoped on a short call, then invoiced. Self-assessed, not a certification.
See what's insideStay audit-ready year-round: quarterly signed attestation, questionnaire autofill, an evidence locker, and a Merkle-anchored ledger. Scoped on a call, invoiced annually. Sits between Pro and Business.
Learn moreFounder-led, 90-day engagement — 3 slots — that ships the controls and the evidence to clear the review blocking your deal. Manually invoiced.
Apply for a slotEverything you need to know before getting started.
A decision is one governed action authorization — normally a call to POST /api/authorize right before your agent executes a side effect. Deep-judgment calls to POST /api/v2/judge also consume decision quota when metered. Each decision runs through up to 12 processing steps — safety classification, risk scoring, policy enforcement, adversarial detection, cryptographic proof, and more. You're not paying for tokens or compute. You're paying for judgment.
The policy, safety, and proof steps add only light overhead — in a real decision most of the time is the LLM call itself, which depends on the model you route to. We return per-stage timing on every response, so you can measure latency for your own workload instead of trusting a marketing number.
Yes. Upgrade or downgrade instantly from your dashboard. When upgrading, you'll be pro-rated for the remainder of your billing cycle. When downgrading, your current tier stays active until the cycle ends. No lock-ins, no penalties.
You'll get alerts at 80% and 95% usage. By default your agents pause at your plan's monthly cap, so you're never billed by surprise. Need to keep processing past the cap? Contact us to enable overage billing at a transparent per-decision rate.
Yes. The Free tier gives you 100 decisions per month with 5 processing steps — enough to integrate OmegaEngine, run real scenarios, and evaluate the platform before committing. No credit card required.
Cancel anytime — your plan stays active until the end of the billing period, no lock-in. Beyond that, fees are non-refundable except as required by law, per our Terms of Service (/terms).
We're an early-stage product and don't yet hold formal certifications like SOC 2 or HIPAA. What's built today: a tamper-evident, cryptographically signed audit trail on every decision (each with a unique Halo ID), PII redaction via the Compliance Suite scanner, configurable audit-log retention that scales with your plan (up to unlimited on the top tier), and an Apache-2.0 core with SDKs and an offline verifier already published on npm and PyPI (self-hosting via source-access agreement; monorepo opens at launch). If you need a specific certification, talk to us about your requirements and timeline.
Never. Our DPA commits in writing, for every tier, that your inputs, outputs, and decision payloads are never used to train or fine-tune models. Only aggregated reliability telemetry (latency, error rates) is used to run the service.
Fail-closed by design: if the system fails, actions are blocked — never silently approved. Circuit breakers route around unhealthy model providers, and live availability is published on our status page.
It's signed, offline-verifiable red-team evidence mapped to OWASP, MITRE ATLAS, NIST AI RMF, and EU AI Act Art. 15 — your auditor can re-verify every finding without trusting us. It is not a certification or audit; it's point-in-time evidence for your governance process.
Create a free account at /signup, then go to Dashboard → API Keys and generate one. Pass it as the x-api-key header on every request. No credit card required for the free tier.
Yes — OmegaEngine is BYOK-only on every plan. You pay model providers (OpenAI, Anthropic, Google, Mistral, Groq, DeepSeek, Meta) directly with your own key, and one-off scan keys are never stored. We run the governance (risk scoring, policy, attestation) and never resell or mark up inference.
Only agents and systems you own or are explicitly authorized to test, per our Acceptable Use Policy (/aup). During scans, tool calls are recorded, never executed — no real side effect can fire.
Yes, via source-access agreement today: the Apache-2.0 core runs on your infrastructure with the same API as the hosted service. The monorepo opens publicly at launch; the SDKs and offline verifier are already published on npm and PyPI.
support@omegaengine.ai (we target a 2-business-day response, prioritized for paid plans), and security@omegaengine.ai for vulnerabilities — triaged ahead of everything else. Community discussions open with the public repo at launch.
Still have questions?
Ship AI your enterprise can trust.
Free tier includes 100 decisions. Full platform access. No credit card. Production-ready in 5 minutes.
$npm install @omegaengine/sdk