Loading...
Models, prompts, skills, tools, third-party libraries, training data — your agent's supply chain is opaque to the customer who depends on it. Armalo makes provenance, capability attestations, and dependency audit a queryable property of every agent. Like SBOM for AI.
Free to start · Audit one agent immediately
SBOM
For Agents
Models · Skills · Tools · Data
Signed
Capability Claims
Tamper-evident
EU AI Act
Mapped
Provenance requirements
On-chain
Anchoring
Base L2 · Survives vendor changes
Proof primitives for production-grade agent trust
Verifiable Pacts
Commitments third parties can inspect
Contestable Jury
Independent verdicts, not one black box
Economic Accountability
Escrow-backed consequences for delivery
Live Oversight
Operators can inspect and intervene
Portable Trust Oracle
A queryable record that travels
Open Proof Surface
112 MCP tools · REST · SDK
Works with the stack agents already run on
Models, training data, skills, tools, providers — every component is a supply chain risk and none of them are inventoried.
When your agent uses a third-party skill or tool, you cannot prove the version, origin, or behavior to an auditor.
Armalo scans your agent and registers every model, skill, tool, library, and provider it touches.
Each component gets a capability claim and an attestation. Tampering breaks the chain visibly.
SBOM became table stakes for software in three years. The same is happening for AI. Armalo treats the supply chain as a first-class trust property — not a documentation afterthought.
Model provenance
Provider, model ID, version, training-cutoff window. Verified at registration and continuously.
Armalo AI
Free plan audits one agent and publishes its provenance. Enterprise plans add continuous attestation.
Free to start · Audit one agent immediately
EU AI Act, NIST AI RMF, SEC AI rules — all require documented supply chain. Without instrumentation, you have nothing to show.
Auditors, buyers, and counterparties can query /api/v1/trust/:agentId/provenance for the full supply chain.
Skill / tool attestations
Every skill and tool your agent uses is registered with a capability claim. Hash mismatch breaks the chain.
Dependency audit
Continuous scan of agent dependencies. Vulnerable component? Trust score reflects it.
Counterparty-readable
Provenance is public. Buyers and auditors query it directly — not through your sales team.