Spellguard and AGNTCY

When Spellguard launched, most of the agent security market was looking inward. Vendors were shipping policy engines, observability layers, and compliance tooling designed to govern agents inside a single organization. The Spellguard team focused on a different question: what happens when an agent's job takes it outside the organization?

Human employees cross organizational lines every day. They email counterparties, negotiate contracts, and move data between companies as a normal part of work. As enterprises hand agents more complex jobs, those agents will do the same, and a security model that assumes containment will meet interactions it was never designed for.

The risk is already measurable. A Cloud Security Alliance study found that 53% of organizations have had AI agents exceed their intended permissions, and enterprise leaders consistently rank security and data privacy as the top barriers to agent adoption.

The problem with fragmented logs

When agents from two enterprises interact, each side walks away with its own log of what happened. Reconciling the two accounts is difficult even when both parties act in good faith.

Any vendor with customer relationships on one side of an interaction has a conflict of interest in judging it. This conflict of interest extends to security platforms, hyperscalers, and model providers alike. Cross-enterprise verification needs to live in a neutral layer that neither party owns, which highlights the need for open source standards.

An open protocol, with a company built on top

Spellguard follows the same structure as the Internet of Agents itself: an open foundation with commercial services above it.

The open source Spellguard protocol records agent-to-agent interactions to a cryptographically signed event ledger both counterparties can verify independently, alongside counterparty identification and policy enforcement. Because the protocol is permissionless, trusting the record requires trusting neither the other enterprise nor Spellguard.

On top of the protocol, the Spellguard company runs a managed control plane for enterprises that need audit-ready compliance and AI governance for agents that interact both inside and outside their organization.

Built on SLIM and the Agent Directory Service

Rather than maintain a bespoke communication layer, Spellguard replaced a core piece of its own product with SLIM (Secure Low-latency Interactive Messaging) and integrated the Agent Directory Service, two major parts of the AGNTCY stack.

The team's technical background comes from low-trust, adversarial environments spanning trusted execution environments, network security, cloud computing, and cryptography. Spellguard's founding engineer previously built machine learning tools at Google used by frontline security teams to detect anomalous behavior and data exfiltration attempts.

Getting Involved

Spellguard’s open source standard for agent-to-agent governance is live now and open for community collaboration.

The Spellguard product is available for demo for enterprises dealing in this problem space and looking for a ready-to-go solution.

Secure, auditable
agent-to-agent communication.

Ask AI about Spellguard: