The independent trust layer for AI agents

Govern AI agents. Prove every action.

Stop prompt injection, data exfiltration, and tool poisoning before your agents execute, with in-path enforcement and cryptographically signed proof of every decision. Independent of any AI vendor, and verifiable without trusting us.

Zero false positives on our reproducible public benchmark · Verify a receipt offline →

Decision receipt
Signed
rcpt_9f3a1c7e…d204
decisionDENY
lawQX-L-0002
subjectsend_email · mcp
risk0.94
detectorcall-args@2
issued2026-07-24T20:41Z
Ed25519 signature
MEUCIQC7xk2mZ0nJf4vK1oR9pW2wF8sHu3bNa7QcVd0eLgIhAJ+u4rT…aQ==
Verified offline@queldrex/verify
The exposure

Your agents take real actions. The tool call is the blind spot.

Model guardrails watch the words. Almost nothing watches the tool call, where an agent with your credentials actually reaches your data and the network.

Tool poisoning

A single poisoned tool description can redirect an agent to exfiltrate secrets. The tool passes review; the instruction hides in the metadata your agent reads at call time.

Prompt injection

The #1 risk in the OWASP LLM Top 10. Untrusted content reaches a model that also holds your credentials and can reach the network, the lethal trifecta.

Data exfiltration

Agents act with real permissions. Once a call is untrusted-tainted and egress-capable, one step ships your data out, and nothing conventional is watching the tool call itself.

Silent capability drift

A tool you approved changes after approval, a rug-pull. Nothing re-checks it at call time, so the version you trusted is not the version that runs.

The solution

Scan. Govern. Prove.

A deterministic enforcement layer in front of your agents, and a signed, independently verifiable record behind them.

Scan

Every tool, MCP server, prompt, and tool output is checked for poisoning, hidden instructions, and exfiltration paths before your agent ever trusts it. Deterministic and fast, in the request path.

Govern

Queldrex sits in front of every tool call and enforces your policy: allow, pause for a human, or block. Per-agent budgets and allowlists, an emergency stop, and a live console, tighten-only over a safe baseline.

Prove

Every decision is an Ed25519-signed receipt your auditors verify offline, and blocks are sealed to a tamper-evident, hash-chained transparency log with inclusion and consistency proofs. Nobody has to take our word for it.

Evidence for your auditors

Signed proof that maps to the frameworks you answer to.

Queldrex produces the logging, transparency, and human-oversight evidence these frameworks ask for, as artifacts your auditors can verify. This is technical evidence, not a certification and not legal advice.

EU AI ActNIST AI RMFISO/IEC 42001OWASP LLM Top 10OWASP Agentic Top 10
Why independent matters

Not owned by an AI vendor, a cloud, or a security giant.

When the layer that judges your agents is sold by the company that also sells you the agents, something is always pulling the other way. Queldrex is an independent Colorado company. Every verdict is signed, every block is logged to a public transparency tree, and you can verify all of it offline with our zero-dependency, MIT-licensed verifier. Trust is the product, so it is built to be checked, not believed.

Start here

Request an AI risk and EU AI Act assessment.

A scoped, human-led review of where your agents can be attacked and what evidence you would need under the EU AI Act and the OWASP LLM Top 10. No obligation, no sales spam.

  • A map of your agents’ attackable tool calls
  • Where in-path enforcement would apply
  • The signed evidence your auditors would receive

No sales spam. This files a request for a human-led assessment, not an automated report. You can reach a person any time at hello@queldrex.com.