Protected credentials
Credentials stay inside the protected environment, outside the agent’s reach.
Connect your business systems, define the rules, and let AI carry out permitted actions inside a protected execution environment. Keep sensitive credentials out of the agent’s reach. Prevent bypass. Prove enforcement.
Get updates about early access.
01 / THINKING
AI agents can connect to payments, customer data, identity, infrastructure, and external services, giving a single system unprecedented reach and authority across the business.
As agent capabilities grow, businesses need reliable controls over what they are allowed to do.
Before a sensitive action is carried out, the business needs to know:
Policies aren't enough if they can be bypassed.
02 / APPROACH
Policy checks and permitted operations run together inside the protected environment. Your rules are enforced where the action happens, without exposing credentials to the agent.
Prevent bypass. Prove enforcement.
Credentials stay inside the protected environment, outside the agent’s reach.
Requests follow your configured policy, including additional approval when required.
Review the request, policy decision, and calls and responses recorded within the protected environment.
03 / FOUNDATION
Radix runs inside ProvenCore, ProvenRun’s formally verified operating system. This foundation provides strong isolation for the code that evaluates policy, accesses protected credentials, and executes permitted operations.
For on-premises deployments, dedicated ProvenHSM hardware adds physical protection around this trusted environment.
ProvenCore is certified to Common Criteria EAL7, the highest assurance level under the Common Criteria framework.
ProvenHSM provides Common Criteria EAL5+ assurance, with FIPS 140-3 Level 3 validation in progress.
ProvenCore certification details →TEAM
Brian Hall
Head of GTM & Partnerships
Leads Radix’s commercial strategy, customer development, and partnerships.
LinkedIn