OATHERA logo OATHERA
Platform Features Integrations Use cases Developers Security Request access

Security & trust

Designed so we never hold your keys.

On this page

  1. Principles
  2. The bearer-token problem
  3. Audit & evidence
  4. Compliance

Principles

Keys stay with you

Agent private keys are generated in your environment and never leave it. OATHERA never receives them.

No route into your systems

The OATHERA service is never given network access into your environment. Only approval requests and token requests cross the line.

Your data stays put

OATHERA verifies and decides; your data flows from the agent to your systems, not through us.

Fail closed

Anything that cannot be verified is refused.

Short lived by default

Tokens expire in minutes; revocation takes effect within one token lifetime.

Open, reviewed cryptography

Ed25519, RFC 9421 HTTP Message Signatures, OIDC and SPIFFE; no proprietary crypto.

Verifiable records

Approvals and decisions are signed and chained so tampering is detectable.

The bearer-token problem

AI agents are now the fastest growing class of non-human identity, and in most organizations they already outnumber human users many times over. Almost all of them authenticate with a bearer credential — a static key or token that grants its full authority to anyone who holds it, with no check on who is actually using it.

That is the gap attackers exploit. When a token is copied from a log, a repo or a disk, legitimate use and malicious use look identical, so the theft raises no sign-in alert. Industry incidents in which stolen integration tokens were replayed across hundreds of organizations — without tripping authentication — are the predictable outcome of a bearer model, not an exception to it.

  • Sender-constrainedCredentials work only with the bound private key and the machine they were issued for.
  • No bearer pathA token lifted from a log authorizes nothing on its own.
  • MinutesToken lifetime; a credential that is not renewed simply lapses.

OATHERA closes the gap by removing the bearer property entirely. Each request must carry a fresh signature made by a private key that never leaves your environment, inside an unexpired, human-approved token scoped to one machine. There is nothing to replay: steal the token and it fails, because the thief has neither the key nor the machine it is bound to.

Audit, evidence and regulatory readiness

Boards and risk committees are already asking how AI agents are authorized and exactly what they can reach. With the EU AI Act now in force and similar expectations spreading, “we are not sure” is an answer that gets more expensive every quarter. OATHERA is built so the answer is always on hand.

  • Every action is attributable. Each request ties back to a specific agent, its named owner, and the exact task, capability, operation and resource it was authorized for.
  • Every decision is logged. Allowed or refused, the gateway's verdict is recorded, so you can reconstruct precisely what happened during any agent's access window without hand-reading logs.
  • Approvals are evidence. The one-time human approval of an agent is sealed into a tamper-evident certificate that you can hand to an auditor.
  • Scope is provable. Because access is least-privilege by construction and expires on its own, you can show not just what an agent did, but the narrow envelope it was ever able to do it within.

Governance should accelerate adoption, not block it. When security can see who created each agent, what it may do and how it is behaving, approvals become lightweight instead of a bottleneck — and because OATHERA sits alongside your existing OIDC and workload-identity systems, there is no new identity stack to migrate to first.

Compliance

We will add SOC 2, ISO 27001 or other attestations here once achieved. In the meantime, review our Privacy Policy, Data Processing Agreement and Sub-processors, and request a security questionnaire via our contact page.

← Back to OATHERA
OATHERA logo OATHERA

The agentic identity platform. Verifiable, human-approved, short-lived identity for every AI agent.

Product

  • Platform
  • Features
  • Integrations
  • Use cases

Developers

  • Docs
  • GitHub
  • Demo

Company

  • Security
  • Contact
  • Careers soon

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
© 2026 OATHERA · Agentic Identity Platform

Cookie preferences

We use cookies to run this site and, with your consent, to understand usage and improve OATHERA. Strictly necessary cookies are always on; you can choose whether to allow analytics and marketing cookies below.

  • Strictly necessaryAlways on

    Required for the site to work — security, load balancing, and remembering your cookie choices. These cannot be switched off.

  • Help us measure traffic and see how the site is used, so we can improve it. No personal profiles are built.

  • Used to make messages about OATHERA more relevant across other sites. Off unless you turn it on.