You cannot buy this. You can still change it.
Said plainly before you spend any more time: there is no dedicated deployment to purchase, no self-hosted edition to licence, and no managed tier behind a sales call. That is not a gating tactic and the page will not warm up to a hidden offer. What is on this route is a conversation that is still early enough to be worth having, and the rest of this page is the evidence for why that sentence is not a euphemism.
The inventory, first
"Hosted authority" is a name for three things, and we run none of them for anyone.
The phrase appears on this site and it is worth being exact about what it denotes, because it is the kind of phrase a procurement document copies verbatim. It is our name for an aggregate, not a component you can point at, and the aggregate is these three. Each is stated on two axes, because they genuinely differ: what exists as code is not what exists as a service we operate, and reporting only one of those is how an inventory that meant to be conservative ends up simply inaccurate.
KMS-backed key custody
The signing seam is a port, and one adapter is live: GcpKmsOperatorSigner performs a real Cloud KMS asymmetricSign against an EC_SIGN_ED25519 key version, so a private key can stay inside a KMS its owner controls. Two limits, and the second is the one worth reading twice. First, only that one adapter is live — AWS and Azure are written to spec and deliberately inert, both returning Err(not_live()). Second, and more important: the live path signs operator control-plane material, not VAID documents. A VAID is signed by a ring Ed25519 keypair the kernel reconstructs from raw PKCS#8 bytes it holds in memory, and the KMS seam does not reach that key — there is no KMS branch in the kernel-key bootstrap at all. So this seam does not yet let you keep your VAID-signing key in your own KMS, which is the thing most people will assume it means. And beyond both: custody as a service — keys we hold, rotate and attest on your behalf — does not exist. The kernel key is a published anchor, not an operated custody service.
Durable audit ledger
The ledger is hash-chained, schema-migrated and Postgres-backed, and its tamper-evidence is proven by attack rather than asserted: a direct SQL mutation of a written row is caught on recomputation, reported as AUDIT CHAIN BROKEN at seq N, and exits 4. It survives process exit. What does not exist is the hosted ledger — retention, operation and export run by us — and that is the commercial part.
Durable revocation
The revocation seam is three-state and lineage-aware: revoking a parent revokes its children, an unassemblable lineage is detected rather than silently passed, and a store that cannot answer fails closed instead of vouching. It is a trait, so a host supplies a durable backend and is not blocked. Two limits. First, what ships from us is an in-memory reference store that does not survive a restart — a boundary the spec states in R.6, and one it records as unchanged and not scheduled to change. Second, revocation is only consulted inside a deployment that holds the store: there is no published revocation list, and chain verification by a third party does not consult revocation or expiry at all. So a revoked VAID still verifies as authentic to anyone checking it from outside.
Hosted by us: No hosted versionWhat is real
So that the absence above is read correctly.
A page that only lists what is missing invites the conclusion that nothing works. That is not the case, and the distinction is between what runs and what is operated for you.
A governed agent, in production
Provisioned with a cryptographic identity of its own, carrying a short-lived credential that renews itself. Policy evaluates each request through the governed path and the verdict is enforced — allowed and the agent proceeds, denied and it stops. You can drive one from this site without an account.
Third-party verification against a published anchor
A party holding no credential, given only the published key and a document, can establish that document's authenticity offline. That is the property most enterprise architectures cannot get from a platform vendor, and it is the one that is finished.
Enforcement across an estate
The federation router is in-process today and reports its own readiness as Degraded. Cross-process enforcement across a whole estate is not shipped, so "one policy engine for everything you run" describes the design and not the deployment.
What a tenant can read back
Governance decisions about your agents, yes. The identity lifecycle of those same agents — mints, revocations, capability grants — no: those records carry no verified tenant, so they belong to nobody and are returned to nobody. Worth knowing before it appears in a control narrative.
The ending, and it is the offer
Nothing is built. Which is exactly what makes this conversation worth having.
Every enterprise requirement that usually arrives too late — data residency, key custody, air-gap, retention period, who holds the signing key, which jurisdiction the ledger sits in — arrives on this route before the thing it constrains has been designed. Those three components in section 01 have not been built. The constraints you name now are inputs; the same constraints named in eighteen months are migrations.
Tell us the constraint, not the requirement. "We need it in-region" is a requirement and we cannot meet it today. "Our regulator requires the signing key never leaves our jurisdiction" is a constraint, and it changes the key custody design, which is unwritten.
You get an honest map back. What exists, what is a name for something unbuilt, and what we have no plan for — at the level of detail on this page, applied to your case. That includes being told your requirement is out of reach, which is the outcome for air-gapped operation today.
No date will be invented for you. There is no roadmap commitment behind this conversation and no timeline will be offered. If a date is what you need before you can proceed, this route ends here honestly rather than three calls in.
Name the constraint.
Residency, air-gap, key custody, retention, jurisdiction. We will tell you what is possible today and what is not, and we will not tell you when.
Wrong door?
I build with agents and I want the identity primitive.
Builders about 90 seconds 02I am responsible for securing agents my organisation runs.
Security leaders about 6 minutes 03My business is adopting AI and I need to know what could go wrong.
Business owners about 4 minutes 04None of those, or not sure yet.
Everyone else about 2 minutes