diff --git a/data/research.json b/data/research.json
index 2fb0f72..013f96b 100644
--- a/data/research.json
+++ b/data/research.json
@@ -108,6 +108,7 @@
"spec": "https://wcm.agentrust-io.com/",
"code": "https://github.com/agentrust-io/weight-custody-manifest",
"patent_pending": true,
+ "doi": "10.5281/zenodo.23020644",
"date": "2026-09-27",
"abstract": "Deploying proprietary model weights into infrastructure controlled by a customer reverses the usual confidential-computing trust problem: the model builder, rather than the infrastructure owner, supplies the secret. Existing confidential-computing stacks can attest workloads and release secrets, while model-signing systems authenticate model artifacts. Neither capability alone specifies continuing custody of a particular weight artifact after release. This technical report describes the Weight Custody Manifest (WCM), a vendor-neutral protocol and conformance model that binds an exact weight digest, an approved workload measurement, attestation policy, a fresh transport key, renewable authorization, terminal refusal and wipe evidence, and derivative lineage. WCM distinguishes cryptographic custody against software adversaries from accountability-grade controls when the infrastructure operator physically owns the machine. The evaluated Python reference implementation, version 0.28.0, supplies 91 portable conformance vectors across four levels. Its test suite produced 618 passing tests and three skips on September 3, 2026, and the same counts when rerun at the same commit for this edition. Two later findings bound those results: a published advisory showed that the evaluated key broker did not require GPU confidential-compute mode before release, and the SEV-SNP platform used for the hardware run does not enable the ciphertext hiding that the cryptographic-custody claim against a hypervisor-privileged operator requires. The contribution is a portable artifact-to-runtime custody contract with explicit lifecycle evidence, derivative accountability, and conformance, not a new attestation primitive or a certification of any deployment.",
"pages": 6,
@@ -115,6 +116,89 @@
"paper.pdf": "a0338db4e4f8a35f134f5b8313a167f81b829a047c9439d8b3c2b34e3c5e0c59",
"source.zip": "ce91e7c14ef7abde96b922129eb4467a5e47720933acee707c5c3cd7c080ddeb"
}
+ },
+ {
+ "slug": "ca2a",
+ "short_title": "cA2A",
+ "title": "cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A",
+ "authors": [
+ "Rishabh Poddar",
+ "Aaron Fulkerson",
+ "Imran Siddique"
+ ],
+ "topic": "Delegation evidence",
+ "description": "cA2A technical report: attenuated, attested delegation between AI agents on A2A, rerun experiments, later findings and hardware limits.",
+ "contribution": "A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.",
+ "limits": [
+ "Software experiments were rerun on September 27, 2026 against ca2a 0.3.1: correctness counts matched the July 2026 draft, and chain verification cost about 216 rather than 195 microseconds per hop.",
+ "Cross-operator attestation was exercised only with synthetic evidence. Recorded hardware runs cover one-directional appraisal across clouds and a same-operator diagnostic, not mutual attestation between independent operators.",
+ "The results do not show that a peer's key is confined to attested code. Provenance checks on unsigned records establish structural consistency only; authenticity rests on signed records."
+ ],
+ "changes": "Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.",
+ "spec": "https://ca2a.agentrust-io.com/",
+ "code": "https://github.com/agentrust-io/ca2a",
+ "patent_pending": true,
+ "date": "2026-09-27",
+ "abstract": "The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.",
+ "pages": 21,
+ "sha256": {
+ "paper.pdf": "2e9fc6b2c9acebd252594985eaecf783b1e8714b57d39449fa914efc2e2846fb",
+ "source.zip": "9289ce4ea510d3c36fac3f91580ab1ae6aba2e570682507f2fd636c96dc01dbc"
+ }
+ },
+ {
+ "slug": "agentrust-telemetry",
+ "short_title": "AgenTrust Telemetry",
+ "title": "From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract",
+ "authors": [
+ "Imran Siddique"
+ ],
+ "topic": "Governance telemetry",
+ "description": "AgenTrust Telemetry technical report: a privacy-constrained contract separating agent observability from governance evidence, with rerun results.",
+ "contribution": "A backend-neutral contract for six governance event families that keeps lossy operational telemetry separate from evidence whose completeness is stated.",
+ "limits": [
+ "The evaluated release is 0.1.0-alpha.2. On September 27, 2026 its 111 Python tests passed and all 13 fixtures gave their expected verdicts again, with agentrust-trace pinned to 0.9.0. The TypeScript suite was not rerun.",
+ "Completeness is a producer assertion that the accumulator records but does not measure.",
+ "A defect found after the evaluation let an edited evidence snapshot be signed at the evaluated release; it was fixed later and is reported beside the results."
+ ],
+ "changes": "Aligns claims with the evaluated code, positions the contract against prior governance telemetry work, and adds a post-evaluation findings section.",
+ "spec": "https://agentrust-io.com/telemetry/",
+ "code": "https://github.com/agentrust-io/agentrust-telemetry",
+ "patent_pending": false,
+ "date": "2026-09-27",
+ "abstract": "Agent observability conventions describe model, tool, and agent operations, but governance facts are commonly fragmented across policy engines, approval stores, cost modules, and audit systems. Copying those facts into ordinary traces creates two hazards: sensitive payload capture and the false inference that sampled operational telemetry is complete audit evidence. This technical report describes AgenTrust Telemetry, a backend-neutral contract for six governance event families: policy decisions, approval lifecycles, usage, classified data flows, action execution, and evidence lifecycle. The contract correlates with W3C Trace Context and OpenTelemetry without installing a provider, exporter, or competing tracing model. A metadata-only profile rejects prompts, outputs, source code, tool arguments and results, credentials, and authorization tokens by key. Durable run and action identifiers survive process and asynchronous handoffs; propagated metadata remains untrusted and does not confer identity or authority. An optional accumulator accepts events before lossy export and can be finalized into a separately verifiable TRACE record. Its completeness status is a producer assertion that the accumulator records but does not measure. The evaluated release, 0.1.0-alpha.2, ships Python and TypeScript reference SDKs over shared schemas and a portable conformance set of six valid and seven invalid fixtures. At that commit 111 Python unit tests pass and all 13 fixtures produce their expected verdicts, on September 3, 2026 and again when rerun for this edition. A defect found after the evaluation let an edited evidence snapshot be signed; it is reported beside the results it qualifies. The contribution is not another agent tracing convention; it is a narrow semantic boundary between operational observation and governance evidence whose completeness must be stated rather than inferred.",
+ "pages": 6,
+ "sha256": {
+ "paper.pdf": "502c3d61e335d47c642ff8d6b7c1cf9ec9c25f5c99213f2eefea0b01b5d7359b",
+ "source.zip": "34517b8856bae49bf757beb3ba4c43b4b7db9f0df25e9b5dd2e40b6d2f30afaa"
+ }
+ },
+ {
+ "slug": "confidential-handoffs",
+ "short_title": "Confidential Handoffs",
+ "title": "Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation",
+ "authors": [
+ "Imran Siddique"
+ ],
+ "topic": "Confidential handoffs",
+ "description": "Confidential handoffs technical report: conditions for keeping inference confidentiality through agent tool calls and delegation, software evidence.",
+ "contribution": "A conditional composition argument and proposed handoff contract for when tool calls and delegations preserve an authorized plaintext-holder boundary.",
+ "limits": [
+ "All results are software results: attestation in the composed experiment is synthetic and one operator runs every party.",
+ "The composed experiment was rerun on September 27, 2026 at WCM main 94d5519: 36 of 36 hosted and 32 portable cases locally, matching every recorded observation.",
+ "Hardware acceptance and independently operated peers are future work. Raw hardware diagnostic captures are not published."
+ ],
+ "changes": "Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.",
+ "spec": "https://wcm.agentrust-io.com/",
+ "code": "https://github.com/agentrust-io/weight-custody-manifest/tree/main/python/composed",
+ "patent_pending": true,
+ "date": "2026-09-27",
+ "abstract": "This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.",
+ "pages": 13,
+ "sha256": {
+ "paper.pdf": "21a1abd5e6fbc822105437c2a639c59368880a3ff79c2dc32b4cfac652602728",
+ "source.zip": "b0f2ea632176aff353d78813fe74293bd80e12bed53448d3e1395b1dc699b641"
+ }
}
]
}
diff --git a/research/agentrust-telemetry/index.html b/research/agentrust-telemetry/index.html
new file mode 100644
index 0000000..e7f1ee2
--- /dev/null
+++ b/research/agentrust-telemetry/index.html
@@ -0,0 +1,92 @@
+
+
From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract
+
Imran Siddique
OPAQUE Systems
+
September 27, 2026Not peer reviewed
+
+
Abstract
Agent observability conventions describe model, tool, and agent operations, but governance facts are commonly fragmented across policy engines, approval stores, cost modules, and audit systems. Copying those facts into ordinary traces creates two hazards: sensitive payload capture and the false inference that sampled operational telemetry is complete audit evidence. This technical report describes AgenTrust Telemetry, a backend-neutral contract for six governance event families: policy decisions, approval lifecycles, usage, classified data flows, action execution, and evidence lifecycle. The contract correlates with W3C Trace Context and OpenTelemetry without installing a provider, exporter, or competing tracing model. A metadata-only profile rejects prompts, outputs, source code, tool arguments and results, credentials, and authorization tokens by key. Durable run and action identifiers survive process and asynchronous handoffs; propagated metadata remains untrusted and does not confer identity or authority. An optional accumulator accepts events before lossy export and can be finalized into a separately verifiable TRACE record. Its completeness status is a producer assertion that the accumulator records but does not measure. The evaluated release, 0.1.0-alpha.2, ships Python and TypeScript reference SDKs over shared schemas and a portable conformance set of six valid and seven invalid fixtures. At that commit 111 Python unit tests pass and all 13 fixtures produce their expected verdicts, on September 3, 2026 and again when rerun for this edition. A defect found after the evaluation let an edited evidence snapshot be signed; it is reported beside the results it qualifies. The contribution is not another agent tracing convention; it is a narrow semantic boundary between operational observation and governance evidence whose completeness must be stated rather than inferred.
+
+
What this report contributes
A backend-neutral contract for six governance event families that keeps lossy operational telemetry separate from evidence whose completeness is stated.
+
Evidence and limits
The evaluated release is 0.1.0-alpha.2. On September 27, 2026 its 111 Python tests passed and all 13 fixtures gave their expected verdicts again, with agentrust-trace pinned to 0.9.0. The TypeScript suite was not rerun.
Completeness is a producer assertion that the accumulator records but does not measure.
A defect found after the evaluation let an edited evidence snapshot be signed at the evaluated release; it was fixed later and is reported beside the results.
+
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
Imran Siddique. From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract. AgenTrust technical report, version 1, 2026.
@techreport{agentrust2026agentrusttelemetry,
+ title = {From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract},
+ author = {Imran Siddique},
+ institution = {AgenTrust},
+ year = {2026},
+ type = {Technical report},
+ note = {Version 1; not peer reviewed},
+ url = {https://agentrust-io.com/research/agentrust-telemetry/v1/}
+}
+
+
Version history
Version 1, September 27, 2026: Aligns claims with the evaluated code, positions the contract against prior governance telemetry work, and adds a post-evaluation findings section.
+
Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.
+
File checksums. Published version files are retained; substantive revisions receive a new version.
+
Questions and corrections
Open an issue in the project repository and identify the report version and section.
From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract
+
Imran Siddique
OPAQUE Systems
+
September 27, 2026Not peer reviewed
+
+
Abstract
Agent observability conventions describe model, tool, and agent operations, but governance facts are commonly fragmented across policy engines, approval stores, cost modules, and audit systems. Copying those facts into ordinary traces creates two hazards: sensitive payload capture and the false inference that sampled operational telemetry is complete audit evidence. This technical report describes AgenTrust Telemetry, a backend-neutral contract for six governance event families: policy decisions, approval lifecycles, usage, classified data flows, action execution, and evidence lifecycle. The contract correlates with W3C Trace Context and OpenTelemetry without installing a provider, exporter, or competing tracing model. A metadata-only profile rejects prompts, outputs, source code, tool arguments and results, credentials, and authorization tokens by key. Durable run and action identifiers survive process and asynchronous handoffs; propagated metadata remains untrusted and does not confer identity or authority. An optional accumulator accepts events before lossy export and can be finalized into a separately verifiable TRACE record. Its completeness status is a producer assertion that the accumulator records but does not measure. The evaluated release, 0.1.0-alpha.2, ships Python and TypeScript reference SDKs over shared schemas and a portable conformance set of six valid and seven invalid fixtures. At that commit 111 Python unit tests pass and all 13 fixtures produce their expected verdicts, on September 3, 2026 and again when rerun for this edition. A defect found after the evaluation let an edited evidence snapshot be signed; it is reported beside the results it qualifies. The contribution is not another agent tracing convention; it is a narrow semantic boundary between operational observation and governance evidence whose completeness must be stated rather than inferred.
+
+
What this report contributes
A backend-neutral contract for six governance event families that keeps lossy operational telemetry separate from evidence whose completeness is stated.
+
Evidence and limits
The evaluated release is 0.1.0-alpha.2. On September 27, 2026 its 111 Python tests passed and all 13 fixtures gave their expected verdicts again, with agentrust-trace pinned to 0.9.0. The TypeScript suite was not rerun.
Completeness is a producer assertion that the accumulator records but does not measure.
A defect found after the evaluation let an edited evidence snapshot be signed at the evaluated release; it was fixed later and is reported beside the results.
+
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
Imran Siddique. From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract. AgenTrust technical report, version 1, 2026.
@techreport{agentrust2026agentrusttelemetry,
+ title = {From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract},
+ author = {Imran Siddique},
+ institution = {AgenTrust},
+ year = {2026},
+ type = {Technical report},
+ note = {Version 1; not peer reviewed},
+ url = {https://agentrust-io.com/research/agentrust-telemetry/v1/}
+}
+
+
Version history
Version 1, September 27, 2026: Aligns claims with the evaluated code, positions the contract against prior governance telemetry work, and adds a post-evaluation findings section.
+
Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.
+
File checksums. Published version files are retained; substantive revisions receive a new version.
+
Questions and corrections
Open an issue in the project repository and identify the report version and section.
+
+
+
diff --git a/research/agentrust-telemetry/v1/paper.pdf b/research/agentrust-telemetry/v1/paper.pdf
new file mode 100644
index 0000000..741b960
Binary files /dev/null and b/research/agentrust-telemetry/v1/paper.pdf differ
diff --git a/research/agentrust-telemetry/v1/source.zip b/research/agentrust-telemetry/v1/source.zip
new file mode 100644
index 0000000..ac45dd7
Binary files /dev/null and b/research/agentrust-telemetry/v1/source.zip differ
diff --git a/research/ca2a/index.html b/research/ca2a/index.html
new file mode 100644
index 0000000..b131312
--- /dev/null
+++ b/research/ca2a/index.html
@@ -0,0 +1,94 @@
+
+
+
+cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A | AgenTrust
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+Skip to content
+
+
cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A
+
Rishabh Poddar, Aaron Fulkerson, Imran Siddique
OPAQUE Systems
+
September 27, 2026Not peer reviewedPatent Pending
+
+
Abstract
The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.
+
+
What this report contributes
A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.
+
Evidence and limits
Software experiments were rerun on September 27, 2026 against ca2a 0.3.1: correctness counts matched the July 2026 draft, and chain verification cost about 216 rather than 195 microseconds per hop.
Cross-operator attestation was exercised only with synthetic evidence. Recorded hardware runs cover one-directional appraisal across clouds and a same-operator diagnostic, not mutual attestation between independent operators.
The results do not show that a peer's key is confined to attested code. Provenance checks on unsigned records establish structural consistency only; authenticity rests on signed records.
+
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
@techreport{agentrust2026ca2a,
+ title = {cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A},
+ author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
+ institution = {AgenTrust},
+ year = {2026},
+ type = {Technical report},
+ note = {Version 1; not peer reviewed},
+ url = {https://agentrust-io.com/research/ca2a/v1/}
+}
+
+
Version history
Version 1, September 27, 2026: Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.
+
Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.
+
File checksums. Published version files are retained; substantive revisions receive a new version.
+
Questions and corrections
Open an issue in the project repository and identify the report version and section.
+
+
+
diff --git a/research/ca2a/v1/CITATION.cff b/research/ca2a/v1/CITATION.cff
new file mode 100644
index 0000000..45acbfa
--- /dev/null
+++ b/research/ca2a/v1/CITATION.cff
@@ -0,0 +1,44 @@
+{
+ "cff-version": "1.2.0",
+ "message": "Cite the versioned technical report. It has not been peer reviewed.",
+ "type": "dataset",
+ "title": "cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A",
+ "version": "1",
+ "date-released": "2026-09-27",
+ "authors": [
+ {
+ "given-names": "Rishabh",
+ "family-names": "Poddar"
+ },
+ {
+ "given-names": "Aaron",
+ "family-names": "Fulkerson"
+ },
+ {
+ "given-names": "Imran",
+ "family-names": "Siddique"
+ }
+ ],
+ "url": "https://agentrust-io.com/research/ca2a/v1/",
+ "license": "CC-BY-4.0",
+ "preferred-citation": {
+ "type": "report",
+ "title": "cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A",
+ "authors": [
+ {
+ "given-names": "Rishabh",
+ "family-names": "Poddar"
+ },
+ {
+ "given-names": "Aaron",
+ "family-names": "Fulkerson"
+ },
+ {
+ "given-names": "Imran",
+ "family-names": "Siddique"
+ }
+ ],
+ "year": 2026,
+ "url": "https://agentrust-io.com/research/ca2a/v1/"
+ }
+}
diff --git a/research/ca2a/v1/SHA256SUMS b/research/ca2a/v1/SHA256SUMS
new file mode 100644
index 0000000..1704c40
--- /dev/null
+++ b/research/ca2a/v1/SHA256SUMS
@@ -0,0 +1,2 @@
+2e9fc6b2c9acebd252594985eaecf783b1e8714b57d39449fa914efc2e2846fb paper.pdf
+9289ce4ea510d3c36fac3f91580ab1ae6aba2e570682507f2fd636c96dc01dbc source.zip
diff --git a/research/ca2a/v1/citation.bib b/research/ca2a/v1/citation.bib
new file mode 100644
index 0000000..cdfdd7c
--- /dev/null
+++ b/research/ca2a/v1/citation.bib
@@ -0,0 +1,9 @@
+@techreport{agentrust2026ca2a,
+ title = {cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A},
+ author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
+ institution = {AgenTrust},
+ year = {2026},
+ type = {Technical report},
+ note = {Version 1; not peer reviewed},
+ url = {https://agentrust-io.com/research/ca2a/v1/}
+}
diff --git a/research/ca2a/v1/index.html b/research/ca2a/v1/index.html
new file mode 100644
index 0000000..b1e06eb
--- /dev/null
+++ b/research/ca2a/v1/index.html
@@ -0,0 +1,94 @@
+
+
+
+cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A (version 1) | AgenTrust
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+Skip to content
+
+
cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A
+
Rishabh Poddar, Aaron Fulkerson, Imran Siddique
OPAQUE Systems
+
September 27, 2026Not peer reviewedPatent Pending
+
+
Abstract
The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.
+
+
What this report contributes
A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.
+
Evidence and limits
Software experiments were rerun on September 27, 2026 against ca2a 0.3.1: correctness counts matched the July 2026 draft, and chain verification cost about 216 rather than 195 microseconds per hop.
Cross-operator attestation was exercised only with synthetic evidence. Recorded hardware runs cover one-directional appraisal across clouds and a same-operator diagnostic, not mutual attestation between independent operators.
The results do not show that a peer's key is confined to attested code. Provenance checks on unsigned records establish structural consistency only; authenticity rests on signed records.
+
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
@techreport{agentrust2026ca2a,
+ title = {cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A},
+ author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
+ institution = {AgenTrust},
+ year = {2026},
+ type = {Technical report},
+ note = {Version 1; not peer reviewed},
+ url = {https://agentrust-io.com/research/ca2a/v1/}
+}
+
+
Version history
Version 1, September 27, 2026: Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.
+
Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.
+
File checksums. Published version files are retained; substantive revisions receive a new version.
+
Questions and corrections
Open an issue in the project repository and identify the report version and section.
+
+
+
diff --git a/research/ca2a/v1/paper.pdf b/research/ca2a/v1/paper.pdf
new file mode 100644
index 0000000..c985f2d
Binary files /dev/null and b/research/ca2a/v1/paper.pdf differ
diff --git a/research/ca2a/v1/source.zip b/research/ca2a/v1/source.zip
new file mode 100644
index 0000000..cb72c6f
Binary files /dev/null and b/research/ca2a/v1/source.zip differ
diff --git a/research/confidential-handoffs/index.html b/research/confidential-handoffs/index.html
new file mode 100644
index 0000000..2150412
--- /dev/null
+++ b/research/confidential-handoffs/index.html
@@ -0,0 +1,92 @@
+
+
+
+Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation | AgenTrust
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+Skip to content
+
+
Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation
+
Imran Siddique
OPAQUE Systems
+
September 27, 2026Not peer reviewedPatent Pending
+
+
Abstract
This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.
+
+
What this report contributes
A conditional composition argument and proposed handoff contract for when tool calls and delegations preserve an authorized plaintext-holder boundary.
+
Evidence and limits
All results are software results: attestation in the composed experiment is synthetic and one operator runs every party.
The composed experiment was rerun on September 27, 2026 at WCM main 94d5519: 36 of 36 hosted and 32 portable cases locally, matching every recorded observation.
Hardware acceptance and independently operated peers are future work. Raw hardware diagnostic captures are not published.
+
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
Imran Siddique. Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation. AgenTrust technical report, version 1, 2026.
@techreport{agentrust2026confidentialhandoffs,
+ title = {Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation},
+ author = {Imran Siddique},
+ institution = {AgenTrust},
+ year = {2026},
+ type = {Technical report},
+ note = {Version 1; not peer reviewed},
+ url = {https://agentrust-io.com/research/confidential-handoffs/v1/}
+}
+
+
Version history
Version 1, September 27, 2026: Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.
+
Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.
+
File checksums. Published version files are retained; substantive revisions receive a new version.
+
Questions and corrections
Open an issue in the project repository and identify the report version and section.
+
+
+
diff --git a/research/confidential-handoffs/v1/CITATION.cff b/research/confidential-handoffs/v1/CITATION.cff
new file mode 100644
index 0000000..e1207c3
--- /dev/null
+++ b/research/confidential-handoffs/v1/CITATION.cff
@@ -0,0 +1,28 @@
+{
+ "cff-version": "1.2.0",
+ "message": "Cite the versioned technical report. It has not been peer reviewed.",
+ "type": "dataset",
+ "title": "Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation",
+ "version": "1",
+ "date-released": "2026-09-27",
+ "authors": [
+ {
+ "given-names": "Imran",
+ "family-names": "Siddique"
+ }
+ ],
+ "url": "https://agentrust-io.com/research/confidential-handoffs/v1/",
+ "license": "CC-BY-4.0",
+ "preferred-citation": {
+ "type": "report",
+ "title": "Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation",
+ "authors": [
+ {
+ "given-names": "Imran",
+ "family-names": "Siddique"
+ }
+ ],
+ "year": 2026,
+ "url": "https://agentrust-io.com/research/confidential-handoffs/v1/"
+ }
+}
diff --git a/research/confidential-handoffs/v1/SHA256SUMS b/research/confidential-handoffs/v1/SHA256SUMS
new file mode 100644
index 0000000..1515f52
--- /dev/null
+++ b/research/confidential-handoffs/v1/SHA256SUMS
@@ -0,0 +1,2 @@
+21a1abd5e6fbc822105437c2a639c59368880a3ff79c2dc32b4cfac652602728 paper.pdf
+b0f2ea632176aff353d78813fe74293bd80e12bed53448d3e1395b1dc699b641 source.zip
diff --git a/research/confidential-handoffs/v1/citation.bib b/research/confidential-handoffs/v1/citation.bib
new file mode 100644
index 0000000..6c08001
--- /dev/null
+++ b/research/confidential-handoffs/v1/citation.bib
@@ -0,0 +1,9 @@
+@techreport{agentrust2026confidentialhandoffs,
+ title = {Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation},
+ author = {Imran Siddique},
+ institution = {AgenTrust},
+ year = {2026},
+ type = {Technical report},
+ note = {Version 1; not peer reviewed},
+ url = {https://agentrust-io.com/research/confidential-handoffs/v1/}
+}
diff --git a/research/confidential-handoffs/v1/index.html b/research/confidential-handoffs/v1/index.html
new file mode 100644
index 0000000..896d2cd
--- /dev/null
+++ b/research/confidential-handoffs/v1/index.html
@@ -0,0 +1,92 @@
+
+
+
+Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation (version 1) | AgenTrust
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+Skip to content
+
+
Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation
+
Imran Siddique
OPAQUE Systems
+
September 27, 2026Not peer reviewedPatent Pending
+
+
Abstract
This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.
+
+
What this report contributes
A conditional composition argument and proposed handoff contract for when tool calls and delegations preserve an authorized plaintext-holder boundary.
+
Evidence and limits
All results are software results: attestation in the composed experiment is synthetic and one operator runs every party.
The composed experiment was rerun on September 27, 2026 at WCM main 94d5519: 36 of 36 hosted and 32 portable cases locally, matching every recorded observation.
Hardware acceptance and independently operated peers are future work. Raw hardware diagnostic captures are not published.
+
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
Imran Siddique. Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation. AgenTrust technical report, version 1, 2026.
@techreport{agentrust2026confidentialhandoffs,
+ title = {Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation},
+ author = {Imran Siddique},
+ institution = {AgenTrust},
+ year = {2026},
+ type = {Technical report},
+ note = {Version 1; not peer reviewed},
+ url = {https://agentrust-io.com/research/confidential-handoffs/v1/}
+}
+
+
Version history
Version 1, September 27, 2026: Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.
+
Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.
+
File checksums. Published version files are retained; substantive revisions receive a new version.
+
Questions and corrections
Open an issue in the project repository and identify the report version and section.
+
+
+
diff --git a/research/confidential-handoffs/v1/paper.pdf b/research/confidential-handoffs/v1/paper.pdf
new file mode 100644
index 0000000..c99066b
Binary files /dev/null and b/research/confidential-handoffs/v1/paper.pdf differ
diff --git a/research/confidential-handoffs/v1/source.zip b/research/confidential-handoffs/v1/source.zip
new file mode 100644
index 0000000..84c189a
Binary files /dev/null and b/research/confidential-handoffs/v1/source.zip differ
diff --git a/research/index.html b/research/index.html
index 04c77cc..6de3a5c 100644
--- a/research/index.html
+++ b/research/index.html
@@ -2,23 +2,23 @@
Research: AI Agent Identity, Enforcement and Evidence | AgenTrust
-
+
-
+
-
+
-
+
@@ -58,7 +58,7 @@
AgenTrust Research
Identity, enforcement, and evidence for AI agents.
Technical reports with open source, recorded experiments, and explicit limits. Read the work, inspect the evidence, and cite a specific version.
A backend-neutral contract for six governance event families that keeps lossy operational telemetry separate from evidence whose completeness is stated.
These reports preserve historical designs and software evaluations. A signature, an attestation result, and an execution-completeness claim establish different properties. Each paper page identifies the evidence evaluated and the limits that remain.
For implementation, follow the current project specifications linked from each report. Paper text is available under CC BY 4.0; code retains its project license.
Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary
September 27, 2026Not peer reviewedPatent Pending
Abstract
Deploying proprietary model weights into infrastructure controlled by a customer reverses the usual confidential-computing trust problem: the model builder, rather than the infrastructure owner, supplies the secret. Existing confidential-computing stacks can attest workloads and release secrets, while model-signing systems authenticate model artifacts. Neither capability alone specifies continuing custody of a particular weight artifact after release. This technical report describes the Weight Custody Manifest (WCM), a vendor-neutral protocol and conformance model that binds an exact weight digest, an approved workload measurement, attestation policy, a fresh transport key, renewable authorization, terminal refusal and wipe evidence, and derivative lineage. WCM distinguishes cryptographic custody against software adversaries from accountability-grade controls when the infrastructure operator physically owns the machine. The evaluated Python reference implementation, version 0.28.0, supplies 91 portable conformance vectors across four levels. Its test suite produced 618 passing tests and three skips on September 3, 2026, and the same counts when rerun at the same commit for this edition. Two later findings bound those results: a published advisory showed that the evaluated key broker did not require GPU confidential-compute mode before release, and the SEV-SNP platform used for the hardware run does not enable the ciphertext hiding that the cryptographic-custody claim against a hypervisor-privileged operator requires. The contribution is a portable artifact-to-runtime custody contract with explicit lifecycle evidence, derivative accountability, and conformance, not a new attestation primitive or a certification of any deployment.
-
+
What this report contributes
A portable custody contract binding exact weights, measured workload, fresh channel-bound release, renewable authority, terminal evidence and derivative lineage.
Evidence and limits
The evaluated version is WCM 0.28.0 (commit 2acedfa). Its software results were rerun on September 27, 2026 with the same counts: 618 passed, 3 skipped, 91 of 91 conformance vectors. The SEV-SNP hardware runs were not repeated.
Advisory GHSA-j665-99rh-w85h affects the evaluated version: the key broker did not require GPU confidential-compute mode before release. The fail-closed result does not cover GPU mode.
The measured Azure SEV-SNP platform does not enable ciphertext hiding, so the cryptographic-custody claim does not hold there against a hypervisor-privileged operator. Against an operator who physically owns the machine, WCM claims accountability, not custody.
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
@@ -80,6 +81,7 @@
Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
+ doi = {10.5281/zenodo.23020644},
url = {https://agentrust-io.com/research/weight-custody-manifest/v1/}
}
Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary
September 27, 2026Not peer reviewedPatent Pending
Abstract
Deploying proprietary model weights into infrastructure controlled by a customer reverses the usual confidential-computing trust problem: the model builder, rather than the infrastructure owner, supplies the secret. Existing confidential-computing stacks can attest workloads and release secrets, while model-signing systems authenticate model artifacts. Neither capability alone specifies continuing custody of a particular weight artifact after release. This technical report describes the Weight Custody Manifest (WCM), a vendor-neutral protocol and conformance model that binds an exact weight digest, an approved workload measurement, attestation policy, a fresh transport key, renewable authorization, terminal refusal and wipe evidence, and derivative lineage. WCM distinguishes cryptographic custody against software adversaries from accountability-grade controls when the infrastructure operator physically owns the machine. The evaluated Python reference implementation, version 0.28.0, supplies 91 portable conformance vectors across four levels. Its test suite produced 618 passing tests and three skips on September 3, 2026, and the same counts when rerun at the same commit for this edition. Two later findings bound those results: a published advisory showed that the evaluated key broker did not require GPU confidential-compute mode before release, and the SEV-SNP platform used for the hardware run does not enable the ciphertext hiding that the cryptographic-custody claim against a hypervisor-privileged operator requires. The contribution is a portable artifact-to-runtime custody contract with explicit lifecycle evidence, derivative accountability, and conformance, not a new attestation primitive or a certification of any deployment.
-
+
What this report contributes
A portable custody contract binding exact weights, measured workload, fresh channel-bound release, renewable authority, terminal evidence and derivative lineage.
Evidence and limits
The evaluated version is WCM 0.28.0 (commit 2acedfa). Its software results were rerun on September 27, 2026 with the same counts: 618 passed, 3 skipped, 91 of 91 conformance vectors. The SEV-SNP hardware runs were not repeated.
Advisory GHSA-j665-99rh-w85h affects the evaluated version: the key broker did not require GPU confidential-compute mode before release. The fail-closed result does not cover GPU mode.
The measured Azure SEV-SNP platform does not enable ciphertext hiding, so the cryptographic-custody claim does not hold there against a hypervisor-privileged operator. Against an operator who physically owns the machine, WCM claims accountability, not custody.
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
@@ -80,6 +81,7 @@
Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
+ doi = {10.5281/zenodo.23020644},
url = {https://agentrust-io.com/research/weight-custody-manifest/v1/}
}
Identity, enforcement, and evidence for AI agents.
Technical reports with open source, recorded experiments, and explicit limits. Read the work, inspect the evidence, and cite a specific version.
Research collection{len(papers)} reports / Not peer reviewed
{cards}
Read the evidence with the claim
These reports preserve historical designs and software evaluations. A signature, an attestation result, and an execution-completeness claim establish different properties. Each paper page identifies the evidence evaluated and the limits that remain.
For implementation, follow the current project specifications linked from each report. Paper text is available under CC BY 4.0; code retains its project license.
'''
- outputs[ROOT/'research/index.html']=shell('Research: AI Agent Identity, Enforcement and Evidence','Read AgenTrust technical reports on TRACE, cMCP, Agent Manifest and Weight Custody Manifest, with PDFs, source, evidence, limits and citations.','/research/',body)
+ outputs[ROOT/'research/index.html']=shell('Research: AI Agent Identity, Enforcement and Evidence','AgenTrust technical reports on agent identity, tool-call enforcement, runtime evidence, model custody, delegation and telemetry, with PDFs, source and limits.','/research/',body)
return outputs