Kill the key. Long live the proof.
For fifty years the internet has guarded secrets (passwords, tokens, certificates) and watched them get stolen. ENI6MA ends the reign of the stored secret: every message from every person, app, and AI proves itself with knowledge, once, and the proof dies with the moment. Nothing to steal. Nothing to replay. Nothing to breach.
This isn't a stronger lock. It's a new order of trust.
Applied Scenarios
Browse all scenariosIllustrative scenarios. The organizations named and the logos shown are publicly documented reference organizations, not ENI6MA customers. No commercial relationship, deployment, or endorsement is claimed or implied.
Ambient credentials are the breach
Every API key, bearer token, and service certificate in your estate is a secret that works from anywhere until you notice it's gone. ENI6MA makes authority expire at the end of each request.
Every API key, bearer token, and service certificate is a secret that works from anywhere until you notice it is gone.Ambient credentials authorize by possession alone; ENI6MA replaces that model with one-shot, request-bound proofs.
An API key, bearer token, or service certificate works from any network path that can present it. Theft equals capability.
Revoking ambient credentials means chasing every workload that embedded them. Miss one and the breach continues.
MCP tools, autonomous agents, and machine-to-machine callers mint long-lived secrets faster than humans ever did.
How a Gate decides
Eight fixed checks run on every untrusted request before application logic executes. Stage 5 (burn-before-validate) is why replay dies.
Recompute the request hash
The gate hashes the body it actually received and compares it to the envelope.
Rejects: A body that was altered after the proof was made.
Check endpoint and policy
The envelope names the endpoint and the policy it was made for; both must match this route.
Rejects: A valid proof relayed to a different endpoint.
Confirm the circuit is active
The handle is resolved against the registry and must be active. Deactivating a handle is how revocation happens.
Rejects: A proof from a revoked identity.
Check freshness
The envelope timestamp must fall inside the freshness window configured for the route.
Rejects: A captured envelope replayed after the window closed.
Burn the nonce
The nonce is spent here, before the proof is validated. Every submission spends it, including one that is about to fail validation.
Rejects: Any second use of the same envelope. This is where replay dies.
Validate the proof
Only now is the proof itself checked, against the local binary or the registry. Both modes are equivalent at the envelope layer.
Rejects: A forged or malformed proof.
Apply application policy
Ordinary authorization runs in the post-proof zone: arguments, limits, and business rules.
Rejects: A well-proved request asking for something it is not allowed to ask for.
Serve the request
The application does its work, and the response is bound back to the request that earned it.
Burn-before-validate is the structural reason a second submission of the same envelope always fails.ShippingGate stage 5 spends the nonce in the durable ledger before stage 6 validates the proof.Holds under the reference architecture
Replay is impossible by design.ShippingThe nonce is burned before validation in a durable ledger; it is spent even when validation later fails.Holds under the reference architecture
Absolute claims hold under the reference architecture requirements.
Four products. One authorization plane.
Foundry mints identity into circuits. Control registers, ledgers, and observes. Gate enforces. Verify attacks your deployment the way an adversary would.
Full catalog and form factors on Products.
Product capabilities
Cloud. Agent. Human.
One family of one-shot proofs, Gate on estates and MCP tools, Pass+ ceremony for people, the same burn-before-validate contract underneath.
Cloud
Protect the estate without rewriting it
Put Gate in front of the routes that matter. PKI and mTLS stay for transport identity; ENI6MA replaces the reusable API keys and bearer tokens that authorize requests.
Explore →Agent
Per-call authority for tools that change the world
MCP and agent runtimes decide which tool to call. ENI6MA decides whether that call may produce a side effect, without ambient API keys sitting in the agent host.
Explore →Human
Prove knowledge without broadcasting a secret
Pass+ turns human memory into a dynamic interactive proof. The Private Synonym Map decouples what appears on screen from what the user communicates, so observers, cameras, and keyloggers see ambiguous tokens, not a reusable password.
Explore →Start where credentials fail first
Three buyer tracks. Agent and MCP security leads, that is where ambient tokens are proliferating fastest.
Secure your AI agents and MCP servers
Wrap tools so each invocation carries a one-shot envelope. A stolen agent secret is not a stolen capability.
Explore →Secure your APIs and endpoints
Put Gate in front of high-risk routes. Method, body, and policy bind into every proof.
Explore →Replace or augment PKI authorization
Replaces the part of PKI that keeps breaching you (the credentials that authorize requests). Certificates stay for transport identity; ENI6MA owns request authority.
Explore →What changes when authority is one-shot
Mechanism claims, stated plainly. Each absolute claim assumes the reference architecture.
Envelope authorizes one request, then the nonce is spent
Authority expires at the end of each request.The envelope binds method, endpoint_id, request hash, policy hash, tau, and nonce (one message, one use).Holds under the reference architecture
endpoint_id and request-hash binding reject relays
Immune to phishing.No reusable credential exists to harvest; endpoint_id binding means a relayed proof fails on any other route.Holds under the reference architecture
Identity lives in compiled circuits, not a secret store
Immune to credential-vault breach.No vault of reusable secrets exists; identity is compiled into the circuit binary, not stored as a transferable credential.Holds under the reference architecture
One registry state change deactivates the circuit handle
Revocation is one state change.Deactivating a circuit handle in the registry revokes the identity; there is no rotation campaign across every workload.Holds under the reference architecture
Full mechanism detail on Security architecture. Guarantees assume the reference architecture.
Applied scenarios
Illustrative architectures against publicly documented reference organizations, not customer engagements.
Global technology
Role-based access without ambient MFA tokens
Reference organization: Microsoft
Illustrative ScenarioBanking
Request-bound authorization for financial APIs
Reference organization: JPMorgan Chase
Illustrative ScenarioAerospace and defense
Mandatory access control for regulated workloads
Reference organization: Boeing
Illustrative ScenarioIllustrative scenarios. The organizations named and the logos shown are publicly documented reference organizations, not ENI6MA customers. No commercial relationship, deployment, or endorsement is claimed or implied.
Live capture
Security guided tour
Twenty-nine screens from a live DEMO-HACK red-team run, burn-before-validate, envelope binding, and every reject stage, with hotspot callouts and payload excerpts.
See a proof happen
Walk the DEMO-HACK cloud host→client→server tour, then the Gate happy path and reject stages, or try the Pass+ ceremony teaching UI.
Security guided tour
Primary path: twenty-nine live DEMO-HACK screens with hotspots and payload evidence.
Open →Gate walkthrough
Happy path and every reject stage on a live Gate.
Open →Verify walkthrough
Watch the attack suite exercise burn-before-validate.
Open →Pass+ ceremony
Teaching UI: six zones, bearing-only responses, one verdict after six witnesses.
Open →Research and IP
Observer-bit framing, formal bounds, and provisional patent filings. Precision over slogans.
Protect an endpoint
Start with Gate on a single high-risk route, or request a Foundry evaluation for cohort manufacturing.
Need executive delivery alongside the product? Fractional CAISO lives under Services. Services
Evaluate Gate against a real route, or talk to us about Foundry-licensed manufacturing and Control at your perimeter.