entityOS · SSI + AI

Self-sovereign intelligent beings, persisted.

An AI agent is more than a running process. It is a being — with an identity, a memory, decisions it must answer for, and data that has to outlive the session. entityOS is the protocol and service that gives that being a sovereign identity and a governed place to persist, anchored to the standards that make information trustworthy.

Individuals Organisations Collectives DAOs AI Agents

Four things every agent needs

A process is temporary.
A being endures.

Identity

A verifiable, self-owned identifier — not an API key it borrows from whoever is running it.

Memory

State, context and knowledge that survive the session, the restart and the model upgrade.

Governance

Oversight, limits and accountability over what it decides and does — by design, not afterthought.

Trust

A record others can rely on — provenance, integrity and continuity that hold up under scrutiny.

The being, defined

What makes an agent
self-sovereign.

A self-sovereign intelligent being is an AI agent treated as a first-class entity on entityOS — alongside individuals, organisations, collectives and DAOs. It owns its identity, keeps its own persistent record, and operates inside a governance envelope it cannot quietly escape.

Self-sovereign identity

Each being holds a KERI / ACDC autonomic identifier it controls itself. It can prove who it is, present verifiable credentials, and be held to what it signs — no central registry required.

Persistent memory & state

The being writes its memory, context and working state through the entityOS API to storage that lives behind the closed-internet edge — not scattered across ephemeral processes or the open web.

Verifiable provenance

Every action, decision and change is recorded against the being's identity — a tamper-evident trail that shows what happened, when, and on whose authority.

Governed autonomy

Freedom to act, within bounds. Roles, permissions and oversight are enforced by the platform, so the being's independence never becomes unaccountable.

Why it matters

The same agent,
with and without a foundation.

The unfounded agent

Capable, but unaccountable

  • Identity is a shared key — anyone holding it is the agent.
  • Memory lives wherever the runtime happens to put it, or vanishes at restart.
  • No record of why it acted, so nothing can be verified after the fact.
  • Governance is a prompt and a hope, not an enforced boundary.
  • A single disruption erases its state and its continuity.

The being on entityOS

Capable, and trustworthy

  • Self-sovereign identifier it controls and can prove.
  • Durable memory persisted through a certified information-security regime.
  • Every decision carries verifiable provenance against its identity.
  • Governance and risk controls enforced by the platform, not the prompt.
  • Continuity by design — state survives outages and incidents.

entityOS as protocol & service

Where a being's data lives —
and what governs it.

entityOS persists each class of the being's data through its own mechanism, and each is held to a specific standard. Persistence is never just storage; it is storage with a governing rule behind it.

The being's data How entityOS persists it Governed by
Identity & keys Self-sovereign identity — KERI / ACDC autonomic identifiers the being controls. ISO/IEC 27001
Memory & state Written through the entityOS API to storage behind the closed-internet edge. ISO/IEC 27001 · 22301
Decisions & actions Executed under AI-governance controls, with oversight and enforced limits. ISO/IEC 42001 · NIST AI RMF
Provenance & audit Recorded as verifiable, tamper-evident credentials against the being's identity. ISO/IEC 27001 · 42001
Outputs & quality Produced through documented, repeatable processes that are measured and improved. ISO 9001
Risk posture Assessed and treated within a structured framework before the being acts under uncertainty. ISO 31000

The primary standards

Two load-bearing standards.
Everything else builds on them.

A being that persists data is only as trustworthy as the rules behind the information and the AI itself. These two carry the weight.

01 ISO/IEC 27001 Primary

Protects information and trust.

Information security management. Every byte a being persists — its identity, memory, credentials and decision logs — sits inside a certified Information Security Management System. Confidentiality, integrity and availability are managed as a discipline, not assumed. This is the certification entityOS already holds, and the reason a being's data can be trusted at rest and in transit.

02 ISO/IEC 42001 · NIST AI RMF Primary

Governs the responsible use of AI.

AI management and AI risk management. ISO/IEC 42001 provides the management system for building, deploying and operating AI responsibly across its lifecycle; the NIST AI Risk Management Framework — govern, map, measure, manage — gives the risk discipline that sits beside it. Together they govern the being itself: its oversight, transparency, accountability and the limits on what it is allowed to decide and do.

The supporting standards

Value, resilience
and sound decisions.

Three further standards keep a being useful, durable and considered — so its independence is matched by dependability.

ISO 9001

Quality

Ensures the organisation consistently delivers value.

Quality management. The being's outputs are produced through documented, repeatable processes that are measured and continually improved — so value is consistent, not incidental.

ISO 22301

Continuity

Ensures resilience under disruption.

Business continuity management. The being's persisted state is protected against outages, incidents and failure — so the being carries on through disruption instead of starting from nothing.

ISO 31000

Risk

The framework for managing uncertainty.

Risk management. Before a being acts under uncertainty, risk is identified, assessed and treated within a structured framework — turning autonomous decisions into considered ones.

Give your agents a foundation

An identity worth trusting.
A memory worth keeping.

01
Treat the agent as an entity

A self-sovereign being with its own identity — not a disposable key on a running process.

02
Persist through the protocol

entityOS carries the being's identity, memory, provenance and state behind the closed-internet edge.

03
Anchor to the standards

27001 and 42001 / NIST AI RMF at the core; 9001, 22301 and 31000 in support.

An AI agent becomes a being you can trust the moment its identity is its own, its memory is protected, its decisions are governed, and every one of those things is held to a standard.