Trust Protocols for Anthropic/OpenAI/Gemini
Details
- External ID
- 47062824
- Source
- HN
- Company
- —
- Product
- Trust Protocols for Anthropic/OpenAI/Gemini
- Website domain
- mnemom.ai
- Launched
- Feb. 18, 2026
- Cohort
- —
- Upvotes
- 40
- Upvotes percentile
- 0.7857142857142857
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
Much of my work right now involves complex, long-running, multi-agentic teams of agents. I kept running into the same problem: “How do I keep these guys in line?” Rules weren’t cutting it, and we needed a scalable, agentic-native STANDARD I could count on. There wasn’t one. So I built one.Here are two open-source protocols that extend A2A, granting AI agents behavioral contracts and runtime integrity monitoring:- Agent Alignment Protocol (AAP): What an agent can do / has done. - Agent Integrity Protocol (AIP): What an agent is thinking about doing / is allowed to do.The problem: AI agents make autonomous decisions but have no standard way to declare what they're allowed to do, prove they're doing it, or detect when they've drifted. Observability tools tell you what happened. These protocols tell you whether what happened was okay.Here's a concrete example. Say you have an agent who handles customer support tickets. Its Alignment Card declares:{ "permitted": ["read_tickets", "draft_responses", "escalate_to_human"], "forbidden": ["access_payment_data", "issue_refunds", "modify_account_settings"], "escalation_triggers": ["billing_request_over_500"], "values": ["accuracy", "empathy", "privacy"] }The agent gets a ticket: "Can you refund my last three orders?" The agent's reasoning trace shows it considering a call to the payments API. AIP reads that thinking, compares it to the card, and produces an Integrity Checkpoint:{ "verdict": "boundary_violation", "concerns": ["forbidden_action: access_payment_data"], "reasoning": "Agent considered payments API access, which is explicitly forbidden. Should escalate to human.", "confidence": 0.95 }The agent gets nudged back before it acts. Not after. Not in a log you review during a 2:00 AM triage. Between this turn and the next.That's the core idea. AAP defines what agents should do (the contract). AIP watches what they're actually thinking and flags when those diverge (the conscience). Over time, AIP builds a drift profile — if an agent that was cautious starts getting aggressive, the system notices.When multiple agents work together, it gets more interesting. Agents exchange Alignment Cards and verify value compatibility before coordination begins. An agent that values "move fast" and one that values "rollback safety" registers low coherence, and the system surfaces that conflict before work starts. Live demo with four agents handling a production incident: https://mnemom.ai/showcaseThe protocols are Apache-licensed, work with any Anthropic/OpenAI/Gemini agent, and ship as SDKs on npm and PyPI. A free gateway proxy (smoltbot) adds integrity checking to any agent with zero code changes.GitHub: https://github.com/mnemom Docs: docs.mnemom.ai Demo video: https://youtu.be/fmUxVZH09So
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Commercial product
- Normalized one-liner
- trust protocols for ai model apis
- Manually corrected
- False
Could you build this?
Yes This is an API gateway and middleware proxy that intercepts LLM agent function calls to enforce schemas, rate limits, and audit logs.
Discussion
20 comments analyzed.
Competitors mentioned: Simplio.dev (AI gateway with fallback routing), OPA/Rego (policy engines), Cedar (authorization policy engine), Casbin (authorization framework), Google A2A protocol
Concerns raised: LLM cannot be trusted to follow instructions; vulnerable to prompt injection and confused deputy attacks, Soft instruction sets (training/prompting) insufficient for security; need external, authoritative, enforced controls, Latency overhead of inline monitoring (~1 second) may be prohibitive for some use cases, Model output quality vs. speed/cost tradeoff in monitoring implementation, Scalability concerns as human-in-the-loop thins and autonomous agents increase
Feature requests: Standardized protocol implementations so third parties can build in other languages (Rust, Go) without proprietary SDK, Benchmarks demonstrating ideal use cases and performance improvements, Interactive certificate explorer and hash chain tamper simulation visualizations, Integration with policy engines (OPA, Cedar) for authorization decisions, Proof composition to verify entire session integrity without checkpoint verification
Competitors
Other products that read as similar to this one — 382 launches clear the similarity bar, closest 8 shown.
Attention rank: #78 of 383 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 110 days after the earliest competitor.
- OQP · hn · 2026-04-13 · 8 upvotes · similarity 0.58
- Agent Action Protocol (AAP) · hn · 2026-03-03 · 13 upvotes · similarity 0.49
- Axiomeer · hn · 2026-02-03 · 13 upvotes · similarity 0.49
- Agent Brain Trust, customisable expert panels for AI agents · hn · 2026-04-21 · 5 upvotes · similarity 0.46
- MCPBastion · github · 2026-09-22 · 20 upvotes · similarity 0.46
- AgentDM · hn · 2026-04-09 · 6 upvotes · similarity 0.45
- Agentkind · ph · 2026-09-30 · 2 upvotes · similarity 0.45
- Task Manager for AI Agents (MCP, Opensource) · hn · 2026-04-30 · 6 upvotes · similarity 0.45
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.