IAP Exchange
02 / Protocol

A Non-Invasive Safety Sidecar for Institutional AI.

IAP sits beside your agent, not inside it. It never holds assets and never sees the model. It verifies, constrains and signs.

02.1LOW-FRICTION INTEGRATION

A sidecar, not a rewrite.

No core system is replaced. IAP mediates only the moment of interaction with an external counterparty.

Institution A

Your agent

Credit, treasury or risk agent. Existing model, existing framework, unmodified.

Interlock

IAP

Identity verified. Mandate checked in hardware. Provenance signed. Channel opens only if every condition holds.

Institution B

Counterparty platform/agent

Receives a proposal it can cryptographically trust, without seeing your pricing logic.

No retraining

Model logic is untouched. IAP mediates the interaction, not the reasoning.

No core overhaul

Deploys from an innovation environment into production without re-architecture.

Framework agnostic

Compatible with the major agent frameworks in production use today.

Policy without code

Compliance teams map existing risk rules into IAP; the protocol handles enforcement.

02.2Controls

Seven controls, applied before anything executes.

Governance tooling observes and reports. IAP sits in the path, so a breach is prevented rather than recorded.

Control 01

Verified agent identity

Cryptographic proof of who the agent is and who authorised it, bound to the firm's legal entity identifier. No anonymous counterparties.
Control 02

Hardware-enforced safety

Your risk policies are locked inside a secure digital vault. If an AI Agent attempts a move outside its mandate, the communication channel is instantly cut.
Control 03

Hidden Logic (Zero-knowledge)

The system proves your AI is playing by the rules without revealing your proprietary trading strategies to the counterparty. They only see a green light.
Control 04

Verified Data Origins

We trace the lineage of all market data feeding the AI. If the input data is unverified or corrupted, the system pauses the trade.
Control 05

Outlier circuit breaker

A deterministic safety model runs alongside the negotiation. A statistical outlier triggers a cooling-off period and human intervention.
Control 06

Stated Intent Verification

The system double-checks the counterparty's stated intentions against the actual transaction parameters. If they don't align, everything
Control 07

Tamper-Proof Audit Trails

Every handshake writes a tamper-evident record: authority, limits, proposal, decision. Effortless compliance audits without exposing internal IP.
02.3Liability

Clear boundaries, by design.

IAP is a technology provider

No custody of assets, no decision authority. It verifies and constrains; it does not trade.

Mandates are fixed at runtime

Limits are set in advance and cannot be altered by the agent mid-interaction.

Liability remains with the institution

The firm owns its agent's commercial decisions. IAP makes the limits of those decisions provable.

A technical walkthrough is available under NDA.

Protocol specification, enclave design and the pilot deployment model.

Request Technical Briefing