Your board will ask which AI agents are running. Can you answer?

FIND WHAT IS RUNNING · PROVE WHAT IT DID

Most enterprises cannot. The agents nobody owns are still holding credentials, touching customer data, and spending money.

What the assessment returns

A finding with a dollar figure attached.

Governance findings get deferred. Findings with money attached get funded.

ACME CORP · ALL ENVIRONMENTS · FINDINGS SUMMARY
Agents discovered11
Attested — origin and work provable7
Unattested — cannot prove anything3
Failed verification — record altered1
Total agent token spend$25,140 / mo
Spent by agents nobody owns$8,920 / mo
Annualized, unowned$107,040

Read the full sample report

Security review, answered up front

It cannot leak what it never sends.

The four objections your security team will raise, answered before you forward this to them.

No egress

Discovery runs inside your VPC. Your agent inventory, topology, and spend data are never transmitted to us.

No write access

Read-only by construction. It holds no credentials to your systems and takes no action on them.

No agent installed

Reads from sources you already run — Kubernetes API, cloud inventory, provider billing, existing endpoint telemetry.

Open format

The record format and verifier are published. Your team can confirm what it does without trusting our description of it.

Week one

From nothing to a board-ready answer.

Point it at your environment

Read-only credentials to inventory sources you already run. No install, no host agent.

Get the inventory

Every agent — containers, scheduled jobs, serverless, workflows, robots, credential-holding scripts — with owner, purpose, data access, uptime, and spend.

See what cannot prove itself

Agents with no verifiable record are listed as unattested. That list is the finding, and usually the surprise.

Take it to the committee

Export the findings report with exposure, recommended actions, and the annualized dollars each one frees up.

Why the free tool cannot vouch

Discovery observes. It cannot attest.

Attestation requires signing with a key unavailable to the platform running the agent. If the discovery tool held that key, the platform would be certifying its own agents — the exact failure the index exists to expose.

It is an architectural boundary, not a feature gate. Everything discovery can honestly do stays free.

FREEFind every agent, read its record, verify signatures, report what cannot be proven
LICENSEDIssue records, countersign work, quarantine, revoke, meter spend
Pricing

Discovery is free. Proof is licensed.

Not a trial that expires.

Discovery — free

Full inventory across environments. Owner, purpose, data access, uptime. Token spend per agent, attested or not. Verify existing records. Findings report export.

Attestation — $4 / agent / mo

Issue creation records. Countersigned action history. Adopt existing agents into record. Continuous verification. SIEM export.

Attestation + Control — $9 / agent / mo

Everything above, plus break-glass quarantine and revocation, responder keys with dual approval, expiring holds, and the freshness policy engine.

TokenMark™ — 0.9% of spend managed

Per-agent budgets and hard stops. Metering against the attested record. Anomaly holds. Monthly savings statement.

On TokenMark pricingPriced on spend under management, not on savings — we do not bill against a number we calculate ourselves. Savings are reported and checkable against your provider invoices.
Questions your team will ask

Straight answers.

What does it connect to?Read-only access to what you already run: Kubernetes API, cloud resource inventory, model-provider billing, and existing endpoint telemetry. No host agent, no inbound access, no credentials to your data systems.
Will it find everything?No. It reports what the collectors can reach. Unmanaged networks and offline systems are out of scope, and absence of a finding is not assurance that no agent exists. We say this in the report itself.
What happens to agents we already have?They are adopted, not backdated. An adopted agent’s standing begins at adoption on stated evidence, and everything before that is recorded as unverified. You get an honest record instead of a fictional one.
Can we stop an agent immediately?Yes. Any authorized responder can quarantine an agent without the owner’s key. The hold is signed, expires automatically unless renewed, and only the owner can lift it.
Are we locked in?No. The record format is published and the verifier is open. Records you create remain verifiable with or without us.
After attestation

Then cap what they spend.

Once agents can prove what they did, TokenMark™ meters every charge against that record — per-agent budgets, hard stops, and a monthly savings statement you can check against your provider invoices.

See TokenMark™ Back to the demo

Programs & participation
NVIDIA InceptionMember
NIST Zero DraftsSubmissions filed
NIST AI 300-1Public comment
NIST NCCoEPost-Quantum Cryptography
Community of Interest
DOE Genesis MissionConsortium participant
Congressional Internet CaucusAdvisory Group — former member

Participation in an open public process is not endorsement. No agency, standards body, consortium or company listed here endorses Atom Works™, its products or its claims.