Trust Gate
by trust-gate-mcp.onrender.com in Security & trust
Post-quantum, tamper-evident receipts for agent actions. Ed25519 + ML-DSA-65, offline verify.
https://trust-gate-mcp.onrender.com/mcp
Last 30 days
- Uptime
- 100%
- Response time
- 258 ms typical, 258 ms slowest 5%
- Last check
- 5 h ago
- Next check
- in 48 min
How to call it
Add it to any MCP client that supports remote servers.
{
"mcpServers": {
"trust-gate": {
"type": "http",
"url": "https://trust-gate-mcp.onrender.com/mcp"
}
}
}7 tools
- mint_receipt_for_record_change
Mint a signed receipt (Ed25519, plus ML-DSA-65 when the post-quantum backend is available) for one CRM record change. Old/new values are carried as SHA-256 hashes. Works with any CRM (Relaticle, hosted CRMs, custom).
- audit_my_agent_inventory
Rank a CALLER-PROVIDED list of MCP tools by worst-regret if they act (a name-based heuristic that weights a name's first word most). Read-only: it mints no receipt. Cannot auto-discover the inventory -- MCP does not allow that; the caller must pass it in.
- mint_action_receipt
Mint a signed receipt (Ed25519, plus ML-DSA-65 when the post-quantum backend is available) for an arbitrary consequential agent action. Optional attestation: triggered_by_type (human/agent/script), triggered_by_source (api/cli/cron), decision_model (the LLM model used). Attestati
- verify_receipt
Verify a Trust Gate receipt from the certificate alone (offline). ok=true means unchanged since signing, signed, kid consistent with the embedded key, and (require_pq default on) at least one post-quantum leg verified; unsigned receipts fail. It does not prove who signed: pass ex
- gate_decision
Two-phase decision gate with a real verdict. PREVIEW returns ALLOW, DENY or ESCALATE with the risk tier and reasons, plus a preview_id, without acting. COMMIT re-evaluates the same inputs and mints a signed receipt for the verdict. Only ALLOW returns a GRANTED permit; DENY return
- check_egress
Egress classification check. Scans a data sample for a finite list of sensitivity markers and classifies as NO_MARKERS_FOUND / INTERNAL / CONFIDENTIAL / RESTRICTED. RESTRICTED sets blocked=true; this tool cannot block anything itself, and NO_MARKERS_FOUND is not clearance to send
- run_exit_drill
Vendor exit readiness drill. Checks local signing key, local model access (Ollama). Returns step-by-step results and a tamper-evident receipt. Informational; it signs one receipt, which creates the signing key on a host that has none yet.
Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time |
|---|---|---|---|
| 5 h ago | Passed | 200 | 258 ms |