Bind
Sender, recipient, purpose and parent hop are attached before anything leaves.
ZTroven runs inside your agents, at every outbound handoff to a model, a tool, an MCP server, another agent or a queue. It decides what that recipient may see, sends the permitted payload itself, and signs a value-free record of what left.
Inside your application · No ZTroven service in the data path · Works across agent stacks
The full workflow context stays inside the application.
Your policy decides this hop.
Gateways, routers and runtime controls decide which agents run, which tools they may use and what they spend. ZTroven works one layer in, inside the agent, deciding which facts each recipient may learn and recording exactly what was sent. It adds to the controls you already run. It replaces none of them.
The same pattern applies whether the recipient is a model, a tool, another agent or a queue.
Sender, recipient, purpose and parent hop are attached before anything leaves.
Your egress contract determines this recipient’s permitted view, deterministically.
Each declared field is allowed, removed or tokenized locally. The hop can also be blocked or held for review.
ZTroven sends the payload itself, so the bytes evaluated are the bytes sent.
A signed, value-free record links the hop to its transaction.
Fail-closed by default. If a policy cannot be enforced, or a recipient has no matching contract, the hop stops or is visibly marked unverified. There is no model in the decision path, so the same inputs always give the same decision.
You declare which fields are sensitive. ZTroven locates them and applies the action your contract sets for each recipient.
allowThe recipient needs this value for this purpose, so it is sent.
removeThe field is taken out of this recipient’s view entirely.
tokenizeA reversible token replaces the value. The vault and keys stay with you.
blockThe hop does not go out.
require_reviewA person on your team confirms before the hop proceeds.
Each hop record is something your reviewers can check for themselves. It is deliberately specific about what it does and does not show.
A TypeScript library that runs in-process. Your models, orchestration, tools and runtime stay as they are. Available today to design partners.
import { ztrovenSend } from "ztroven"; const result = await ztrovenSend( call, customerContext ); return continueWorkflow(result);
Whether you run an agent platform or build agents for regulated workflows, we would like to show you the control layer on one of your handoffs.