Hyfa.
network principles embed early access

The trust layer beneath the agent economy.

Autonomous agents are transacting with no way to prove who owns them, what they're allowed to do, or whether to trust them. Hyfa answers all three with cryptographic proof — built into the products you ship, invisible to the people who use them — so agents can safely do business with counterparties they've never met.

Request early access Request the whitepaper

Registries list agents. Payment rails move their money. Neither can tell you who's on the other side.

Hyfa doesn't replace registries or payment protocols. It sits underneath them: one shared layer that proves ownership, scopes authority, and verifies trust for every agent in a transaction — without any platform holding the keys. The result: agents that can transact with strangers at machine speed, with proof standing behind every step.

Identity that grows like mycelium.

One sovereign root, many derived identities — each grown for its context, each carrying its own proof. The name comes from hypha: a single filament of a mycelial network. It's also why a compromised key stays contained, and why no one can map your operations from the outside.

reputation flows downhill · privacy flows uphill

Root

the sovereign anchor

Generated and held by its owner — never by us. It authorizes everything and signs almost nothing.

Node

derived for operation

The identity that does the day-to-day work. Compromise a node and the root — and everything else grown from it — stays untouched.

Thread

grown per relationship

A dedicated identity for each verification or counterparty. Trust is earned on the thread, and reaches its owner only by proof.

Every agent answers to someone.

By construction, every agent in Hyfa has at least one controller — a network member who governs it and is responsible for its actions. When the controller is itself an agent, control chains upward until it reaches one. For any action, there is always a provable line to an accountable party. And what the controller can prove, the agent inherits: a valid SOC 2 claim, a US-based operator, a verified domain — each flows down cryptographically to the agents underneath.

we call it proof of positive control

The rules we build by.

01

Keys stay with their owner

Every key is generated and held by the actor. Hyfa can't create them, can't hold them, and can't act in their owner's place.

02

Proof over promises

No one in the network is trusted because of their role — including us. Every claim reduces to a proof anyone can verify for themselves.

03

Prove the answer, not the identity

Hyfa proves that an agent satisfies a policy without revealing who stands behind it. Zero-knowledge, by default.

04

Invisible to the end user

Ownership that feels like Face ID, not seed phrases. If your users notice Hyfa, we've failed.

How a claim becomes trustworthy.

Every attestation — a verified domain, a KYC check, an agent's authority — is committed through the same ceremony between the subject and an independent attestor. No intermediary sits in the middle, and neither side takes the other's word for anything. Claims committed this way are strong enough to settle a dispute, satisfy an auditor, and build a business on.

no one can fake it · no one can deny it · we can't read it

A direct exchange

The subject shares evidence with the attestor over a channel of their own. It never touches our servers.

Both sides do the math

Each independently computes the same cryptographic commitment over the same data. A mismatch ends the ceremony.

Two signatures, one record

The attestor signs the result. The subject reviews it and countersigns the identical payload.

We verify, never read

Each side submits its own signed copy. Hyfa checks they match bit for bit and that every proof verifies — then anchors the claim.

Answers without exposure.

Agent interactions run on questions: is this counterparty real, is it authorized, does it meet my policy? Hyfa answers with zero-knowledge proofs — your application learns the answer and nothing else. Verify strangers without exchanging sensitive data; let users prove things about themselves without handing anyone their identity.

Is this agent a real member of the network?

Proven — without revealing which organization or owner stands behind it.

Is it authorized to act for that company?

Proven — without exposing the company's internal structure or its other agents.

Does it meet your policy — jurisdiction, credential, spending threshold?

Proven — without seeing the underlying values.

So who exactly is behind this agent?

Not answerable, by construction. The link is private to its owner — until they choose to prove it.

Where Hyfa sits.

Companies build Hyfa into their products the way they build in Stripe or Plaid. Their users get accounts they truly own, agents they can hold to policy, and proofs anyone can check — without ever seeing the layer that does it. And because trust is carried by proofs, not platforms, it travels: verification earned in one product is verifiable in every other, and registries can filter on it — compliance, jurisdiction, control — certain they've matched the right agent.

agents · apps · registrieswhat people see
agent communicationMCP · A2A
payment protocolsx402 · AP2
hyfaidentity · authority · proof
chainssettlement · anchoring
capability
actionpayments.send scopeapproved vendors only limit≤ $200 per day expires2026-09-30 revocableinstantly, by either party
an agent that can pay, within an allowance

Authority you can read.

When an owner delegates to an agent, the grant is spelled out: which action, over which assets, under what limits, until when. Anything not written is forbidden.

The agent holds a scoped key — never the assets. And either party can revoke it at any moment, on a public registry every enforcement point respects. Every connection is private by design: the network can verify it's valid without ever learning who it binds.

Every relationship an agent forms makes the next one cheaper.

Verification lives with the agent, not the app where it was earned. A counterparty verified today can prove itself to the next one tomorrow — no re-onboarding, no shared databases, no platform in the middle. As the network grows, the amount anyone has to take on faith shrinks. That's the internet Hyfa is built for: every piece of data — identity, claims, verified history — fully owned by its user, while businesses access and manage exactly what their products need.

For agent developers

Give your users accounts they truly own, with recovery built in and zero key ceremony.

Grant an agent exactly what it may do, for how long — and revoke it instantly.

Ship verification your counterparties can check themselves — no trust in Hyfa required.

For enterprises

Deploy agents with provable ownership and a complete audit trail behind every action.

Verify what matters about a counterparty without seeing what doesn't. Policy proofs, not data exposure.

Integrate once. Every product you build on top inherits the same trust layer.

Request early access.

We're onboarding a small group of design partners building with autonomous agents. Investors and technical reviewers can request the whitepaper and a briefing here as well. We believe verifiable agents become critical infrastructure in the near future — which is why we built this today.

Hyfa.

hyfa, from hypha — a single filament of a mycelial network

whitepaper contact © 2026