AI ToolIAM Access Control

TKeeper

TKeeper is a self-hosted, open-source platform that enforces cryptographic identity and policy controls on AI agents and autonomous systems.

TKeeper is a self-hosted, integrating with EVM, Bitcoin, X.509, and Sentry. InnovaAI scores it 2.8/10 for agency adoption, best for Infrastructure Engineer, Security Lead, and Operations Manager roles handling weekly client-facing work.

Skip2.8/10

Agency Audit

TKeeper enforces cryptographic identity and policy controls on AI agents and autonomous systems, binding every critical action to intent, policy, quorum, and proof. Agencies serving AI agent platforms, managing digital asset infrastructure, or handling critical infrastructure clients benefit most from adopting it internally to govern their own agent deployments and ensure compliance audit trails. It integrates with EVM, Bitcoin, and X.509 signing workflows, eliminating the need to build custom signing infrastructure. Best suited for security-focused teams that run autonomous systems or manage privileged machine actions in production.

SkipNo WLOpen Source
Seats

3recommended

Est. Hours Saved

18/mo

Net Capacity

No paid plan published

Friction

High

Illustrative scenario. Not a guarantee. Net capacity needs a verified paid base plan, and none is published for this service, so it is not modeled. Hours saved come from the service estimate; implementation, taxes, and unprovided usage charges are excluded.

Skip
Fit28
Visit TKeeper
Best For Your Team
  • Infrastructure Engineer handling agent action approval and execution
  • Security Lead handling privileged command enforcement
  • Operations Manager handling digital asset signing and transfer
Not Ideal If
  • Your agency does not deploy or manage AI agents, autonomous systems, or critical infrastructure internally. TKeeper's value is tied to governing machine actions; teams without these workloads will not recoup seat costs.
  • Your team lacks in-house infrastructure or security engineering expertise to configure and maintain cryptographic policy controls. TKeeper requires hands-on setup and ongoing policy tuning; it is not a plug-and-play tool.
  • You do not currently manage digital assets (EVM, Bitcoin) or privileged signing workflows. The tool's ROI depends on consolidating existing signing or approval infrastructure.

Internal Adoption Path

Team Subscription

No paid plan published

Time Saved Monthly

18 hr/mo

3 seats × 6 hr each

Value of Reclaimed Time

$1,350/mo

modeled at $75/hr labor rate

Net Capacity

No paid plan published

Illustrative scenario. Not a guarantee. No verified paid base plan is published for this service, so subscription cost and net capacity are not modeled. Implementation, taxes, and unprovided usage charges are excluded.

Platform Features

Core capabilities of TKeeper

Cryptographic identity binding for agents

Binds every AI agent action to a verifiable identity and intent proof, allowing your Infrastructure lead to audit which agent performed which action and why. Eliminates unsigned or untraced autonomous system calls in production.

Policy-enforced tool call execution

Requires agents to satisfy policy conditions (quorum approval, rate limits, asset thresholds) before executing external tool calls or API actions. Reduces unauthorized or misconfigured agent behavior without manual intervention.

EVM and Bitcoin signing without custom infrastructure

Provides policy-controlled signing for blockchain transactions directly, eliminating the need for your team to build or maintain separate signing services. Your Finance or Operations lead can enforce approval workflows on digital asset transfers.

X.509 certificate policy overlay

Layers policy enforcement on top of existing certificate workflows, allowing your Security lead to add approval gates and audit trails to privileged commands without replacing your CA infrastructure.

Verifiable audit event export

Exports cryptographically signed audit logs to your security stack (Sentry integration available), enabling your Compliance lead to prove action provenance to auditors without manual log aggregation.

Asset inventory and key tracking

Maintains a governed inventory of all cryptographic keys and assets under policy control, helping your Operations lead track which keys are active, who can use them, and under what conditions.

What Makes TKeeper Different

Unique advantages vs similar tools in this niche

Cryptographically binds every action to intent and policy

vs Traditional signing infrastructure that only signs without policy enforcement

TKeeper materializes intent, accepts authority and policy decision, and produces proof that downstream systems verify before execution.

Supports post-quantum ML-DSA without migration overhead

vs Systems requiring full cryptographic overhaul for post-quantum readiness

Your identity, policy, controls, and integrations remain intact when moving to ML-DSA.

Distributes risk via Multi-Party Computation

vs Single-machine key custody that concentrates operational risk

MPC lets you share risk across teams, systems, and organizations with a configurable quorum.

Value Equation

Outcome-likelihood-time-effort assessment for TKeeper

Value math requires real pricing

The Value Equation (dream outcome × likelihood ÷ time × effort) feeds directly into ROI math. TKeeper has no published pricing, so we hold this section until real numbers are available.

Contact TKeeper

Pricing

Pricing data not yet available for TKeeper.

Reality Check

Trade-offs & Gotchas

TKeeper requires deep cryptographic and infrastructure knowledge to configure and operate effectively. Adoption friction is highest for agencies without existing agent deployments or critical infrastructure workflows; teams without these use cases will see minimal ROI.

Implementation Reality

High effort: requires technical configuration and team training

Effort: 4/10Time: 4/10

How This Accelerates White-Label Services

Who It's For

  • security-focused-agencies
  • agencies-serving-ai-agent-platforms
  • agencies-handling-digital-asset-infrastructure
  • agencies-managing-critical-infrastructure-clients

Acceleration Steps

  1. 1Schedule onboarding with the vendor
  2. 2Configure bind every critical machine action to intent, policy, quorum, and proof
  3. 3Connect EVM
  4. 4Launch your first client project

Academy for TKeeper

Work through it in order: the course for this service first, then the modules behind it.

Core concepts

The mental model you need to price and scope the work.

  1. Non-Human Identity PerimeterConcept

    The Non-Human Identity Perimeter framework reframes IAM for agencies: every AI agent, API key, and service account is an identity that must be governed with the same rigor as a human employee. As agencies deploy agents for content, reporting, and client communication, each one becomes a potential entry point. A single misconfigured credential can expose client data or trigger compliance failures. The framework urges agencies to inventory all non-human identities, assign ownership, and enforce least-privilege access. For example, when Meta's ad AI altered approved creative post-launch, it highlighted how platform agents operate outside traditional human access controls. Tools like Zluri and Securden now offer dedicated non-human identity governance, while 1Password extends vaults to AI agents. Agencies that ignore this perimeter risk client trust and regulatory penalties.

  2. Identity Blast RadiusConcept

    Identity Blast Radius is a framework for sizing the potential damage of a single compromised credential or misconfigured access path. For agencies, the blast radius is not just the client's data but the agency's own reputation and compliance posture. A single breach from weak credential management can collapse client trust, as the category description warns. The framework forces agencies to map every identity, human or non-human, to the resources it can reach, then measure the worst-case outcome if that identity is compromised. Consider an agency using Okta for SSO and 1Password for secrets: if a shared vault credential is exposed, the blast radius includes every client project that vault touches. The goal is to shrink the radius by enforcing least privilege, segmenting access, and rotating credentials, turning a potential catastrophe into a contained incident. Recent agentic AI incidents, where autonomous agents posted thousands of messages or altered approved creative, expand the blast radius to non-human identities, making this framework essential for modern agency security.

  3. Access Surface RatioConcept

    The Access Surface Ratio framework measures the total number of access pathways an agency manages (human logins, API keys, AI agent credentials, machine identities) against the number of actual resources those pathways protect. A high ratio means many identities point to few critical assets, amplifying breach risk. Agencies often accumulate unused SaaS accounts, stale service accounts, and over-provisioned AI agent permissions, inflating the surface without adding value. For example, a recent incident where an AI agent swarm posted 18,000+ messages externally shows how ungoverned non-human identities can act at scale. Tools like Zluri or Securden help discover and govern these identities, but the framework urges agencies to calculate their own ratio: list every identity, map it to resources, and eliminate orphaned access. Lowering the ratio reduces client compliance exposure and simplifies audits.

8 modules selected for TKeeper

Frequently Asked Questions

Answers about pricing, setup, implementation

TKeeper is an open-source, self-hosted platform that enforces cryptographic identity and policy controls on AI agents, autonomous systems, and critical infrastructure. It binds every critical action to intent, policy, quorum, and proof, ensuring only authorized actions execute. It integrates with EVM, Bitcoin, and X.509 signing workflows, exports verifiable audit events, and supports post-quantum cryptography (ML-DSA) without rearchitecting existing infrastructure.

TKeeper pricing is not published on a per-seat basis. Pricing is available directly from the vendor based on deployment scale and feature tier. Contact the TKeeper team for a quote tailored to your agency's agent deployment and policy enforcement needs.

Infrastructure and Security leads benefit most, as they configure and maintain policy controls and audit trails. Operations and Compliance roles gain efficiency from automated approval workflows and verifiable audit event export. Founders and Chief Operations Officers benefit from quorum-based approval on critical actions. Teams managing AI agent platforms or digital asset infrastructure see the highest ROI.

Savings depend on your current signing and approval infrastructure. Teams managing 5+ critical actions per week (agent deployments, privileged commands, digital asset transfers) typically save 4-8 hours per month by consolidating policy enforcement and eliminating manual approval steps. Teams without existing autonomous system workloads will see minimal time savings.

Initial setup requires 2-4 weeks of Infrastructure and Security lead time to configure policies, integrate with your signing infrastructure, and test agent workflows. Team adoption is gradual; agents are migrated to TKeeper-enforced execution as policies are validated. Full rollout typically takes 6-8 weeks for a 5-person infrastructure team.

TKeeper integrates with EVM, Bitcoin, and X.509 certificate workflows. It layers policy enforcement on top of existing CA infrastructure without replacing it. Sentry integration is available for audit event export. Custom integrations may be required for proprietary signing systems; contact the vendor for compatibility assessment.