Sidaxis is the human authorisation layer for AI agents. Proof that a live person authorised that machine — with a scope, a ceiling and an expiry, and a receipt any counterparty can check.
Software can act now. It still cannot prove who asked.
A password identifies whoever knows it. A token identifies whoever took it. An agent identifies nothing at all — and none of the three answers the only question that matters the moment a machine starts spending, signing or opening doors on somebody's behalf.
Problem 01
Identity is fragmentedThe same person is verified from scratch by every company they touch, and each one keeps a copy of their face. Eleven databases, eleven breaches waiting, one human.Every new vendor is one more copy of the same face.
Problem 02
Presence is unprovableA generated video passes a selfie check. When anything on a screen can be synthesised, the only credential left that cannot be forged is a living body, proven at that second.A selfie proves a picture existed, not a person.
Problem 03
Agents need a principalAn autonomous agent is only trustworthy if a real person authorised it. Every mandate, payment and signature it makes leads back to one verified human — or to nobody at all.Without a principal, an agent is an unsigned instruction.
Two primitives
Prove the human. Bound what the machine may do.
Everything else on this layer is these two, arranged differently. There is no third thing to learn.
Seven applications already run on these two — identity, biometric payment, signature, ticketing, screening, data sharing and media access.What runs on the layer ↗
How it works
From a human decision to a receipt anyone can check
Human intentA person decides, on their own device.
Advanced biometricsProof of living tissue, on the device, nothing stored.
Mandate issuedScope, ceiling and expiry, written down.
Agent actsInside the mandate, checked before every action.
Receipt anchoredAny counterparty can check it, with no account.
Reconciliation stops being a monthly report and becomes a lookup. Give a counterparty the hash and they see the same truth you do — settled amount, sealed liveness, mandate under which an agent acted.Open a live receipt →
Anyone can check, no account
Three legitimate viewsParties to the transaction see what they are owed. The public sees seals. Internal audit sees the full chain. Same receipt, masked per surface.
Agents with a leashAn autonomous agent holds a mandate with a ceiling, a scope and an expiry. Every action it takes anchors under that mandate, so revocation is instant and provable.
Nothing heldNo funds, no private keys, no raw biometrics. Non-custodial is an architecture here, not a policy that a future quarter can revise.
Our MCP servers expose identity, payment and catalogue tools that any model can call. The mandate is enforced at the protocol, not in your prompt — so a jailbreak cannot exceed a ceiling that the rail refuses to clear.
A technical mapping, not a partnership, an endorsement or a certification of conformance.
Proprietary technology
Fourteen patent claims, and none of them describe a database
Filed as a provisional application. Everything that makes a person unique is computed where they are standing, and only a proof travels.
14Claims, provisionally filedCovering how the coordinate is resolved, how liveness is read, and the per-party derivation that makes correlation impossible.
Processed on the deviceRead, resolved and signed inside the person’s own hardware. Nothing is uploaded — not once, not even to enrol.
Non-custodial by architectureNo template and no master key. It is not a promise we make — it is a capability we do not have, and cannot be given.
Nothing to store, nothing to stealBreak into us and you get proofs that things happened. You do not get one person’s face, because there is not one to get.
Prove a human and issue your first mandate today.
Sandbox keys in minutes, no card. The first anchored receipt takes one call, and a failed call is never billed.