Neutral trust infrastructure for security and AI

Trust, proven. Continuously.

Persora makes trust verifiable: the security controls you claim with Attest, and the AI agents that act for you with Conduct. Time-bound, revocable, independently verifiable.

Minimal data surface
No evidence storage
Signed, tamper-evident records
Revocable & time-bound
Status-only verification

To rely on a claim, you have to be able to verify it. Persora is the neutral layer that makes claims (about security controls and about AI agent behavior) verifiable, time-bound, and revocable.

Products

Two surfaces where trust breaks

Prove what you claim. Govern what acts for you.

Persora Attest

Prove cyber controls with verifiable attestations, not questionnaires.

Instant status verification for insurers, auditors, and regulators
Validate once, reuse across underwriting, audits, and compliance
Revocation and freshness built in, so reliance is never stale
New

Persora Conduct

Your agents act. Conduct proves what they did.

Scope-deny policy enforced before every tool call
Signed, hash-chained audit of everything agents do
Open-source core, Apache-2.0: no runtime fork, no phone-home

One Architecture

Two products, one set of rails

Attest and Conduct run on the same trust primitives. That's what makes them one company, not two tools.

Append-Only Integrity

Attestation events and agent audit records land in hash-chained, append-only logs: alteration, deletion, or reordering is detectable by any verifier.

External Key Custody

Persora never holds the keys that matter: issuer keys stay with issuers (Attest), signing keys stay out of the agent process (Conduct).

Expiry & Revocation First-Class

Every trust signal is time-bound and revocable. Freshness is checked, never assumed. A stale claim is a failed claim.

Status-Only Disclosure

Public verification confirms validity without leaking claim details. Full context is disclosed selectively, to authorized parties only.

One trust architecture. Two surfaces where trust breaks.

Read the Security Model

The Evidence

Unverified claims fail when it matters

The cost of trusting what you can't verify: in court, in claims, in breach outcomes.

$0

Coverage after rescission

A policyholder attested to MFA on a questionnaire, was breached through an unprotected admin account, and the court rescinded the policy entirely.

Source: Travelers Property Casualty v. International Control Services, C.D. Ill. (2022)

74%

Ransomware via remote access

of ransomware intrusions in Q1 2026 began with compromised remote-access credentials: exactly the control questionnaires claim is covered.

Source: Beazley Security Quarterly Threat Report, Q1 2026

−10%

Verified controls cut risk

breach likelihood per 25% more EDR deployed, and −9% with phishing-resistant MFA. Verified control state drives outcomes. Claims don't.

Source: Marsh McLennan Cyber Risk Intelligence Center, 2025

15%

Autonomous decisions by 2028

of day-to-day work decisions are forecast to be made autonomously by agentic AI by 2028, up from 0% in 2024. Most of that surface has no policy gate or audit trail today.

Source: Gartner, October 2024 (forecast)

Whether it’s a control claim on an insurance application or an AI agent acting in production: verify, don’t trust.

Neutrality

What we don't do

Persora is neutral trust infrastructure. It does not score risk, scan environments, or sell remediation.

We don't scan your environment
We don't store audit evidence
We don't score or rank organizations
We don't sell remediation tools
We don't inspect or score your models' reasoning
We make assurances verifiable.