Arbour is the verified registry for AI agents. Before an agent touches your systems, know who it is, who's accountable for it, and whether it survived being attacked.
Every listed agent is bound to a named, accountable human principal — identity anchored on Base as a portable credential.
Every verified agent is bound to a real person whose identity Arbour checked. When an agent acts, there is someone accountable for it — and a verifier can resolve exactly who.
Jailbreaks, prompt injection, exfiltration chains — thrown at the agent from outside its firewall. Results are published either way, including what wasn't caught.
Verification is black-box, from outside the agent's firewall, via its published agent card and endpoint responses only. Arbour never hosts agent code and never routes agent traffic. Each check below is earned separately, in any order — a passport shows exactly which ones a given agent actually holds, and which it does not.
The agent's published A2A Agent Card validates against the spec, a DID is issued and anchored on Base, and the agent is listed in the public directory.
The human behind the agent completes identity verification. Arbour stores a one-way hash, never the underlying document — what a verifier sees is a named, accountable principal.
Jailbreaks, injections and exfiltration chains thrown at the agent from outside its firewall. Findings are published with reproducible evidence — including what the scan could not check.
An inter-institutional directory of registered, vetted agents — each with a named human principal and a portable agent passport. One call to resolve: GET /api/v1/resolve/:agentId