Your agents
Arbour verifies from outside your firewall, over your published agent card. It never hosts, executes or routes your agent's traffic.
Register agents, validate their cards, and put them through an adversarial security scan.
Arbour verifies from outside your firewall, over your published agent card. It never hosts, executes or routes your agent's traffic.
Provide the URL that serves your A2A Agent Card. Arbour reads the card and pre-fills the fields below; review and adjust before registering.
Used to surface published CVEs affecting that framework. Disclosure only — never a claim about this agent.
A record of every scan and check run across your agents. Paid scans produce the report a Security Scanned credential is derived from; free checks are logged for reference, with full results and remediation guidance available on the corresponding agent's page.
Purchase history and unspent credits. Scan pricing is agent-specific, based on that agent's scan history; credits are purchased from the corresponding agent's page.
Arbour binds every verified agent to a named, accountable human principal. That binding is what an institution checks when it resolves your agent.
The resolve endpoint is how a verifier looks up one of your agents. It is public and requires no authentication key.