EMBER SOVEREIGNTY SYSTEMS
Check your email — click the sign-in link, or enter the code from it here:
You're in. One more step: register your security key (a passkey). Signing in stays email-only — the key is what approves security-critical actions, as the owner of your org's smart account.
00CONTROL
One structure, always: the smart account governs, policy sets the dial, sealed keys execute only inside the attested TEE, and every call proves itself.
01POSTURE · LAST — CALLS
02VENUE KEYS
Only attested execution opens a key. Sealing a venue again rotates the old key out in place; revocation fails closed. Rotation and revocation move under owner quorum when #2 lands.
02.1AGENT KEYS
An ek_ key resolves to the AGENT role: it calls models under your policy and can never seal, revoke, or govern. The secret is shown once, at mint.
| NAME | PREFIX | MINTED | LAST USED |
|---|
03RECEIPTS
A receipt is trusted only when every bond holds: signer, venue, request, response, nonce, org, key, status. Open a row for the proof. Refusals are receipted too.
| TIME | MODEL | VENUE | VERDICT | STATUS | SEC | PROOF |
|---|
04TENANTS · SOVEREIGN MODE
Each customer gets the same control plane you use: their own owner set, the TEE signer on it, their own sealed keys and receipts. You provision the control object and route calls through it; you never hold their keys and cannot loosen their policy. Vendor-administered until claimed (#9); co-branded by default, white-label is a paid feature.
05USAGE
$0.01 per compute-second of attested execution. Token counts ride along in receipts; the meter is seconds.
| KEY | LABEL | CALLS | COMPUTE-SEC | METERED |
|---|
POINT YOUR HARNESS
One env var. Any Anthropic-wire harness. OpenAI-compatible route is #4.