A credential proves who someone is. Something still has to decide what they are allowed to do. That gap sits under every interaction the internet runs: opening an account, signing a contract, letting an agent move money or change your production platform.
KeyFlux closes it. For people, and for machines.
A licence held up to a camera. A password. A security question your mother could fail. A wet signature on a scan of a scan. Every one of them adds risk to a transaction that was supposed to be private, and every one of them is verified again from scratch next time.
An agent files a change to production. A pipeline pushes to a cluster. A workflow pays an invoice. Standing keys and long-lived tokens say a machine is known. They cannot say which machine acted, on whose authority, or inside what limits.
You can cryptographically prove a credential is real and still not know whether the holder qualifies. Over 18 is not the same as allowed to buy. Employed is not the same as authorised to approve. Verification confirms. Something else has to decide.
Six answers, one thesis underneath.
A state credential, verified in seconds. No upload, no review queue.
Sign-in bound to the device. Phishing and SMS interception get nowhere.
Prove someone is over 18 without learning who they are.
Confirm the approver actually holds the power to approve, not just that they are logged in.
Every machine action traced to a human who answers for it.
Credential a clinician, an installer, a broker in minutes instead of weeks of chasing paper.
Agents already operate production systems, ship code and move money. Adoption is not waiting for trust to catch up.
eIDAS 2.0 and ISO 18013-5 mDLs are moving from mandate to circulation. Hundreds of millions of people are about to carry a credential a business can actually verify.
The layer that decides what a verified party is allowed to do, human or machine, is unclaimed. It gets built once, and whoever builds it runs it.
Governments and their PKI providers issue the root: national IDs, mobile driving licences, residence and professional credentials. National or private PKI, ISO and W3C formats, standards conformance that has to survive audit.
Banks, telcos, insurers and credit bureaus take a government credential and issue their own on top of it. A verified customer becomes a reusable asset instead of an onboarding cost repeated forever.
Same engine. Different scale, different implementation architecture. And in both markets the value is not the credential. It is the decision made over the top of it.
Everyone wants agents to run operations, ship changes and settle payments. Almost nobody trusts them to, and the news keeps explaining why. Dependence on agents will only grow.
The missing piece is the human trust chain: every machine action pinned to a person or an organisation with the authority to have permitted it, inside a scope, inside a window, with a record that stands up afterwards. The question underneath is eligibility, asked of a machine: is this agent, this action, this request allowed right now, given the conditions?
That is REMIT.
How REMIT worksTurn a state-issued credential into an instant onboarding, authentication and authority decision.
Verified onboarding across channels, and a human trust chain for the AI you are about to put into network operations.
Give every agent, service, build and caller verifiable, attributable identity.
Issue credentials your citizens carry and other countries accept.
Verify practitioners and credential networks without chasing paper.
Right to work, corporate identity and delegated authority, verified at hire and in the flow of work.
Tamper-evident qualifications a graduate carries for life.
Prove someone is old enough without learning who they are.
Two engines. One question: eligibility.
Is this actor allowed to do this thing, right now, in this context? Core asks it of people and organisations. REMIT asks it of agents and workloads. That shared question is why the two belong in one company.
Is this agent, this action, this request eligible right now, given the conditions? Short-lived, scoped authority issued for one piece of work, pinned to a person or an organisation who answers for it.
Does this holder qualify, given the verified attributes they just presented? Issues, holds and verifies the credentials people and organisations carry, built on the ISO and W3C stacks, for foundational issuance and for derived issuance.
They share a thesis, not a codebase. A credential check and a machine authorisation are different problems with different failure modes, so they are different engines on purpose. Core decides eligibility over a presented credential, through Resolve. REMIT decides eligibility over a proposed action, through its own policy surface. Same discipline, two surfaces, deliberately. Different code, different data, different runtime.
What they share is the thesis that verified is not eligible, the open standards underneath, and the evidence discipline: every decision recorded with the reasoning attached. One seam is real today, and we will not claim more than it. Transact uses credential verification to establish who is paying.
Government PKI, private PKI, registries and trust lists, resolved across jurisdictions.
Keys rotate, leak and expire. What has to outlast them is the record of who acted, and on whose authority.
ReadTelling an agent what to do is not the same as bounding what it is able to do. Control is issued, not instructed.
ReadVerification confirms a credential is real. Eligibility decides whether the holder qualifies.
ReadTell us the question you need answered and we will walk you through it live.
Request a demo