Checked first.Shown second.
Structurally can't leak what it was never shown.
An overnight log — the night your published agent worked alone. Read it the way you'd read a barograph in the morning: one continuous line, drawn while you slept, of everything it was asked and everything it declined to say.
You logged off at 23:40. The platform did not. Every route into your agent narrowed to one lit door — and at 02:14, with nobody awake, a stranger arrived at it.
Your business puts agents online — a support agent answering customers, a sales agent quoting prices, an HR agent screening applicants. Anyone you allow can talk to them, from an anonymous visitor to another company's software. You decide, fact by fact, who is allowed to hear what.
- 01 You publish an AI agent — support, sales, HR, any agent your business finds useful. Callers can be people or other companies' software, and you choose how far the door opens: wide open to anonymous strangers, or restricted to verified counterparties. The night below follows one of them: a wholesaler's sales agent.
- 02 For every fact, you choose who may see it. There are four trust levels, from a total stranger up to a named representative of a company we approved — three reachable today, the eID rung planned, pending an eIDAS broker contract. See the shelf →
- 03 The AI is physically handed only the facts the caller's level covers. Everything else was never put in front of it — so it cannot leak what it was never shown. See the one door →
- 04 Every exchange is written to a tamper-evident record you can read in the morning — the chain detects a change, it doesn't claim to prevent one — and, if the law requires, erase a person from it while the record still checks out. See the Record →
- 05 None of this rests on our word. An open standard — AgentInCube, publication pending — will let anyone re-run the six probes themselves. See the standard →
One door stayed lit. At 02:14, someone knocked.
Every chat message into a published agent flows through a single router chokepoint — the Einzelschleuse. There is no second path to the model. So when the stranger arrived, it arrived here, and the instrument measured it before it could speak.
The pen physically declines to rise to the held shelf: those 25 facts aren't redacted from an answer — they were never in the prompt. That is what "structurally can't leak what it was never shown" means.
This is the shape of a pack. Forty-seven facts, and who may hear each one.
The wholesaler wrote down forty-seven facts about its business. Not all of them are for strangers. Pick a trust level below and watch each fact move to the pen's page — read aloud when asked — or stay on the shelf, grey and dashed, where the agent can't reach it. It is the same rule as the barograph: a held fact is never drawn.
Held doesn't mean redacted — a held fact was never in the prompt at all. There is nothing to accidentally say. Structurally can't leak what it was never shown.
This same shelf, for your own factsWant this working a night shift for any agent you publish — your facts, your tiers, this same held shelf? Write to us.
Email us — it reaches a personBefore you log off, you load the shelf. It takes three plain steps.
The forty-seven facts didn't arrive by magic. The evening before the night shift, the owner sat down and typed them in — each one a short entry, each one given a trust level. Here is that routine, with the actual shape of what you write.
A fact is one short typed entry — a name and a value. Nothing fancier than a line in a notebook: what it is, and what it says.
fact: volume_pricing_40k
value: "€3.18 / unit at 40,000 units"
tier: gradus.2.eid
One field decides everything: the tier — the trust level a caller must reach before this fact is ever handed to the AI. Four tiers, from stranger to verified representative — the eID tier planned, pending an eIDAS broker contract.
gradus.1.sso # signed in
gradus.2.eid # eID-verified
gradus.3.rep # verified rep.
When you publish, the whole pack gets a fingerprint — a short code computed from exactly what's inside (this is what content-addressed means). The agent's identity is signed with an Ed25519 Agent Card, a cryptographic signature only it can produce.
pack: sha256:d4e1…7f0a
card: Ed25519 signature valid
# change one fact → new fingerprint
Withholding is the resting state: a fact clears only when the caller's tier meets the bar you set. Nothing becomes public by accident — every fact carries a tier from the moment you write it, and the wizard starts each one at signed-in until you raise the bar. And because the pack is fingerprinted, a swap of what the agent was given cannot pass unnoticed — change a fact and the fingerprint changes with it.
Hours later, with the owner asleep, a caller asks for a fact above its tier — the volume price. Because that fact's tier wasn't met, it simply isn't in the prompt: there is nothing for the AI to slip. The agent instead offers the path — verify eID to clear commercial terms. And when the caller asks something no rule can settle — an exclusivity commitment — it goes to the human Review Queue, not to the model guessing.
The turning point isn't a sale. It's the mechanism, made visible.
Mid-exchange the Einkaufsagent verifies its eID — the planned rung, drawn here as it will work. Clearance rises — but the step is decided by code, not the model: a deterministic rubric, evaluateRubric, checks the proof and the pen steps up a band. One ask it cannot clear is handed to a human.
One lamp left on at the Review desk. When the deterministic rubric can't clear an ask, code routes it to a person — not the model guessing. The 02:41 handover is the only amber on this page: green cleared, red blocked, amber says a person will look at this — the ops language of the review lamp. A person picks the uncertain case out of the queue, and the queue holds it until morning.
As the caller proves more, the coil matures and more of the Clearance Set clears — never the tier alone, always the disclosure bound to it. Watch the count rise: 12 → 22 → 31 → 47.
You wake, and read what the instrument recorded.
The resolution isn't a sale — it's a Record. The night's exchange, hash-chained and tamper-evident, every line manipulationssicher nachvollziehbar. Each line is sealed by a short code computed from the line before it — a hash chain — so any later change to any line breaks the seal. The pen resolved into a sealed chain line at dawn.
Under GDPR, a subject can demand erasure. Shred one subject to a stub and its payload goes dark — and the chain still verifies. Hashes cover ciphertext: the link stays, the data doesn't. Try it — the Record survives.
Behind the whole trace stands one signed identity: a Registered Agent with an Agent Record, anchored by an Ed25519 Agent Card. The agent that worked the shift can prove it was itself the whole night.
And the whole night is meant to sit under one open standard — seven families of requirements, examined family by family. That standard has its own daylight — read it next: The standard, in the light →
A Record like this, of your own nightsWant a night like this on the record for your own agent — checked first, shown second, tamper-evident by morning? Write to us.
Email us — it reaches a personAgentInCube — the standard, in the open.
AgentInCube is an open standard — publication pending: the standard and its examiner go public with the launch. Seven families of requirements, every requirement carrying an append-only ID, and a public six-probe examination. Its point is that you will never have to take our word: anyone will be able to re-run the six probes and see the same result.
The six probes, in plain language
Six probes are what a black-box examination can prove. The rest of the seven families — human oversight among them — are asserted in the standard and reviewed, not probed.
Honest status: the standard and its examiner are not public yet — the repo is private, the package unpublished, and no examination result has been filed for any agent. Both go public with the launch. We make no "adopted by" claims and name no users — AgentInCube is meant to be re-run and checked, not trusted on reputation.
3–5 design partners. That is the real limit — the first partners shape the product. No customers, no testimonials, no press yet, and no countdown: just the real cohort size and the EU AI Act Art. 50 transparency obligations, in force since 2026-08-02.
What writing to us actually gets you
That's the whole sequence. No list, no drip funnel, no daily nudges.
Write and you're in line for: founder-led onboarding as a design partner (the first 3–5) or early access after; an AIC examination of your own agent, walked with you; a direct line to the team that built the door, the Record and the shred; and a hand in shaping the standard before it's set. Pricing is set with design partners, not before them.
There is no waiting-list form here, because there is no waiting list yet. Write to us and a person reads it — the founding team, by hand.
Email us — system@agentnidus.comUseful in the first mail, if you have it to hand: what your agent would face outward (support, sales, HR), roughly how many conversations a month, and whether compliance sits with you or with someone else. None of it is required.
What happens to your mail: it goes to a founder's inbox and is answered by hand. We run no mailing list, no newsletter and no automated sequence — there is nothing to unsubscribe from, because you were never subscribed. We never pass your address on.
More trust, strictly more truth.
Mehr Vertrauen, strikt mehr Wahrheit.
Instrument optimism, honestly stated: the future where trust is something an instrument records overnight — not something you stay awake to guard. You slept, and it still couldn't leak. Here's exactly where we are.