Financial platforms spend months on KYC/AML onboarding. AI agents deploy without audit trails or policy guardrails. Vantix provides hardware-attested verifiable credentials and a tamper-evident audit log that every compliance officer and regulator demands — all open-source, all local-first.
KYC/AML compliance takes weeks per customer. Identity verification is fragmented across vendors, and audit trails are spreadsheet-based. Regulators demand a single source of truth.
An LLM with a wallet can be prompt-injected and drained of funds. No policy engine sits between the model and the signing key. No audit log proves what the agent did or didn't do.
WebAuthn hardware attestation. W3C Verifiable Credentials. Tamper-evident audit log. Plugs into existing KYC flows in hours, not months.
Policy-bound verifiable credential. An agent is attested to operate under a specific policy hash. Platforms verify before trusting a trade, withdrawal, or swap.
Every credential issuance and verification is hash-chained. Delete a record and the chain breaks. That's the compliance artifact regulators accept.
All packages are TypeScript, typechecked, tested (78 tests), and built for Node 20+ and modern browsers. They compose as a stack but ship independently.
Cross-platform P-256 key generation and signing backed by hardware attestation (WebAuthn / App Attest / Android).
Hardware-bound wallet runtime with a local, non-bypassable policy engine for exchange request signing.
Verifiable credentials and a tamper-evident audit log for compliance-grade identity verification.
Verifiable credentials binding an AI agent to a bound policy hash, with a shared audit chain.
Hyperliquid client with nonce-safe action builders and builder-fee support.
Coinbase (CDP) integration for trade, swap, and stake via Secure Enclave keys.
Model Context Protocol server exposing a policy-gated Secure Enclave wallet to AI agents.
The April 2026 SEC Staff Statement confirmed a 5-year exemption (through 2031) for self-custodial wallet interfaces. Vantix never touches keys, so it falls squarely within the exemption — no registration burden.
Autonomous agents are executing trades, staking, and transacting on-chain with no policy layer. Prompt-injection is a real attack vector. Every agent platform will need attestation infrastructure.
Regulators in the US and EU are increasing scrutiny on automated financial systems. An append-only, hash-chained audit log is the compliance primitive they're asking for — not a database dump.
All core SDKs are MIT-licensed and free — that's the distribution engine. Revenue comes from the layers on top.
Managed credential issuance, verification, and audit-log ingestion with uptime SLAs. The Human Verify and Agent Attestation APIs as a service — pay per credential, not per developer.
Custom hardware security module integrations, threshold multisig policy engines, and white-label SDK licensing for quantitative trading firms and regulated exchanges.
Hyperliquid integrates builder-fee routing at the protocol level. Every trade routed through a Vantix-attested agent contributes 0.04% to the network — sustainable, token-free revenue.
Vantix is built and maintained by one engineer. Every package, test, API route, deployment, and policy decision ships directly from the founder. The code is public and the commit history is the resume.
Built on
$5,000
total budget, $500 on infrastructure and $4,500 in reserve.
Packages shipped
7
all MIT-licensed, typechecked, and tested with 78 passing tests across the workspace.
Commit history
Public
every decision is visible at github.com/gabelossless/vantix-zk — from smart-contract purge to compliance primitives.