
CSOAI
Initializing...
Free forever · No credit card

CSOAI
Initializing...
Every agent-to-agent call traverses identity → trust → policy → firewall → rate-limit → handoff → audit → governance. Each stage emits a signed attestation. The whole pipeline chains into one auditor-defensible event for EU AI Act Article 12 + DORA Article 17 + ISO 42001 clause 9. MIT-licensed self-host or £799/mo managed.
Because the next protocol layer agents are converging on is agent-to-agent infrastructure, not the chatbox. Anthropic shipped MCP. Google shipped A2A. Stripe shipped A2A Payments. The pieces between agents — identity, trust, policy, audit — need standardisation.
Sold separately, each primitive is £29-£199/month. Bought together as the Substrate, you get all 20, the unified api.meok.ai/v1/a2a/<primitive> endpoint, 100K calls/month included, and the signed governance-bridge event chain — for £799/month.
Or skip the subscription entirely: £0.0002 per call, no monthly minimum, billed monthly via Stripe metered.
identity-trusttrust scoredata-residencytransfer-basis OKpolicy-enforcementscoped allowinjection-firewallno LLM01rate-limitergrant tokenhandoff-certifiedsigned provenanceaudit-loggerhash-chainedEvery stage is an MCP. You can self-host them all under MIT licence, or call them individually via uvx <name>-mcp. The Substrate is the managed pipeline that runs them in sequence behind one endpoint, with one signing key, one invoice, and one HMAC-chained evidence trail.
W3C DID + verifiable credentials → trust score
uvx agent-identity-trust-mcpGitHub →OWASP LLM01 scan on prompts + RAG + tool args
uvx agent-prompt-injection-firewall-mcpGitHub →Folds 7 signals into EU AI Act / DORA / ISO 42001 evidence
uvx a2a-governance-bridge-mcpGitHub →5-voter Byzantine council halts agent loops on no-progress
uvx bft-progress-council-mcpGitHub →Per-session hard cap with signed budget-exhausted attestation
uvx agent-token-budget-mcpGitHub →Multi-tenant chargeback splitter with signed per-tenant summary
uvx agent-cost-allocator-mcpGitHub →Stripe ACP + Google AP2 + Coinbase x402 bridge
uvx agent-commerce-protocol-mcpGitHub →Coinbase HTTP 402 on-chain settlement — pay-per-call without Stripe
uvx agent-x402-paywall-mcpGitHub →Cisco OASF + AGNTCY bridge under Linux Foundation
uvx oasf-agent-directory-mcpGitHub →Step-debug agent runs + deterministic replay + signed audit
uvx agent-replay-debugger-mcpGitHub →The agent interop space has 6 live protocols right now. The Substrate bridges all 6 behind one signing key, so your code stays portable when the standards shake out.
Note on "ACP": the acronym is overloaded. IBM ACP (Agent Communication Protocol) was wound down in Sept 2025 and merged into A2A under Linux Foundation. Stripe ACP (Agentic Commerce Protocol) is a live, separate protocol for in-conversation payments. Our Substrate covers both.
Built passively as customers use the Substrate. We don't read your payloads. We aggregate the metadata of what's happening across the fleet.
Every blocked attempt feeds an anonymized signature corpus. After 1M scans we own the most current real-world dataset.
→ £999/mo to CISO teams + SIEM vendors (Wazuh/Elastic/Splunk integrations)
Every evaluate_call → DENY event categorised. The canonical map of agent-permission failure modes.
→ Quarterly 'State of Agent Permissions' report — £2,499 full data access
How agent incidents cascade across EU AI Act Art 73, DORA Art 19, NIS2 Art 23, GDPR Art 33.
→ £2,500/day consulting · regulator briefings
Anonymised production-fleet data on which model hands off to which, for which tasks, under which trust threshold.
→ Annual 'State of A2A' report · content marketing engine
Set of agent DIDs that have ever interacted, with anomaly-detection signals.
→ £0.0005/check — called by firewalls + payment systems before transactions
The frontier of agent-to-agent infrastructure: identity, trust, audit. One email a month, no spam.
We never share your email. By subscribing you agree to receive monthly MEOK updates. Operated by CSOAI LTD (UK Companies House 16939677).
Yes. All 20 MCPs are MIT-licensed. uvx <name>-mcp installs each. The Substrate subscription gives you the managed pipeline + signed verify URL + 99.9% SLA — not the source code (which is free).
Each tool invocation on any of the 20 primitives = 1 call. A typical A2A interaction traverses ~3-5 primitives, so one customer-facing request = ~3-5 billable calls. 100K Substrate-included calls ≈ 20-30K full pipeline runs/month.
Substrate customers opt-out by default for moat data sharing during the first 60 days. After that, anonymized aggregate metadata feeds the moats with no payload reading. Enterprise contracts can require permanent opt-out — no discount, but available.
Those are orchestrators. We're the trust + audit substrate underneath them. Use them for workflow, use us for what regulators ask for. Many customers run both.
Two protocols share the 'ACP' acronym. IBM ACP (Agent Communication Protocol) was wound down in September 2025 and merged into A2A under the Linux Foundation — our Substrate already supports it via A2A. Stripe ACP (Agentic Commerce Protocol) is a separate live protocol for agent commerce inside ChatGPT — we ship the bridge in Q3 2026. See the multi-protocol coverage table above.
Yes — both shipped. agent-commerce-protocol-mcp covers Stripe ACP + Google AP2 mandates + Coinbase x402 in one bridge. agent-x402-paywall-mcp is the dedicated Coinbase HTTP 402 + on-chain settlement primitive. x402 also wraps our api.meok.ai gateway so you can pay-per-call without a Stripe account.
Live now: BFT Progress Council (loop halt), Token Budget cap, Cost Allocator, ACP bridge, x402 paywall, OASF Directory (Cisco/AGNTCY), EUDI Wallet (eIDAS 2.0), Replay Debugger. Next: agent-content-watermark (Article 50 + C2PA), agent-incident-relay (Article 73 5-clock broadcaster), agent-eu-mlbom-export.
MEOK AI Labs · CSOAI LTD · UK Companies House 16939677 · MIT-licensed source · Apache 2.0 Python · hello@meok.ai