Vervain
Berkeley, California

Identity decides who may read. Nothing tracks where it went next.

Vervain is a local data and action control layer for AI agents. It maps where agent context and derived data persist, then produces bounded evidence of what a revocation or deletion actually reached.

The gap

Your identity and authorization systems decide whether an agent may read a customer record. They do not show where that record and its derivatives went afterward. A single agent turn can leave copies in a context window, a cache, a vector index, a tool result, a log line, and a checkpoint, each with its own lifetime.

So when a customer asks you to delete their data, or a tenant boundary is questioned, the honest answer today is usually an estimate.

Identity Agent A may read record R. Decision logged. This is where most stacks stop.
Contextprompt and turn history
Cachereused prefix state
Indexembeddings and chunks
Tracelogs and tool output

Vervain instruments the second row: where the data landed, how long it stayed, and what a delete request actually reached.

What it does

Vervain runs inside your environment, on the same infrastructure as the stack it governs.

Where to start

One-week cross-tenant contamination assessment

For teams running multi-tenant agent systems. Can you show today that one tenant's data has never appeared in another tenant's context? We instrument your stack, trace real requests, and report what we found and where we could not see.

You get a written map of the persistence points we reached, the specific requests behind any cross-tenant path we observed, and an explicit list of the surfaces the assessment did not cover.

LengthOne week
Runs onYour infrastructure
StacksvLLM, SGLang, Ollama
Start a conversation →

What this does not claim