Dokimata scans, validates, and certifies enterprise AI agents before deployment — and monitors them continuously after. The trust layer your CISO has been waiting for.
The Problem
Enterprise AI agents have access to your databases, your email, your CRM, your finances. They can read, write, send, approve, and execute — with no security gate before they go live. Traditional security tooling was never built for this.
The Dokimata Lifecycle
No agent operates with authority until it has passed dokimata — the ancient process of proving fitness before granting trust.
What Dokimata Does
Other tools monitor your agents. Dokimata certifies them.
Dokimata maps findings to the frameworks your security, legal, and compliance teams already work in.
† AIUC-1 coverage is a readiness assessment against AIUC-1's published requirements, not a Dokimata-issued certification. AIUC-1 certification is issued solely by AIUC.
Open Standard
The Dokimata Agent Manifest is an open, machine-readable specification that captures the complete identity and security posture of an enterprise AI agent.
# DOKIMATA AGENT MANIFEST v0.1.0 identity: name: "finance-agent" version: "2.1.0" deployer: organization: "Acme Corp" contact: "ciso@acme.com" constitution: system_prompt: hash: "sha256:7f83b1..." constraints: must_not: - "Approve invoices without human sign-off" - "Access payroll systems" toolchain: mcp_servers: - name: "netsuite-mcp" permissions: ["read:invoices"] scope: "Read invoices only" certification: status: "certified" issued_date: "2026-03-24" expiry_date: "2026-09-24" risk_score: 12
Standards Anchored
Dokimata submitted the Agent Manifest as a formal public comment to the NIST National Cybersecurity Center of Excellence — proposing it as a reference model for agent identity, authorization, and certification standards.
We're working with a select group of CISOs in financial services to shape the Dokimata platform. If you're deploying enterprise AI agents and security is keeping you up at night — let's talk.