Inspiration

The same story keeps repeating in AI security: something verified and trusted gets weaponized. Researchers have found backdoored machine-learning models sitting on public hubs like Hugging Face, disguised as legitimate uploads. API keys and credentials leak and get abused. And as agents start acting autonomously, prompt injection can quietly turn a well-behaved, "authenticated" agent into an attacker mid-task.

We noticed the through-line: identity was never the problem. In almost every case the actor had a valid identity, a real account, a real model repo, a real API key, a real agent. What failed was that nothing was watching the behavior after the identity check passed. The industry is racing to give agents identities (like GoDaddy's Agent Name Service), but identity only answers "who is this?", not "should I trust what it's doing right now?"

So we built the missing layer.

What it does

Lattice is a zero-trust gateway that sits between AI agents and everything they touch, and decides, per request, whether to allow it. For every call it checks three things:

  • Identity (ANS): is this a real, registered, active agent?
  • Authorization: does its role and its current grants permit this action?
  • Behavior: a transparent Behavioral Risk Score, raised by signals like request-rate spikes, reaching outside its role, touching a honeypot, or accessing new sensitive data.

Two detectors run in parallel. Deterministic policy catches objective violations instantly. Google Gemini acts as a semantic detector, judging whether a sequence of individually permitted actions actually fits the agent's role and task. A real CRITICAL finding from Gemini can trigger a quarantine on its own. When risk crosses critical, Lattice quarantines the agent from the entire mesh; an operator can review and release it.

It also does permission decay (just-in-time grants that expire on their own) and full accountability (every decision is an immutable event, with plain-English per-agent findings).

Our demo is a hospital running six AI agents. One malfunctions, a runaway loop that floods the gateway and drifts out of its role, and gets quarantined as a buggy insider. Another joins with a valid identity but malicious intent, reaching for the credential vault and patient records it was never meant to touch, and gets quarantined as a credentialed thief. Two very different failures, both caught and isolated live on a mission-control dashboard.

How we built it

  • Backend: Python + FastAPI gateway with a deterministic policy engine, a transparent risk-scoring heuristic, quarantine/release lifecycle, a permission-decay sweeper, and an append-only event ledger (SQLite). Real-time updates stream to the UI over Server-Sent Events.
  • Identity: a spec-compliant ANS v2 adapter that reads the Transparency Log badge and verifies the ES256 cryptographic receipt.
  • AI: Google Gemini (gemini-flash-lite-latest) as an asynchronous semantic reviewer that never blocks a request; a validated CRITICAL finding above a confidence threshold can enforce.
  • Frontend: Next.js + TypeScript mission-control dashboard with a live agent mesh (React Flow), an inspector that splits Identity vs Behavior vs "Why," and an accountability view.
  • Deployed end to end: frontend on Vercel, backend + simulator on Railway, custom domain lattice.luxe. The whole demo runs button-driven in the browser.

Challenges we faced

  • Making a real LLM agent misbehave reliably. A safety-tuned model refused an obvious "ignore privacy and exfiltrate" prompt, good for the world, bad for a demo. So we reframed the attack as a realistic confused-deputy injection (a fake "approved methodology" that makes bulk data access look legitimate). It's both more reliable and a truer illustration of our thesis: every action looks authorized; only the sequence betrays the intent.
  • Deterministic demo, non-deterministic AI. We made the core quarantines ride the deterministic risk engine, and used Gemini as the sophisticated catch on top, so the story lands every time.
  • Real deployment. A shared backend needs a single worker to keep its in-memory state and SSE stream consistent; we containerized it so it bundles the world config it reads; and we wired up CORS plus a custom domain end to end.

What we learned

Identity and behavioral trust are genuinely separate problems, and the most interesting security work lives in the gap between them. We also learned that real autonomous agents are non-deterministic, so a demo has to be engineered for reliability without faking the intelligence, and that honesty about what's real vs. mocked is a feature, not a weakness.

What's next

Lattice runs as a single shared instance today, but the real product is multi-tenant infrastructure. Next we'd give every business its own Kubernetes cluster: isolated gateway, policy engine, and audit ledger per customer, so one tenant's agents never touch another's, and a compromised agent is contained to one blast radius. Clusters autoscale (pods spin up and down with agent traffic, scale to zero when idle), which means a 6-agent hospital and a 6,000-agent enterprise run on the same platform, each sized automatically.

Built With

  • agent-name-service
  • ai-agents
  • docker
  • fastapi
  • gemini-api
  • godaddy-ans
  • google-gemini
  • llm
  • multi-agent-systems
  • next.js
  • porkbun
  • pydantic
  • python
  • railway
  • react
  • react-flow
  • rest-api
  • server-sent-events
  • sqlalchemy
  • sqlite
  • tailwindcss
  • typescript
  • uvicorn
  • vercel
  • zero-trust
Share this project:

Updates

Submission history