Negative Zero Trust Center is Live
A dedicated home for how we approach security, compliance and the responsible operation of AI agents.
Trust should be part of the product. Not something added at the end.
Today, we're launching the first version of the Negative Zero Trust Center: a dedicated home for our approach to security, compliance and the responsible operation of AI agents.
As we build Negative Zero, we want customers to understand more than what our agents can do. They should understand how we approach the risks, what safeguards matter and how we test the assumptions behind our engineering decisions.
The Trust Center is where we will make that work visible.
V1 establishes a starting point for customers, partners and anyone evaluating Negative Zero to understand our approach to trust.
Its purpose is practical: explain the principles guiding our development, help answer security and procurement questions, and provide a foundation for sharing evidence as our platform develops.
This is the beginning, not a claim that every question is answered or every risk is solved. We intend to distinguish clearly between what is implemented, what has been tested and what remains in development.
What is in V1
Negative Zero is a Certification Body licensed by IASME to assess and certify organisations for Cyber Essentials and Cyber Essentials Plus. We hold ourselves to the schemes we assess others against, and the Trust Center is where you can check that we do.
System cards for every agent
Alongside the Trust Center we are publishing system cards for the AI agents that run inside our platform, starting with the Cyber Essentials Agent, the scoping and readiness assistant on this site.
A system card sets out, for one agent, what it is for, what it must not do, the foundation model it runs on, the guardrails around it, how it handles data and where a human is required. The Cyber Essentials Agent card, for example, records that transcripts are kept for 30 days and never used to train models, that the agent refuses passwords, credentials and other secrets, and that nothing it says is a certification decision. Only a licensed assessor can make one.
We think this is the right unit of disclosure for agentic systems. A platform-level security page cannot tell you what a specific agent is authorised to do. A system card can, and as we add agents, each will get one.
Evidence, not just assurances
Our approach to trusted, threat-informed prevention must apply to the agents we build, not only the services we deliver.
That means examining how agents could be misled, how their access should be constrained and where human oversight is necessary. Our prompt-injection research and red-team testing are part of that work.
The Trust Center will provide a place to share selected findings, explain what we learn and show how those lessons influence our engineering. We will publish enough detail to make the work useful and credible, while protecting sensitive information and avoiding disclosures that could create unnecessary risk.
We see three priorities for the Trust Center's development.
Deeper evidence. We plan to expand our published research and testing summaries, with clearer information about scope, review dates, limitations and resulting improvements. The aim is to help readers understand what an assessment demonstrates, and what it does not.
Clearer operational answers. As our architecture develops, we intend to explain our agent runtimes, model-provider choices, customer-supplied and managed model access, and the boundaries around permissions and data handling. These explanations should make both technical evaluation and procurement more straightforward.
Trust within the product. Longer term, our ambition goes beyond a public information page. In future versions, the Trust Center will feature directly in the Negative Zero Agent portal, so that relevant trust information sits alongside the decisions customers make: connecting a service, granting access or enabling an agent. That means working towards clearer visibility of what an agent is authorised to do, the safeguards governing its operation and where approval is required.
These are development priorities, not features we are claiming to have delivered in this first release.
The Trust Center will grow as our product, research and operating practices develop.
Our commitment is to make that progress understandable: explain the choices, acknowledge the limitations and support our claims with evidence.
Visit the Trust Center, read the Cyber Essentials Agent system card, or report a vulnerability to security@negativezero.com.
