01 · AEE
AEE
Agent Envelope Exchange
Every action wrapped in a signed envelope. The envelope is the signed unit of work: what is being done, by which agent, when, and under which lease.
the envelope is signed before it moves
Reason
AgentsQuoxMindAgentic TeamsMirrorQuoxLensRemember
QuoxMemoryBrain2CompoundingQuoxPlanCodebase MirrorAct
QuoxFlowQuoxEngineQuoxAgentQuoxChatAutonomyRun
EnterpriseOrganisationsPowers & ToolsmithQlusterQuoxBastionInterfaces
QuoxMCPQuoxCLIQuoxTerminalQuox ConsoleQuoxBoxGovern
HITL ApprovalsQuox SecurityAgent HonestyQuoxVaultAI GovernanceAgentic AIProve
For AuditorsVerifiable AI OpsLoggingEU AI ActCompliance SuiteChannels
Matrix RoomsDiscord ProTelegram ProQuoxSignalCoreCommsAll products A-ZBuild
QuoxProofDeveloper KitPlugin SDKBring your tool to QuoxQuoxpertQuoxSkillsQlarityShip and sell
Build and sellBrowse MarketplaceDownloadsProtocolsDev Suite
Dev ServersQuoxBuildQuoxSlotsShared Skills + RulesDev workflow
RepoBrainGripeTriageFixLoopProofLoopDoneEngineAll products A-ZGet started
OverviewArchitectureProtocols
AEEAOCLVOLTWARDReference
GlossaryAPI ReferencePlugin SDKDockerAll products A-ZThe evidence layer
Most platforms ask you to trust them. Quox gives you the receipts. Four open protocols turn every agent action into verifiable evidence.
Four protocolsOne audit trail
AEE · Agent Execution Envelope
Watch one agent action become cryptographically provable
In plain words
QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE
The protocol stack
Each one does a single job on the way from an agent's intent to a sealed, checkable block. You do not trust the agent, you check it.
01 · AEE
Agent Envelope Exchange
Every action wrapped in a signed envelope. The envelope is the signed unit of work: what is being done, by which agent, when, and under which lease.
the envelope is signed before it moves
02 · AOCL
Agent Orchestration Control Layers
The governed pipeline: scoped powers, policy checkpoints, human-in-the-loop. Every envelope is routed through the control layers, and a step that crosses a line you drew waits for a human.
The full HITL story →03 · VOLT
Verifiable Operations Ledger
The verifiable operations ledger. Signed events carry each governed step between services, verified on receipt, so the record is built as the work happens, not reconstructed afterwards.
04 · WARD
Write-once Append-only Receipt Digests
The append-only, tamper-evident chain, with signed tips and RFC-3161 timestamps. Each block binds the hash of the one before it. Alter one byte anywhere and the whole chain fails verification.
The VOLT and WARD protocols and the evidence API are core. The dedicated ledger and receipt views, and the per-turn decision record, are the Decision Evidence enterprise add-on at $599/yr. See Decision Evidence →
Policy, not promises
AOCL checks each envelope against policy before it moves, and every policy change is logged with actor, diff and reason, held behind an opt-in 4-eyes approval gate.

No trust required
Run the offline verifier against the chain. It checks every block, every signed tip and every timestamp on your own machine, with no call home to us.
quox ward verify --org acme --offlinechecking 4,213 blocks · 0 mutations
chain VERIFIED ✓
For a review
Export the paperwork a review actually asks for, backed by the chain rather than by a policy document.
Capability matrix
Policy enforcement for AI agents is the enforcement half of governance: deciding, per action, what an agent may do, and proving what it did. This is what the platform covers today, and where each capability's evidence lands.
| Capability | What it does | Where the evidence lands | Deep dive |
|---|---|---|---|
| Policy enforcement | AOCL checkpoints gate agent actions before they run: deny policies hard-stop the action, hold policies block execution until a named human decides, and the gate fails closed on evaluation error. | Logged in the AOCL trace, layer by layer. | Read AOCL · What stops an agent going around this |
| Human approval | A sensitive action pauses mid-run and waits in one approval inbox until a person decides. | Who decided, what and when, written to the run's evidence record as an approval receipt. | How HITL works |
| Evidence chain | Every governed step is signed at emit and re-verified on receipt, then appended to a hash-linked, tamper-evident chain. | The VOLT ledger, with tips published and witnessed on WARD. | Read VOLT · Read WARD |
| Audit export | Evidence is packaged into bundles built for external review, not assembled by hand when the request lands. | Exported evidence bundles, each carrying a WARD-signed manifest hash. | The auditor experience |
| Containment | E-STOP halts a single agent, DEFCON steps the whole instance down, and the halt itself has to be proven, not assumed. | The kill switch's own evidence record: what fired, what it stopped, who authorised it. | The kill switch, in full |
| Spend control | A budget cap sits on the control plane, before the action runs, not on a monthly invoice reconciled later. | The same trace as any other containment decision, not a separate ledger. | Spend as containment |
| Fleet governance | The same checks apply whether one agent is running or a hundred, so nothing starts ungoverned. | A fleet-wide evidence register, not a per-agent average. | Govern at scale |
The audit trail
Each entry is a VOLT trace, hash-linked to the one before it, so the record is built while the work happens rather than reconstructed afterwards.

Who it is for
The same chain of evidence, read three ways.
Export WARD-signed PDFs across 7 frameworks (SOC 2, HIPAA, GDPR, ISO 27001, EU AI Act, ISO 42001, NIST AI RMF) with one click. SoA Builder, DPIA and Risk Classifier built in. Every policy change is logged with actor, diff and reason, with an opt-in 4-eyes approval gate per mutation.
Runtime policy denials become first-class incidents: auto-triaged, assigned and fanned out to your SIEM. Behavioural baselines per agent catch drift before it matters. Replay any trace layer by layer, and simulate policy changes with What-If.
A dedicated portal with PBC auto-match, pre-populated working papers and chain-of-custody verification. Every PDF carries a WARD-signed manifest hash you can verify independently: one trust anchor across envelopes, runs and reports.
Read at a glance
Policy denials, behavioural baselines and 4-eyes approvals all feed the same status: what you see here is only ever what AEE and AOCL have already recorded, org-wide.

Seven frameworks
Evidence from the chain, exported against the seven frameworks the Compliance Suite covers, filling the sections your telemetry can evidence and marking the rest action-required.
Read honestly
The same chain that exports against seven frameworks will show you where a control falls short, not only where it is met. A gap on this dashboard is real, and it stays until closed.

Pricing
The protocols and the core platform are free. The compliance tooling on top is paid.
$599/yr
For compliance officers and security teams.
Free
For engineers building custom AOCL layers.
Free
The protocols are open. The platform is free to start.
Bundle both for a 15% discount. Volume pricing available. Talk to sales
Questions
The Compliance Suite generates evidence bundles mapped to each Trust Services Criteria (CC1–CC9). VOLT traces provide the continuous monitoring evidence auditors need, and the evidence is collected automatically rather than in spreadsheets.
Yes. The control plane, policies, memory, secrets and evidence chain run entirely on your infrastructure, and licence activation supports offline mode. Inference runs where you choose: fully local for an air-gapped deployment, or through a model provider you explicitly configure.
Every operation produces a VOLT trace entry with a cryptographic hash chain. Each entry references the hash of the previous entry, so any modification breaks the chain and is immediately detectable.
Every 100 WARD entries, a signed Ed25519 checkpoint is published to an RFC 3161 timestamp authority (FreeTSA.org by default). GitHub, GitLab, S3 Object Lock, webhooks and Gitea are also supported. No extra infrastructure required.
Yes. The Developer Kit is free and is for building and testing custom AOCL layers; the Compliance Suite covers audit exports and production layer runs. There is no bundle to discount because the kit costs nothing.
Email support at [email protected], for the Compliance Suite and the Developer Kit alike. We do not quote a response time or promise named staff, because neither is something we can stand behind yet.
Policy enforcement means an agent action passes a policy checkpoint before it runs: allowed actions proceed, actions matching deny policies are hard-stopped, and actions matching hold policies block until a person decides, with the gate failing closed if evaluation errors. In Quox this is the AOCL control layer, and every decision lands in the evidence chain.
The evidence layer
You do not trust the agent, you check it. Start with the protocol drafts, or talk to us about governance for your deployment, part of the wider Quox enterprise platform.