Tokens are minted without kinds.
Every non-human identity is a token. Without a named owner, scoped permissions, and an expiry, that token outlives the project it was created for, with permissions nobody remembers granting.
AI security colleagues that review agent code, fix what they find, and prove it closed.
MCP tool granted write scope it never uses
Patch approved: local patch approved; simulated merge event recorded. No repository contacted.
Identity re-issued: long-lived key retired; scoped 15-minute token provisioned by Tokynd Birthright.
Finding re-verified: exposure closed on rescan. Evidence written back to the source.
Control evidence logged: SOC 2 CC6.1 / ISO 42001 A.6 evidence pack updated automatically.
Agents now move money, touch customer data, and change production systems. The security model has to govern the identity making the move, not just the traffic around it.
Every non-human identity is a token. Without a named owner, scoped permissions, and an expiry, that token outlives the project it was created for, with permissions nobody remembers granting.
Scanners enumerate; tickets accumulate. Injection paths, over-scoped tools, and drift sit in queues while the same reachable weakness survives another quarter.
Tokynd Security closes both: Tokynd Birthright provisions identity at creation, then the platform runs see, fix, govern, prove across every action.
Nine products work as one colleague system. Each pillar has one operational job, one human gate, and one place in the loop.
Tokynd Winnow turns scanner noise into one owned queue. Tokynd Pulse learns the deterministic baseline and surfaces deviations.
See itTokynd Pair produces the smallest reviewable patch, tests it locally, drafts the PR body, and waits for a human.
See itTokynd Attavard tiers and maps. Tokynd Birthright creates the identity record. Tokynd Vestibule reviews MCP permissions. Tokynd Sparring exercises adversarial configurations.
See itTokynd Dossier packages the approved fix and verified rescan. Tokynd Asbuilt compares architecture intent with deployed reality.
See itEvery product reads from and writes to the Tokynd Assurance Graph. Status labels stay literal: Now · local v0 runs as a deterministic local simulation, Design Partner builds with partners. Nothing here is quietly GA.
Security review that ends in a merge-ready patch, not another ticket.
Agent changes merging with over-scoped tools, prompt-injection surface, and RAG permission bleed, found by an auditor or an incident instead of a reviewer.
The agent owner merges. Tokynd Pair never merges, deploys, or widens its own access.
Five scanners, one weakness, one owner, one fix.
The same CVE paged by three scanners under three IDs, owned by nobody, ageing past fix SLAs.
AppSec approves merges of critical duplicates. Suppression reasons stay auditable.
Every MCP server reviewed like code, before it holds production scope.
An MCP server quietly holding write and delete scope it never calls: the standing privilege a steered prompt turns into data loss.
Security approves every new server and every scope widening.
Identity at creation, not discovered after the incident.
Ownerless agents running on long-lived keys nobody can revoke safely, because nobody recorded what they were for.
Named owner approves scopes. Revocation never waits for a gate. Missing owner fails closed.
AI governance that produces remediation.
Governance theater: polished registers and heat maps while the same reachable weakness survives another quarter.
Named risk owner approves every tier. GRC approves every external answer.
Your diagram is the hypothesis. The API is the evidence.
Architecture risk hiding in the distance between approved design and deployed reality: stray keys, public ACLs, shadow resources.
Architecture confirms intent sources. Owners accept, fix, or time-box risk acceptance.
One approved fix testifies four times.
Audit-season archaeology: reconstructing March in November from tickets and memory, four frameworks collected four times.
GRC reviews exceptions and approves the pack before any auditor sees it.
Know the normal path. Surface the meaningful deviation.
An agent leaving its known tool path, reaching an unknown tool, or following an exfiltration instruction with no explainable deviation record.
Local trace simulation only. No live sensor, network, credentials, or latency claims.
Exercise the agent configuration before an attacker does.
A vulnerable agent configuration reaching production with nobody having exercised its instructions, tools, scopes, and exfiltration paths together.
Deterministic local configuration checks only. No model queries.
Tokynd Birthright gives every agent a birth certificate: a named owner, scoped tools, an expiry, and a kill switch. Missing owner fails closed. Try it: mint a record and watch the kind attach to the token.
This is a local simulation of the v0 record format. No credential is issued, no network is touched.
No invented customer wall, no anonymous praise, no borrowed certification badge. Tokynd Security earns proof from reproducible artifacts and design partners willing to judge the fix.
One repo, one scanner export, one named security and engineering owner. The pilot is measured on accepted patches and verified closures, not alerts generated.
Finding, proposed patch, human decision, verification result. Internal merge-rate targets stay labeled as targets until they become measured outcomes.
A public benchmark repo is planned with planted vulnerable and hardened fixtures and deterministic expected outputs. It is a plan, not a published benchmark today.
v0.4.0, 61 tests, commit 2c24c63. Every status on this page names what runs locally, what needs a design partner, and what remains roadmap.
No, deliberately. Tokynd ingests findings from the scanners and CSPM you trust, traces each to the code, IaC, agent, and owner, deduplicates them into one owned queue, drafts the PR-ready diff and PR body, and verifies closure back at the source. Keep your contracts. Tokynd closes the loop your scanners leave open.
Three rules. Agents propose and humans approve. Every action is scoped by the approved spec and a short-lived identity. Every action is logged to your audit trail and mapped to a control. Tokynd can draft a validated fix diff, tests, risk note, spec check, and PR body; merging always stays with the human owner.
The spec, capabilities, tools, data access, identity, and guardrails, is written and approved before code is generated. It becomes the contract every later stage checks against: PR review, identity provisioning, testing, and evidence. Security stops being a review at the end and becomes a property of how the system was built.
Starter mappings cover SOC 2, ISO/IEC 42001, NIST AI RMF, the EU AI Act, OWASP LLM and MCP Top 10, and CIS Benchmarks. One control is tested once and mapped where it honestly applies. Mappings are not certifications or legal determinations.
Not yet. Nine products have working local code in v0.4.0. Hosted connectors, live runtime sensing, and opening real repository PRs remain design-partner roadmap. A working session starts by inventorying agents, MCP servers, and shadow AI, curating one real queue, and drafting the first merge-ready fixes against your stack.
The build focus is AWS and Microsoft Azure, GitHub and GitLab as code systems of record, and Okta and Microsoft Entra ID for identity. Customer code, prompts, tool definitions, and data are tenant-isolated and never train models without explicit opt-in.
Published structure, no invented numbers. Final numbers publish at GA; design partners lock launch pricing. Talk to us and we will walk through what fits your shape.
Tokynd (pronounced TOH-kind) is Token + Kind. Every non-human identity, a service account, an API key, an agent, a workload, an MCP server, is a token. And every token has a kind: a classification that says who owns it, what it is allowed to do, and how long it is allowed to live.
The fastest-growing attack surface in the enterprise is not malware or phishing. It is machine-identity sprawl: tokens minted without kinds. No owner. No scope. No expiry. Credentials that outlive the projects they were created for, with permissions nobody remembers granting.
Tokynd exists to end that. We govern identity at creation: every agent is born with an identity certificate naming its owner, scope, and lifetime. We enforce least privilege by kind. And we bind every token to a lifetime: credentials that cannot expire are credentials waiting to be stolen.
A token (the ring), governed by its kind (the K), with the identity pinned at the center in amber.
What you will not find here: no shields, no padlocks, no fear. Those symbols sell anxiety. A governed identity is a quiet one.
Design partner, a question about the build, or a working session. One route in, and a human replies.
Founder on LinkedIn:
linkedin.com/in/amjdseyal
We reply to every message personally, usually within one business day.