For enterprises and platform teams

Managed governance for AI agents, partners and customers.

Give AI agents, partner systems and customer portals governed access to your data โ€” under identity, rights and policy that comply with the EU Data Act. We run the authorization layer end-to-end.

The problem we solve

Your AI agents need data โ€” but they need identity and rights, not raw access.

Your partners need data exchange โ€” but EU Data Act requires governed consent and audit.

Your customers expect data sovereignty โ€” and your platform team needs to deliver it.

Your IAM stack handles humans โ€” not AI agents, not partner systems, not credential flows.

What's in the enterprise managed service

AI agent authorization

MCP + OID4VCI authorization layer. AI agents act with verified identity, defined rights and full audit trail โ€” not raw access.

Partner & customer credential issuance

Certified credentials for partners, systems and customer portals. SD-JWT โ€” privacy-preserving and selectively shareable.

EU Data Act managed compliance

Consent, access rights, governance and audit. Designed to satisfy EU Data Act requirements in force since September 2025.

Integration with your existing stack

Your IAM, your LLM platforms, your data products. We add the authorization and credential layer; we don't replace your identity stack.

Where this applies

A large enterprise deploys LLM agents internally

The agents need access to product data, customer records and partner systems. Without an authorization layer, agents either get over-broad access (compliance risk) or constant friction (productivity loss). Protium provides per-agent credentials, scoped data rights and an audit trail per agent action.

A platform business shares data with hundreds of partners

Each partner needs different access scopes, different consent terms and verifiable identity. Protium issues verifiable credentials per partner, runs the consent flow and provides the audit trail โ€” under EU Data Act-compliant governance.

A customer-facing platform offers verifiable data sharing

Customers want control over what data flows where. Protium provides the credential issuance, the consent UX and the audit layer that turns "we promise you control" into "you can verify it."

Built on certified infrastructure

Certifications

iSHARE v3 certified ยท EUDI Wallet ARF v1.5+ ready ยท OID4VCI ยท SD-JWT ยท MCP-compatible ยท EU Data Act compliant

IP position

100% Protium IP on the Participant Credential Issuer (PR v3) and Authorization Registry. The PR base code comes from iSHARE Foundation as open source (AGPL 3.0). The Ozone platform is proprietary Protium IP.

Deployment posture

EU-only deployment. Multi-tenant by design. Production-grade operations. Audit-ready.

Trusted by organisations including

EquinixRabobankFrieslandCampinaMid Europa PartnersAbu Dhabi MunicipalityRoyal LemkesVan Dorp InstallatiesDutch Green Building CouncilHeijmansStedinSensaraSprimoGlassKoppertiSHAREIRTEnecoEnnatuurlijkStagemanQualogyvhp2020HoneywellApatorKloosterboerBR8De HaanRolandINCEKrampGemeente UtrechtGlobal M2M AssociationKOREPortXLDura VermeerDen HartoghTataMCS

Selected organisations Protium has worked with since 2014. Public case studies available on request.

Buyer questions, answered

Does this replace our IAM?+

No. We add the authorization and credential layer on top of your existing IAM (Azure AD, Okta, Ping, etc.).

How does this work with MCP?+

We provide the OID4VCI-based authorization that sits above MCP connections. AI agents get verifiable credentials before they call MCP servers.

Is this GDPR-compatible?+

Yes. Designed for EU Data Act and GDPR. We operate as data processor by default; specific arrangements confirmed per deployment.

What does the EU Data Act actually require here?+

In force since September 2025. Requires verifiable identity, defined data access rights, consent management and audit for data-sharing relationships. Our stack is built around exactly those primitives.

Can we deploy this in our own cloud?+

Standard deployment is managed by Protium in EU sovereign cloud. Customer-cloud deployment options are discussed in architecture review.

Ready to govern AI and data access as a managed service?