For enterprises and platform teams
Managed governance for AI agents, partners and customers.
Verifiable access decisions for AI agents, partner systems and customer portals — added as a managed layer, without replacing your IAM. Every decision carries identity, defined rights and an audit trail you can hand to your DPO.
The problem we solve
Your AI agents need data — but they need identity and rights, not raw access.
Your partners need data exchange — and the EU Data Act obliges you to grant access under documented, fair terms you can evidence.
Your customers expect data sovereignty — and your platform team needs to deliver it.
Your IAM stack handles humans — not AI agents, not partner systems, not credential flows.
What's in the enterprise managed service
AI agent authorization
MCP + OID4VCI authorization layer. AI agents act with verified identity, defined rights and full audit trail — not raw access.
Partner & customer credential issuance
Certified credentials for partners, systems and customer portals. SD-JWT — privacy-preserving and selectively shareable.
Data Act governance and evidence
Recorded access rights, documented usage terms and audit trails that make the EU Data Act obligations — applying since 12 September 2025 — operational and provable. The mapping to your specific obligations happens in the architecture review.
Integration with your existing stack
Your IAM, your LLM platforms, your data products. We add the authorization and credential layer; we don't replace your identity stack.
Direct, or through your partner
Many enterprises reach this service through their telco or platform partner — where a partner operates your trust service, Protium runs behind that brand. Where none is available, we engage directly and can include a future partner route in the architecture plan. The stack and the operations are the same either way.
Where this applies
A large enterprise deploys LLM agents internally
The agents need access to product data, customer records and partner systems. Without an authorization layer, agents either get over-broad access (compliance risk) or constant friction (productivity loss). Protium provides per-agent credentials, scoped data rights and an audit trail per agent action.
A platform business shares data with hundreds of partners
Each partner needs different access scopes, different usage terms and verifiable identity. Protium issues verifiable credentials per partner, runs the agreement flow and provides the audit trail — the documented terms and evidence the EU Data Act expects.
A customer-facing platform offers verifiable data sharing
Customers want control over what data flows where. Protium provides the credential issuance, the consent UX and the audit layer that turns "we promise you control" into "you can verify it."
Built on certified infrastructure
Certifications
iSHARE v3 Participant Credential Issuer and Authorization Registry. Certification scope and current status are included in the due-diligence evidence pack.
IP position
100% Protium IP on the Participant Credential Issuer (PR v3) and Authorization Registry. The PR base code comes from iSHARE Foundation as open source (AGPL 3.0). The Ozone platform is proprietary Protium IP.
Deployment posture
EU deployment, tenant-level separation and documented operating procedures. Region, SLA and audit evidence are agreed per deployment.
Operational evidence
Operating since 2014
Experience across enterprise data sharing, trust frameworks and regulated ecosystems has been converted into reusable platform and operating playbooks.
iSHARE evidence available
Certification scope, conformance evidence and the current service status are available during architecture and compliance review.
References with context
Relevant project references are shared with the role, scope and delivery period clearly stated. Customer names are only published with permission.
Buyer questions, answered
Does this replace our IAM?+
No. We add the authorization and credential layer on top of your existing IAM (Azure AD, Okta, Ping, etc.).
How does this work with MCP?+
We provide the OID4VCI-based authorization that sits above MCP connections. AI agents get verifiable credentials before they call MCP servers.
Is this GDPR-compatible?+
Yes. Designed for EU Data Act and GDPR. We operate as data processor by default; specific arrangements confirmed per deployment.
What does the EU Data Act actually require here?+
The Data Act applies since 12 September 2025. It gives users of connected products rights to their data and obliges data holders to share it under fair, documented terms. It does not prescribe a technology — but meeting it in practice means you can show who received access, under which terms, and on what basis. That is what our identity, rights and audit layer makes operational.
Does this help with the AI Act?+
It provides the accountability groundwork: per-agent identity, scoped rights and a retained log of every access decision — relevant to the logging and oversight obligations that phase in through December 2027. An authorization layer does not make an AI system AI Act-compliant by itself, and we will not claim otherwise.
Can we deploy this in our own cloud?+
Standard deployment is managed by Protium in EU sovereign cloud. Customer-cloud deployment options are discussed in architecture review.