Start with one consequential workflow.
Use PEAC freely. Engage Originary when a customer, partner, auditor, or incident reviewer needs evidence your existing logs cannot provide.
A pilot usually means one API, MCP server, gateway, payment flow, or agent handoff; one signed-record profile; one verifier report or bundle; one integration review; and one rollout recommendation.
You should contact us if another party already asked for verification your logs cannot provide.
Apache-2.0
PEAC Protocol
PEAC Protocol, self-hosted verification, open-source packages, and conformant implementations remain free and portable.
Originary Verify
A scoped verification pilot, deployment and integration support, and help assembling portable record bundles for teams moving one workflow into production.
Originary Verify and implementation support
Scoped pilots and deployment support for self-hosted verification
For teams that need help issuing and verifying signed records in a specific production workflow. If another party has already asked for verification your logs cannot provide, this is the right path.
Best fit: API platforms handling agent traffic, MCP server operators, gateway and agent-infrastructure teams, and security or engineering reviewers.
Not the right fit yet: If you are still evaluating, start with the open-source packages. They are free and unlimited.
Discuss a pilotOriginary Verification Pilot
A fixed-scope engagement that instruments one production workflow end to end. Scoped quote.
- One production workflow
- One signed-record profile
- One issuer and key model
- One verifier or evidence bundle
- Integration and threat-boundary review
- Deployment recommendation
- Duration
- Fixed and agreed in writing before work begins. The scope above is what the pilot covers for that period.
- Your side
- Access to the one workflow, a technical contact, and someone who can sign off on acceptance.
- Deliverables
- A working issuing and verification path for that workflow, an integration and threat-boundary review, and a written deployment recommendation.
- Acceptance
- Records issue from the workflow and verify offline against a key you supply, and a third party can open the resulting bundle.
- Deployment ownership
- It runs in your infrastructure and you hold the keys, during the pilot and after it.
- After completion
- The implementation is yours to run. Continued support applies only under a separate written agreement.
- Not included
- Hosted verification, key custody, record storage, production on-call, and changes to systems outside the agreed workflow.
Two ways to deploy
| OSS only | With Originary support | |
|---|---|---|
| Price | No software license fee | Custom, scoped |
| License | Apache-2.0 | Apache-2.0 + support terms |
| Signing keys | Self-managed | Self-managed, with setup guidance |
| Deployment | Self-hosted | Self-hosted, with guidance |
| Verification | Offline, no dependency | Offline, no dependency |
| Support | GitHub issues | Direct engineering during the engagement |
| Record exports | Self-assembled | Assembly guidance |
| Architecture review | Community docs | Guided integration review |
Common questions
Can I self-host everything?+
Yes. PEAC Protocol and all core packages are Apache-2.0 licensed and free to self-host. Verification does not require Originary to be online. No data is sent to any Originary service.
Is the protocol truly open?+
Yes. The protocol specification, all reference implementations, and core tooling are published on GitHub under Apache-2.0. You can build your own conformant implementation without an Originary account or managed service.
What payment rails are supported?+
PEAC is rail-neutral. It produces verifiable records of interactions, not payment mandates. HTTP 402 adapters are available for teams that need challenge/response payment flows.
Who should contact you about Originary implementation support?+
API platform teams, MCP server operators, gateway and agent-infrastructure teams, and security or engineering reviewers who need help issuing and verifying signed records in a specific production workflow.
The protocol stays open.
The protocol specification, reference implementations, and all core tooling are Apache-2.0 licensed. Originary provides commercial tools and support around the open protocol.