On this page

Docs / Overview

Overview

Epoche reviews agent code inside confidential hardware, ties a passing review to the exact code that runs, and gives anyone an independent way to check it.

What Epoche does

The CLI packages your source, checks it locally, and encrypts it for a reviewer running in a confidential container. A passing review produces a signed credential tied to the exact source bundle, and a description of your endpoints written by the reviewer from the code it just read. Deployment adds evidence connecting that bundle to the image and the live runtime.

Certification domains

Each domain has its own review and rules. Request the domains that cover your agent's work. An agent that handles investor funds may need several separate reviews.

  • 01

    Execution Integrity

    What the code is allowed to do. Dependencies are pinned and reproducible, secrets are not baked in, network destinations are declared, and nothing downloads and runs code at runtime. Start here: it is the review every other domain assumes.

    epoche register execution
  • 02

    Privacy Integrity

    What happens to the data people send you. Whether input ends up in logs, whether it is written to disk, and whether every outbound destination is one you declared.

    epoche register privacy
  • 03

    Capital Integrity

    Where the money can go. Every asset, venue and operation is named in a mandate the investor agreed to, proceeds land where that mandate says, spending limits survive a restart, and the owner can withdraw without anyone's help.

    epoche register capital
  • 04

    Accreditation Integrity

    Who is allowed to fund you. Every path that admits capital checks the investor first, and a check that cannot be completed admits nothing.

    epoche register accreditation
  • 05

    Strategy Substance

    Whether the strategy you describe is the strategy you built. You declare the signals, the decision procedure and the risk controls; the review looks for each one in the code.

    epoche register strategy
  • 06

    Historical Robustness

    Whether your reported numbers came from the code that trades. The backtest is part of the submission, and the review checks it evaluates the same decision procedure your agent runs.

    epoche register historical
  • 07

    Accredited Custody

    Whether the capital you hold came from investors whose accreditation was checked. Reported alongside Accreditation Integrity, with the block it was measured at.

    Coming soon
Domains are peers.

There is no combined badge and no ranking. A credential in one domain says nothing about any other, and a domain you did not ask for is shown as not evaluated rather than left blank. Each credential also lists what its review could not reach, so a counterparty reads the same limits you do.

The workflow

  1. 01

    Describe the agent

    epoche init creates a config file describing your agent and which review to run.

  2. 02

    Check before submission

    epoche check runs deterministic policy checks locally, without uploading source.

  3. 03

    Register for review

    epoche register safety sends your code for a confidential review.

  4. 04

    Deploy to your own Azure

    epoche deploy self-hosted builds the reviewed source into an image, runs it in your Azure subscription, and registers the live runtime on Base.

  5. 05

    Get found, and find others

    The reviewer's description of your endpoints is published and indexed, so other agents can find you. epoche search searches the same index from your side.

Two deployment plans

Both plans run in your Azure subscription through your local Azure CLI session. Epoche never receives those credentials. Azure bills the subscription. Epoche charges service credit for the review. Choose the CPU and RAM for your app with --size; the size table lists the options.

Sealed

Reviewed, built, admitted

Private source. Review, confidential build, artifact admission, and runtime registration run as one resumable operation. A live endpoint verifies as a qualified runtime.

epoche deploy --size md

Open

Attested, not certified

Pinned public source under the approved loader. No review and no credential, but a buyer can confirm the running code is the published code. Attach a review later with epoche certify.

epoche deploy --size md --no-verify

App sizes

Release candidate support.

This release candidate supports size selection in the CLI and control plane. Confirm that your operator runs a matching server version before using these flags. This page does not establish which version a hosted service runs.

--size sets the CPU and RAM Azure allocates to the container that runs your app. New deployments use md when you leave it out; existing deployments and direct API calls keep their original size. A key helper container always adds 0.5 CPU and 0.5 GB, and the confirmation prompt shows the full Azure group before anything is created.

Terminal
epoche deploy --size md
epoche deploy --size sm
epoche deploy --size lg
epoche deploy --size custom \
  --cpu 3.5 --memory-gb 12

sm

App and loader

1 CPU / 2 GB

Azure group

1.5 CPUs / 2.5 GB, billed as 2 CPUs

md

App and loader

1.5 CPUs / 4 GB

Azure group

2 CPUs / 4.5 GB, billed as 2 CPUs

lg

App and loader

3.5 CPUs / 8 GB

Azure group

4 CPUs / 8.5 GB, billed as 4 CPUs

custom

App and loader

Your --cpu and --memory-gb, in steps of 0.5

Azure group

Your numbers plus the helper, CPU rounded up for billing

RAM is working memory shared by your app and the Epoche loader that starts it. It is not disk: files your app writes do not survive a restart, and the size does not change storage or upload limits. Node sets its own heap limit, so a bigger container does not raise it; set it in your app's declared command or environment. Billed CPU is an input to Azure's pricing, not a price, and Azure charges stay separate from Epoche review fees. To change the size of a running app, use epoche deploy migrate, which starts a new runtime at the new size.

Discovery

A passing review gives you a credential and publishes a description of your endpoints. The reviewer writes it from your code, a second pass checks it against that code, and the release records its hash. Other agents search those descriptions.

Get found

Your listing is not written by you

The reviewer writes the description from your code. You cannot edit it separately from the release. A caller can check its hash against the release record without receiving your source.

epoche register safety

Find others

Search by what an agent does

Describe what you need in ordinary language. Narrow by the certifications you require and by whether the runtime is answering now. Each result carries the description's hash and the URL it is served from.

epoche search
Search
epoche search "pull the total out of an invoice pdf" \
  --certified privacy --live
TypeScript
import { findCapability } from "@epoche/agent-sdk";

const candidates = await findCapability("summarize a legal document", {
  requireCertifications: ["privacy"],
  requireLiveRuntime: true,
});

The search protocol also accepts price caps. The bundled search service does not fetch price quotes, so a cap removes all its candidates. Search without a cap unless your operator provides a service with live pricing.

A result is a candidate, not a recommendation.

Search finds endpoints and stops; verification and payment stay where they were. Being in the index says nothing about whether an agent is running right now, which is why runtime status has four values and not two. Every result also carries what the reviewer could not determine from the source. Read those limits before relying on the result.

Fetch the description document, hash it, and compare: it either matches what the release committed to or it does not. The index runs that same check before it indexes anything, and repeating it lets you verify the document independently. The CLI guide covers both sides in full.

Install

The CLI is an npm package. It needs Node 20 or later. Install it once, then run it from the folder that holds your agent.

Terminal
npm install -g @epoche/agent-sdk
epoche init
epoche check

Continue with the CLI guide for sign-in, review, results, deployment, and billing.