RAIDA: Redundant Array of Independent Detection Agents

Authentication infrastructure for the AI era.

Seven applications of RAIDA storage and file transport to problems the AI industry created and cannot currently solve.

AI created millions of digital actors and digital objects that nobody can verify. RAIDA verifies them.

The opening

Every AI security incident of the past two years reduces to the same two questions. Who made this thing, and has it been altered? And: this actor holds a credential, but should it be allowed to act right now?

Poisoned model weights on public hubs. Coding agents with repository credentials pushing compromised commits at machine speed. Malware written specifically to harvest AI CLI tokens off developer machines. Training corpora of unprovable origin. In each case the defenses failed the same way: they authenticated a party, then trusted everything that party produced.

RAIDA authenticates objects, not parties — across 25 independent clouds, with no central issuer to compromise and no ledger to reconcile. That is the property the AI supply chain is missing.

Provenance
Borrowed from the art world, where an artwork's provenance is the documented chain of custody that proves it genuine. In digital terms: where did this file come from, who made it, and has it changed since. Today the honest answer for nearly everything on the internet is that we do not know — we trust the hub, the registry, the platform. Provenance means the object carries its own proof, so the middleman does not have to be trusted.
Why RAIDA
Proving a file is the genuine, unaltered original is the same operation as proving a coin is not counterfeit. We already built that.

Seven applications

01

Agent Identity & Authority Tokens

We need to give our AI a debit card instead of the company checkbook.

RAIDA RAIDA issues single-use authority tokens that each agent spends one action at a time — a push, a pull, a transfer — so a stolen credential store is worthless, because spent tokens are dead and nothing replays.

The s1ngularity-class attacks harvested AI CLI credentials off developer machines, then used the agents' own permissions to exfiltrate. A static key is a checkbook; it does not expire when it is copied.

02

Model & Weight Authentication

We need to know the AI model we downloaded is the one the maker actually built.

RAIDA Every checkpoint or adapter carries a RAIDA authenticator bound to its contents, which the runtime verifies against the 25 clouds in milliseconds before loading — so a tampered re-upload cannot produce a valid token, because forging one requires defeating the quorum.

Thousands of models on public hubs shipped with executable payloads embedded in their serialization format. Nobody could prove a downloaded file was the one the publisher built.

03

Machine-to-Machine Payments

We need to let AIs pay each other, instantly, for pennies.

RAIDA RAIDA authenticates value without a ledger to reconcile or a block to wait for, which is what makes sub-cent, high-frequency settlement between agents viable where card rails fail on cost and blockchains fail on latency.

Agents already buy compute, API calls and data from each other with no human in the loop. The volume is machine-scale; the ticket size is fractions of a cent.

04

Provenance for Code Commits and Artifacts

When an AI breaks something, we need to know exactly what it touched.

RAIDA Each commit, container image and build artifact carries an authenticator naming which agent produced it under whose authority and when, verifiable without trusting the platform, the CI vendor or a certificate authority — so the post-incident blast radius is a query, not an investigation.

Signing keys did not help: the compromised agents legitimately held them. Today, determining which artifacts came from a breached agent takes weeks and ends in a guess.

05

QMail as Agent-to-Agent Transport

We need to stop strangers from giving orders to our AI.

RAIDA QMail carries proof of origin inside the message itself, letting an agent enforce a hard rule — act only on instructions bearing a valid authenticator from a recognized authority — which turns prompt injection from a judgement call into a structural impossibility.

Prompt injection works because an agent cannot distinguish trusted instructions from attacker text that arrived in its context. It remains the industry's leading unsolved AI security problem.

06

Training Data Provenance & Licensing

We need to prove our AI was not trained on stolen data — and pay the people whose data we did use.

RAIDA Datasets and individual records carry authenticators establishing origin and license terms that cannot be claimed twice, giving both a defensible audit trail for training corpora and a settlement rail to compensate rights holders per use.

Copyright exposure is an existential legal risk for every frontier lab, and creators have no mechanism to be paid for training use. Same non-duplication property as environmental credits, far larger market.

07

AI Output Watermarking & Deepfake Provenance

We need to tell real from fake with a lookup, not a guess.

RAIDA Generated images, video and documents receive a RAIDA authenticator at the moment of creation, making verification a network lookup rather than forensic analysis of the pixels — the outcome C2PA pursues with certificate chains, delivered without the certificate authority.

Detection models are in a losing arms race with generation models. Provenance at creation does not degrade as generators improve.

AI gave every enterprise thousands of non-human actors with credentials and no accountability. RAIDA is authentication infrastructure built for objects, not people — which is what we need when the actor is a machine.

The one-line version