Rootwall

This is the AI era, and we noticed. The whole of this site is plain text on purpose, ready to be consumed by your own AI assistant.

Start by asking it this:

Read https://rootwall.ai/llms-full.txt and tell me what Rootwall is and how it can help me with cybersecurity.

Or open it straight in one of these:

If you would rather read it yourself, continue below.

Rootwall is Internet for Business: the company connecting to you is made accountable.

When another company connects to your API, you are the only one defending the connection. What if the company on the other end defended it with you?

Today it has no reason to. The company calling your API carries none of the cost when its own weakness arrives through the connection — which is what a supply chain attack is.

Rootwall changes who pays. A member that breaks a rule owes a sum fixed before anything went wrong, to the member it harmed. Once that is true, the company calling you has its own money riding on its own security, and it hardens itself without being asked.

That is the whole change. The company on the other end stops being something you defend against and becomes part of what defends you.

Nothing is taken off your side of it. You do not defend less — the other end starts defending too. The two add up; they are not rebalanced.

Someone’s agent just called your API. What happens to them if it misbehaves?

Rootwall is a membership scheme for the traffic between two named companies. The party calling your API is admitted against a published standard, accepts rules it can read in advance, and carries a consequence fixed before anything goes wrong. Every session is recorded and signed independently by both sides, which is what makes that consequence enforceable rather than promised.

In one minute

  1. The problem. Third parties call your API every day. If one of them misbehaves you can block it — and nothing else happens to it. No standard it was admitted against, no consequence it agreed to, no warning to the next company it calls.
  2. What you get on an ordinary day. Two independently signed accounts of the same session that agree — a matched pair. Proof the call happened, under a named delegation, inside a declared scope, and that both sides said so at the time.
  3. What you get on the day it goes wrong. The two accounts disagree, both parties are put on notice, and a consequence published in advance attaches to whoever broke a rule — paid to the company that was harmed, never to Rootwall.
  4. What the rules look like. Not abstract — here is a worked example of a scope class: which operations a caller may attempt, the ceilings, and what each breach costs.
  5. What it costs. $6,000 a year if you own the API. $1,000 if your agents call one. The whole schedule is published.

The first member in a sector writes the standard

The rulebook is generic by design. Every clause reads the same for any member in any industry — that is what makes an admission portable instead of bilateral.

Two things cannot be generic. The scope class for your interface: which method kinds a caller may use, the ceilings on them, what has to be asserted about every session. And the sums that attach to it.

Those are written with the first member in a sector. Once written they are published — and every company admitted after you is held to them.

The first company through does not get a discount. It gets to decide what the rules say.

Founding members are named on the register and credited on the standard they helped write, if they want to be. It is available once per sector, and it is not available again.

The matched pair

Most sessions are uneventful. The scheme’s ordinary output is not an alarm — it is a pair of records that agree.

Each time two members’ systems talk, both sides independently send a short signed statement: who called, under whose delegation, against which scope, with what outcome. A few hundred bytes. Never the contents of the message.

Where the two agree, the agreement is the record — signed by the other party, at the time, before anyone knew it would be needed.

Your logs are yours. Theirs are theirs. Neither is evidence against the other, and both were written by a party with an interest in what they say.

A matched pair is what you hand a customer, a regulator, an insurer or a counterparty’s lawyer — and it exists for the ninety-nine sessions in a hundred where the answer is exactly what it was supposed to be.

Why nobody has this

Every partner programme we have read has a gate. None of them has a record.

That is a count, not an impression. We opened the developer documentation, partner directories and published terms of roughly a hundred UK and EU platforms. Almost all decide who gets in. Seven publish a partner rulebook, and they are good documents written by lawyers. Not one holds a record of what a third party actually did. The furthest anyone goes is a right to inspect, exercised once there is already a reason to look.

The survey is published in full — every document quoted, linked, and archived on the day it was read.

An approval says the software was acceptable once. It does not say what it did on Tuesday, under whose authority, or whether that was inside what it was approved for.

What it is not

  1. Not identity. Web Bot Auth, MCP-I, SPIFFE and the rest are a crowded field. Rootwall consumes them and builds none of them. The gap is one layer up: accreditation and enforcement.
  2. Not a gateway or an API security product. You have those. The argument is not that you cannot block a bad agent — it is that nothing happens to the party that sent it.
  3. Not a barrier. Admission does not stop a member breaking a rule, and nothing here is sealed. What changes is that the party on the other end has something to lose: the breach is recorded, attributed and costly. It also does not see what your own defences stop below the published ceiling — a limitation stated in the rulebook rather than left to be found.
  4. Not anomaly detection. Scope is declared in advance, so a deviation is arithmetic, not a judgement about whether behaviour looks unusual. No model, no baseline, no alert nobody trusts.
  5. Not arbitration or insurance. Rootwall rules on whether a rule was broken and takes no position on loss. Recovery stays between the two companies, with the signed records available to both.

Rootwall allocates loss and caps blast radius. It does not detect all misuse, and it does not make an operator accountable where no rule was broken.

What it costs

$6,000 a year if you own the API. $1,000 a year if your agents call one. Plus $350 to join, either side, covering entry and exit, and $1,200 for each scope class assessment on the calling side.

Nothing is ever paid to Rootwall for breaking a rule. Where a sum is payable it goes to the member that was harmed — and the rulebook forbids any such sum reaching the scheme, and forbids that clause being amended.

The full schedule of fees.

Read the rulebook

Published in full. Not behind a form, not behind a meeting. Or start with the common questions.

If this is your problem, say so. One line to info@rootwall.ai — no form, nothing to prepare, nothing to install, nothing to sign.