ZeroProof

Cryptographic Identity Binding for LLM API Security

Drop-in SDK for any LLM app

Add cryptographic security in 3 lines

ZeroProof wraps your existing LLM calls. No architecture changes. Every prompt gets a hardware-signed proof — tamper, replay, and injection attempts are blocked before they reach your model.

Before ZeroProof — unprotected
// Any attacker can intercept & modify this
const response = await openai.chat
  .completions.create({
    messages: [{
      role: 'user',
      content: prompt   // ← unverified, unsigned
    }]
  })
After ZeroProof — cryptographically secured
import { ZeroProof } from 'zeroproof-sdk'
const zp = new ZeroProof({ baseUrl: YOUR_SERVER })

// 1. Register once — stores keypair in Secure Enclave
await zp.register(userId)

// 2. Sign + verify prompt with Touch ID (one call)
const { ok, prompt } = await zp.signAndVerify(
  userId, userMessage, sessionId
)
if (!ok) return unauthorized()

// 3. Safe to call your LLM — prompt is verified
const response = await openai.chat
  .completions.create({
    messages: [{ role: 'user', content: prompt }]
  })
🔑
Register Once
Hardware keypair generated in Secure Enclave. Private key never leaves device.
✍️
Sign Every Prompt
SHA-256 hash signed by Touch ID. Any in-transit modification breaks the signature.
🛡️
Verify on Server
Re-hash, check signature, consume nonce, validate capabilities. All before LLM sees it.
🤖
Safe LLM Call
Cryptographic proof that this exact prompt, from this exact user, with these exact permissions.
npm install zeroproof-sdk
Works with OpenAI, Anthropic, Groq, Gemini — any LLM
1. Register→2. Grant Capabilities→3. Demo

Register Your Device

ZeroProof uses WebAuthn (FIDO2) to bind your identity to a hardware key in your device's Secure Enclave. The private key never leaves your device.

What happens:

→ Your device generates a keypair in hardware (Secure Enclave)

→ The public key is stored on the server

→ You sign exactly which capabilities AI agents are allowed to use

→ Any agent action outside that signed list is blocked — regardless of what the AI decides