OceanAltOceanAlt

RAP Compliance Rating

The trust layer for agent commerce · a purchase-decision signal for buyer agents

When a buyer agent must decide, among thousands of sellers, whether one is safe to buy from, it won't read a prose review — it queries a machine-readable signal: what is this party's compliance trust level? The RAP Compliance Rating is that signal. It compresses how well a payment participant satisfies the seven pillars of the RAP framework into a comparable, queryable grade.

9

Subjects tracked

including unpublished

6

Ratings published

publicly visible

2026-09-06

Last change

grade adjustment

2026-09-06

Last recomputed

method v0.4

Methodology: indicators, weights, evidence levels, review, appeals and conflicts of interest →

What we rate · seven dimensions

Attribution

weight 25

Can we establish who is paying and which entity is accountable

Mandate & limits

weight 20

Are spending boundaries enforced by a system outside the agent

Firewall

weight 20

Are non-compliant payments actually stopped before settlement

AML screening

weight 15

Is the counterparty screened against sanctions and risk signals

Auditability

weight 10

Can what happened be reconstructed after the fact

Privacy

weight 5

Is compliance achieved without over-collecting data

Interoperability

weight 5

Does it work across protocols and rails rather than locking in

Grades · L0 → L3

Grades map from the weighted score by one rule: ≥85 L3 / ≥65 L2 / ≥40 L1 / otherwise L0. NR = not rated or insufficient evidence; N/A = the subject type is not graded.

L3

Trustworthy

≥ 85

Key pillars independently verified; safe as a default counterparty

L2

Usable

≥ 65

Core controls implemented; some parts await third-party verification

L1

Limited

≥ 40

Identity or compliance is claimed, but enforcement is weak

L0

Non-compliant

< 40

Structurally fails attribution; a paying agent should assess the risk before integrating

NR

Not rated

Not yet rated, or public information is insufficient. Neither an endorsement nor a warning

Rating status · three confidence tiers

Public-info assessment

Based on the subject's public disclosures / positioning, preliminarily rated by OceanAlt. Open to response and verification.

Self-attested

Derived from the subject answering the RAP checklist; not independently verified.

Verified

Issued after OceanAlt or a partner (e.g. a security-audit firm) verifies the evidence.

Published ratings

Methodology →

Agentic Commerce Protocol (ACP)

N/APublic informationWeighted 55/100

Commerce / checkout protocol layer

Protocols and settlement rails are not graded: compliance is carried by the platforms and providers built on them; we only record how well the rail supports it.

A commerce protocol for agent checkout, maintained by OpenAI and Stripe and hosted on GitHub. The source pages do not directly document delegated payment tokens or a standardised checkout flow; the judgement that compliance and risk control rely mainly on the underlying payment institution (such as Stripe) is preliminary. The overall grade is marked N/A pending verification of scope and specification against official documentation.

Evidence cutoff / last verified: 2026-08-19

Full profile — gaps, evidence, history →

Google AP2 · Agent Payments Protocol

N/APublic informationWeighted 42/100

Mandate / authorization protocol layer

Protocols and settlement rails are not graded: compliance is carried by the platforms and providers built on them; we only record how well the rail supports it.

Protocol layer, not a compliance entity: this assessment reflects protocol design capability only and is not a compliance grade. The protocol is relatively strong on authorization and intent, while pre-settlement compliance and AML are left open. Scores are for side-by-side reference and need human verification.

Evidence cutoff / last verified: 2026-08-04

Full profile — gaps, evidence, history →

Coinbase x402

N/APublic informationWeighted 10/100

The settlement rail itself

Protocols and settlement rails are not graded: compliance is carried by the platforms and providers built on them; we only record how well the rail supports it.

As a settlement rail, x402 does not itself carry KYC/AML obligations (by design); compliance has to be added by the applications and providers built on top. It is therefore not graded as an entity and is marked N/A.

Evidence cutoff / last verified: 2026-08-04

Full profile — gaps, evidence, history →

Sumsub

L2Public informationWeighted 65/100

Traditional KYC/KYB/AML provider - has an agent-to-human binding product, but no agent credential or spend mandate

A long-established KYC/AML vendor that has published Know-Your-Agent material. Strong on attribution and AML; mandate and controls are not its focus. Based on public information.

Evidence cutoff / last verified: 2026-09-05

Full profile — gaps, evidence, history →

Skyfire

L2Public informationWeighted 67/100

Agent trust stack / KYA identity layer

Verified pillar by pillar against public documentation, the IETF draft and partner press releases (evidence collected 2026-09-05 under method v0.3; recomputed in full under the v0.4 weights on 2026-09-06, with pillar scores and grade unchanged): attribution, auditability and interoperability are sufficiently evidenced; mandate limits, pre-settlement interception, AML screening and privacy are partially evidenced; no public security certification or licence was found. The grade maps from the weighted score by the standard rule, with no human deviation.

Evidence cutoff / last verified: 2026-09-05

Full profile — gaps, evidence, history →

Catena Labs

L2Public informationWeighted 75/100

AI-native financial institution (platform plus a proposed national trust bank, invite-only)

Verified pillar by pillar against the official site, blog, ACK specifications and open-source repositories (evidence collected 2026-09-05). The AML pillar lacks evidence of in-house screening and is pending review; the profile is unpublished and is not shown as a complete rating card.

Evidence cutoff / last verified: 2026-09-05

Full profile — gaps, evidence, history →

Compare

Pick the subjects yourself and compare pillar by pillar. There is no overall league table: ranking by total score needs a larger sample and stronger evidence levels.

Compare up to three at a time; picking a fourth replaces the oldest.

PillarAgentic Commerce Protocol (ACP)N/AGoogle AP2 · Agent Payments ProtocolN/A
Attribution2521
Mandate & limits2022
Firewall2011
AML screening1510
Auditability1022
Privacy522
Interoperability522
Weighted55/10042/100
StatusPublic infoPublic info

Get your agent / service rated

Want buyer agents to trust your service and list it in the Trusted Agent Service Registry? Self-attest for a provisional badge, or request verification for a formal rating. To see compliance enforced before settlement, try it in AI Security Lab.

See it run in AI Security Lab first →

Methodology is open and versioned. The evidence cutoff is shown on each subject's own card above and differs by subject. Ratings are preliminary, do not constitute legal, compliance or investment advice, and are not a final verdict on any party; subjects may respond and request verification. RAP Compliance Rating v0.4, recomputed in full on 2026-09-06.