RAP Compliance Rating
When a buyer agent must decide, among thousands of sellers, whether one is safe to buy from, it won't read a prose review — it queries a machine-readable signal: what is this party's compliance trust level? The RAP Compliance Rating is that signal. It compresses how well a payment participant satisfies the seven pillars of the RAP framework into a comparable, queryable grade.
9
Subjects tracked
6
Ratings published
2026-09-06
Last change
2026-09-06
Last recomputed
What we rate · seven dimensions
Attribution
Can we establish who is paying and which entity is accountable
Mandate & limits
Are spending boundaries enforced by a system outside the agent
Firewall
Are non-compliant payments actually stopped before settlement
AML screening
Is the counterparty screened against sanctions and risk signals
Auditability
Can what happened be reconstructed after the fact
Privacy
Is compliance achieved without over-collecting data
Interoperability
Does it work across protocols and rails rather than locking in
Grades · L0 → L3
Trustworthy
Key pillars independently verified; safe as a default counterparty
Usable
Core controls implemented; some parts await third-party verification
Limited
Identity or compliance is claimed, but enforcement is weak
Non-compliant
Structurally fails attribution; a paying agent should assess the risk before integrating
Not rated
Not yet rated, or public information is insufficient. Neither an endorsement nor a warning
Rating status · three confidence tiers
Based on the subject's public disclosures / positioning, preliminarily rated by OceanAlt. Open to response and verification.
Derived from the subject answering the RAP checklist; not independently verified.
Issued after OceanAlt or a partner (e.g. a security-audit firm) verifies the evidence.
Published ratings
Methodology →Agentic Commerce Protocol (ACP)
N/ACommerce / checkout protocol layer
Protocols and settlement rails are not graded: compliance is carried by the platforms and providers built on them; we only record how well the rail supports it.
A commerce protocol for agent checkout, maintained by OpenAI and Stripe and hosted on GitHub. The source pages do not directly document delegated payment tokens or a standardised checkout flow; the judgement that compliance and risk control rely mainly on the underlying payment institution (such as Stripe) is preliminary. The overall grade is marked N/A pending verification of scope and specification against official documentation.
Google AP2 · Agent Payments Protocol
N/AMandate / authorization protocol layer
Protocols and settlement rails are not graded: compliance is carried by the platforms and providers built on them; we only record how well the rail supports it.
Protocol layer, not a compliance entity: this assessment reflects protocol design capability only and is not a compliance grade. The protocol is relatively strong on authorization and intent, while pre-settlement compliance and AML are left open. Scores are for side-by-side reference and need human verification.
Coinbase x402
N/AThe settlement rail itself
Protocols and settlement rails are not graded: compliance is carried by the platforms and providers built on them; we only record how well the rail supports it.
As a settlement rail, x402 does not itself carry KYC/AML obligations (by design); compliance has to be added by the applications and providers built on top. It is therefore not graded as an entity and is marked N/A.
Sumsub
L2Traditional KYC/KYB/AML provider - has an agent-to-human binding product, but no agent credential or spend mandate
A long-established KYC/AML vendor that has published Know-Your-Agent material. Strong on attribution and AML; mandate and controls are not its focus. Based on public information.
Skyfire
L2Agent trust stack / KYA identity layer
Verified pillar by pillar against public documentation, the IETF draft and partner press releases (evidence collected 2026-09-05 under method v0.3; recomputed in full under the v0.4 weights on 2026-09-06, with pillar scores and grade unchanged): attribution, auditability and interoperability are sufficiently evidenced; mandate limits, pre-settlement interception, AML screening and privacy are partially evidenced; no public security certification or licence was found. The grade maps from the weighted score by the standard rule, with no human deviation.
Catena Labs
L2AI-native financial institution (platform plus a proposed national trust bank, invite-only)
Verified pillar by pillar against the official site, blog, ACK specifications and open-source repositories (evidence collected 2026-09-05). The AML pillar lacks evidence of in-house screening and is pending review; the profile is unpublished and is not shown as a complete rating card.
Compare
Pick the subjects yourself and compare pillar by pillar. There is no overall league table: ranking by total score needs a larger sample and stronger evidence levels.
| Pillar | Agentic Commerce Protocol (ACP)N/A | Google AP2 · Agent Payments ProtocolN/A |
|---|---|---|
| Attribution | 2 | 1 |
| Mandate & limits | 2 | 2 |
| Firewall | 1 | 1 |
| AML screening | 1 | 0 |
| Auditability | 2 | 2 |
| Privacy | 2 | 2 |
| Interoperability | 2 | 2 |
| Weighted | 55/100 | 42/100 |
| Status | Public info | Public info |
Get your agent / service rated
Want buyer agents to trust your service and list it in the Trusted Agent Service Registry? Self-attest for a provisional badge, or request verification for a formal rating. To see compliance enforced before settlement, try it in AI Security Lab.
See it run in AI Security Lab first →
