AI agents are entering systems built for people — and every privileged action ends at a wall designed for humans. SecondSign freezes the agent at that boundary. A human signs. The action completes — attested, audited, provable.
SecondSign turns 2FA and step-up walls from automation blockers into governance primitives. Five states, one invariant: nothing privileged happens without a human signature.
Agent reaches a privileged action. Policy demands step-up.
Execution state pauses. Ticket issued. No retries, no guessing.
Human verifies out-of-band — passkey, TOTP, push. Seconds of effort.
Short-lived elevated token. Expired in five minutes.
Signed record: who approved, what, when. Exportable. Courtroom-grade.
No 2FA seeds. No standing credentials. No long-lived tokens. Secret material never enters prompts, logs, or screenshots — by architecture, not policy.
Every privileged action resolves to a cryptographically signed human approval. SOC 2, EU AI Act, DORA — the audit trail is the product.
MCP-native: OpenCode, Claude Desktop, LangChain, your harness. Local-first and air-gap compatible. Enterprise control plane when you're ready.
SecondSign implements the identity stack your security team reviews today — no proprietary black boxes, no scraping, no bypassing.
SecondSign operates exclusively on systems you own, operate, or are contractually authorized to automate. Legacy session replay is disabled by default and gated behind explicit, auditable configuration. Targets you don't control are out of scope — in writing, by design.