ZeroDriveX Axiomatic Runtime is software that evaluates AI agent actions before execution and enforces trusted runtime policy before side effects occur.
ZeroDriveX Axiomatic Runtime is a provider-independent execution-control service for AI agent systems. It evaluates each proposed action before execution and produces a deterministic RETAIN, GATE, or PRUNE decision according to trusted runtime policy. This gives operators a control point between model output and consequential side effects.
The runtime is designed for agent workflows that can invoke shell commands, repository operations, external APIs, publication actions, infrastructure changes, or custom tools. Authority, deployment scope, destination, and policy are supplied by the trusted host rather than by model-controlled content. Signed Ed25519 decision envelopes bind the approved action, runtime release identity, audience, profile, validity window, and execution nonce so adapters can verify exactly what is authorized.
Actions requiring additional authority can be held behind a separately signed approval artifact using a distinct approval key role. Execution adapters verify the decision and approval artifacts, recompute the canonical action hash, and create a consume-once claim before execution. For distributed deployments, the included DynamoDB claim backend uses conditional writes and strongly consistent reads so replay attempts fail closed and uncertain post-claim outcomes are surfaced as unknown instead of being automatically retried.
Axiomatic Runtime is model-provider independent and can be integrated with single-agent applications, multi-agent orchestrators, queued workers, scheduled jobs, webhook processors, ECS services, EKS workloads, and custom execution adapters. Deployment signing keys remain customer controlled. The qualified container ships as a non-root minimal image and includes the runtime, verifier, approval utility, key-generation utility, and execution adapter.
Highlights
Deterministic pre-execution decisions retain, gate, or prune agent-requested actions before side effects occur.
Ed25519-signed decision envelopes and separate signed approvals bind execution authority to the exact canonical action.
Consume-once execution claims and a DynamoDB backend provide replay-resistant enforcement for distributed deployments.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy one system license for a single deployed agentic system. This is a one-time purchase billed per unit, not a recurring subscription. Each license covers one agentic system, so you add licenses as you deploy more systems. The license applies execution control across the consequential action paths of that deployment. You run the software on your own infrastructure. Hosting, hardware, model or API usage, and other third-party operating costs stay separate from this license.
Top-of-mind questions for buyers
What counts as one agentic system for a single system license?
One license covers one deployed agentic system. The runtime applies RETAIN, GATE, or PRUNE decisions across the consequential action paths of that single deployment. You add another license for each additional deployed system you want to protect.
Does the license cover ongoing costs, or just the software?
The license covers the software only. It is a one-time purchase with no recurring subscription. You run it on your own systems. Hosting, hardware, model or API usage, and other third-party operating costs stay separate and are not part of this license.
What actions does the runtime actually govern within a licensed deployment?
The runtime governs only consequential actions routed through its integrated boundary. Model-proposed actions pass through capability, policy, approval, budget, and evidence checks before side effects execute. It does not govern custom executors or side-effect paths that bypass the runtime boundary.
zerodrivex.com+2
Helpful?
Vendor refund policy
No refunds
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Initial production release of ZeroDriveX Axiomatic Runtime. Qualified release commit 6c27b564a471e9b11b8d4ca71e888507b13a424c. Includes Ed25519-signed decision envelopes, signed GATE approvals, consume-once execution claims, DynamoDB distributed claim support, strict verifier conformance, AWS Marketplace License Manager integration, SBOM, and build provenance.
Additional details
Usage instructions
Run with an IAM role authorized for the purchased AWS Marketplace License Manager entitlement. Set AXIOMATIC_RUNTIME_TOKEN to a host-managed secret of at least 32 bytes. Mount a customer-controlled Ed25519 decision signing key file and set AXIOMATIC_ED25519_KEY_FILE; group/world-readable key files are rejected. The bundled ZDX validated baseline profile is used by default and AXIOMATIC_AUDIENCE defaults to zdx-executor. Expose port 8080 only to trusted callers. POST /v1/evaluate requires bearer authentication and a unique nonce. HTTP callers cannot release GATE by supplying explicitAction. Execute only the exact canonicalAction after /app/axiomatic-adapter verifies the signed decision and performs a consume-once claim. For distributed replicas set AXIOMATIC_CLAIM_BACKEND=dynamodb and AXIOMATIC_DYNAMODB_CLAIM_TABLE; the table uses String partition key claimKey and Number TTL attribute ttlEpoch.
Support
Vendor support
ZeroDriveX provides deployment, licensing, integration, and product support for licensed customers. Contact hello@zerodrivex.com or use https://zerodrivex.com/support. Include the Axiomatic Runtime version, AWS Region, deployment identifier, integration type, and redacted error details. Do not include API keys, access tokens, passwords, private signing keys, or other credentials.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
ZeroDriveX AgentCore Team provides five coordinated AI agents that help customers plan, implement, test, and review software changes in their own AWS environment.
A governed control plane for deploying AI-built and human-built apps safely inside your own AWS account, with built-in access control, policy enforcement and managed infrastructure so your platform team isn't the bottleneck.
Arcade.dev is the industry's first MCP runtime enabling AI to take secure, real-world actions. As the MCP runtime, Arcade is uniquely able to deliver secure agent authorization, high-accuracy tools, and centralized governance for multi-user AI agents at scale.
AUXO Curator is a next-generation log inspection service that provides real-time security insights. It integrates threat intelligence, AI, and customizable telemetry feeds like canary accounts, delivering clear, actionable cases through the AUXO Zero Trust platform.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.