Dirigex decouples your governance, identity, policy, verification, and evidence layer from the agent vendors underneath it — so a vendor becoming a liability is an operational decision, not a governance rebuild.
$ npm i @dirigexai/sdk · pip install dirigex-sdk
The trap was never the agent you route to. It's the governance, identity, policy, verification, and evidence stack you'd have to rebuild the day you leave — slow-moving, expensive, legally load-bearing, and yours. Today it's welded to a vendor's control model: adopt their catalog, inherit their control model; leave the vendor, leave your control model behind. Lock-in isn't a pricing problem you negotiate out of. It's an architecture problem you design out of.
The agents and vendors that do the work. Commoditizing, volatile, and non-monotonic in quality. Replace them as the market moves.
Your governance decisions, verified identity, per-tenant policy, RBAC, scoped keys, and replayable evidence. Expensive to build, expensive to rebuild — and yours.
The control plane sits above the vendor and stays constant no matter what runs underneath it. You build it once; it outlives every vendor you route through.
We say the boundary out loud, because for a trust brand, saying it is the trust.
The failover fantasy is easy to say and impossible to defend. Operational continuity of your control plane is hard to build, hard for a capability-layer competitor to claim, and provable — so that's exactly what we sell.
One control surface, multiple protocols: MCP and A2A run end-to-end today; HTTP/JSON, gRPC, and WebSocket are supported at the platform layer — all on a pluggable registry source, where adding a catalog source is one implementation, not an ingestion rewrite.
Global, tenant, or agent — sever at the radius you choose, and retire an agent's lifecycle outright. Kill switches built into the request path, not bolted on.
Agents carry verification tiers that expire; a freshness runner re-checks on a schedule and delists anything that fails. The trust doesn't reset when you change providers.
Each governed request persists a route trace with protocol, decision, and provenance, with configurable retention.
"If you can't prove how your AI decided, you can't defend what it did."
So the catalog becomes a choice you can change, not a commitment you can't.
Dirigex doesn't promise magic failover. It makes governance portable, evidence durable, and vendor severance an operational decision instead of a trust-stack rebuild.