Market map

Four layers. We own one.

Layer 1 Who are you? Okta · Entra · IndyKite
Layer 2 What should happen? Credo AI · IBM · Holistic AI · Palantir
Layer 3 reht What is AI actually allowed to do? TrigGuard · reht
Layer 4 What does AI do? OpenAI · Anthropic · CrewAI · LangChain

Head-to-head

Where we compete. Where we don't.

Layer 2 — Governance Credo AI, IBM, Holistic AI Different layer

These platforms operate at the policy and risk management layer. They audit models, score fairness, and produce compliance reports. They operate retrospectively — after the AI has acted.

reht operates before the action. The gate decision happens in 43ns (L1 Guardian) to <500ms (MCP/proxy). By the time a governance platform produces its next report, reht has already decided 10,000 actions.

  • No deterministic pre-execution gating
  • No receiver-attested WORM receipt at action time
  • No formal verification of the gate itself

"Governance tells you what should happen. reht decides what AI is actually allowed to do — before it does it."

Layer 3 — Execution Control TrigGuard Nearest competitor

The nearest true competitor. Both own "authorization judge before action" positioning. Both target enterprise AI deployment risk.

  • reht: TLA⁺ formal verification (4,782,943 states, 0 counterexamples). TrigGuard: none.
  • reht: public open standard (ACS/VACS). TrigGuard: proprietary.
  • reht: τ-metric coherence gate (WHY Gate v2). TrigGuard: no coherence dimension.
  • reht: regulatory markets with prEN 18229-1 + EU AI Act Annex III. TrigGuard: enterprise IT security.

Own formal verification + regulatory standard + coherence. Let TrigGuard own enterprise IT security.

Authorization Layer Arcade Complementary

Arcade raised $60M Series A (June 2026). Positioning: "secure AI agent authorization and action runtime." They answer "May this action execute?" (authorization at the tool/API call layer).

reht answers "Should this action exist at all?" (admissibility before intent forms). These are complementary, not competitive.

Compete on the regulatory market (Arcade is US-enterprise-focused, not EU-regulatory-focused). If Arcade dominates enterprise by Month 4, negotiate embedding: reht provides admissibility + WORM proof; Arcade provides authorization + MCP runtime.

Security Layer Straiker, HiddenLayer Different domain

These operate at AI infrastructure security: adversarial input detection, prompt injection defense, model fingerprinting. reht is not an AI security product. reht is a governance runtime.

Integration opportunity: Straiker / HiddenLayer feed threat signals into BARO's CVE/CISA KEV pipeline → BARO routes to VAIG → VAIG enforces.


Defensibility

Moat ranked by replication time

Moat Replication time Why it holds
TLA⁺ formal verification (4.78M states) 18+ months Spec + Rust + test vectors must all be consistent. Expensive to copy correctly.
prEN 18229-1 reference implementation 12 months Standards window closes August 2026. First reference wins the citation game.
τ-metric coherence (WHY Gate v2) 24+ months Requires spectral entropy theory (Spor 1/2 papers). Not yet in any competitor.
WORM SHA-256 hash-chained audit 6 months Technically straightforward. reht's advantage is the standard, not just the implementation.
43ns L1 gate latency 6 months Rust no_std, single cache-line frame, CRC32C via SSE4.2. Replicable but requires Rust expertise.
VACS open standard Ongoing Network effects. More adopters → harder to displace.

"Identity tells us who you are.
Governance tells us what should happen.
reht decides what AI is actually allowed to do."