Field document · encrypted packages

Encrypted entity packages

The canonical package stores the agent identity while encryption and integrity checks protect its release.

What belongs in the canonical package?

A package may contain SOUL.md, ENTITY.json, genesis memory, a manifest, declared skills, runtime configuration, and entity assets. The final package must remain inspectable and cannot run arbitrary scripts automatically.

How are encryption keys protected?

Each package uses a unique data encryption key protected by KMS or HSM-backed infrastructure. Public metadata exposes only the package identifier and hash.

Need the current launch state?Open launch status →