Certisfy, Cloudflare, and HUMAN Security are developing new systems to verify URLs using cryptographic signatures and standardized registry formats [1].
These developments address the growing need to prevent malicious URLs from being accessed, particularly as AI-driven threats become more sophisticated. By establishing a verifiable chain of trust, these companies aim to reduce the success rate of phishing and automated attacks.
Certisfy introduced an approach in April 2026 that utilizes cryptographic signatures to ensure the legitimacy of web addresses [1]. David Sacks said, "This approach allows for a more robust and verifiable way to ensure that URLs are legitimate" [1].
Parallel to these efforts, Cloudflare has unveiled a registry format designed specifically for bot and agent authentication [2]. This system provides a standardized method for authenticating bots, which helps reduce the risk of malicious activity across the web [2].
To further combat AI-based risks, HUMAN Security launched an open-source Model Context Protocol (MCP) server [3]. This tool is designed for analyzing AI threats and verifying the integrity of URLs [3]. HUMAN Security said the server offers a powerful tool for those analyzing AI threats [3].
These three initiatives represent a shift toward a more structured identity layer for the internet. While traditional URL security relied on certificates for entire domains, these new methods focus on the integrity of specific links, and the identity of the agents accessing them.
“"This approach allows for a more robust and verifiable way to ensure that URLs are legitimate,"”
The move toward cryptographic URL signatures and bot registries indicates that traditional domain-level security is no longer sufficient. As AI agents increasingly navigate the web, the industry is shifting toward a 'zero trust' model for individual links, ensuring that both the destination and the visitor can be cryptographically proven before a connection is established.


