As autonomous AI agents move beyond individual enterprises, enabling them to securely communicate and collaborate across organizational boundaries is emerging as a critical challenge. Traditional approaches often push cross-company workflows back to email, portals, and manual data entry, while existing agent-to-agent protocols do not fully address the security and trust requirements of inter-organizational communication. Ellavox is addressing this gap with Elladex, a directory for discovering verified AI agents, alongside AGX, an open-source protocol designed to enable encrypted agent-to-agent communication without exposing inbound endpoints. In an exclusive conversation with AI Reporter America, Rich Waidmann Chairman & Co-Founder of Ellavox discussed how the platform separates discovery, identity, trust, and access controls to create a more secure foundation for cross-company AI collaboration and the emerging agent-to-agent economy.
1. What drove Ellavox to launch Elladex for cross-company AI agent collaboration?
Our enterprise clients kept hitting the same wall. Their agents worked well inside the company, but the moment a task involved another organization like a vendor, customer, partner, etc., everything fell back to email, portals, and people re-keying data. The protocols for agent-to-agent tasks exist, but they assume you're willing to put an endpoint on the internet, manage security credentials with every partner, and trust the Internet in between. Our clients didn’t want to do that, and they shouldn’t either. Elladex and AGX exist so an organization can find a partner's agent and exchange work with it without creating a security risk and attack surface.
Before starting Ellavox, we spent 20+ years as an enterprise managed service provider in the cloud space, running mission critical systems for companies like Caterpillar, UPS, Merck, IBM, and more than 1000 others. It taught us that having an extensive security posture has to be the default for whatever offering we created.
2. How does Elladex help agents discover and securely work with other agents?
Elladex is a directory. Organizations are verified, list their agents, and choose how discoverable each one is: publicly searchable, unlisted but reachable at its exact address, or private. People search Elladex directly; agents query it programmatically.
Discovery and access are deliberately separate. Finding an agent in Elladex doesn't let you send it anything. The receiving organization decides which external agents may submit work, and its gateway rejects everything else by default. The exchange itself runs over AGX, an open-source protocol we created which carries the message through Nostr relays without the receiver exposing an endpoint, and keeps the content encrypted so the relay can't read it.
3. What makes AGX different from existing agent-to-agent protocols?
It operates at a different layer, so it's more complementary than competitive. The current agent to agent communication standard, A2A, defines the structure of a task between agents, and it does that well. AGX addresses the boundary the task crosses: how the message gets from one organization to another, who's allowed to send one, and what the network in between can see.
AGX does a number of very important things: Every message is signed by the sender's key, so the receiver can verify which key sent it and keep that record. The receiving organization never exposes an inbound endpoint; its gateway connects outbound to relays. Message content is encrypted so the relays carry ciphertext. And the gateway is closed by default: only approved peers get through. A2A tasks ride inside the AGX envelope unchanged, so organizations keep their existing agents and frameworks.
4. How does Elladex establish identity and trust between autonomous agents?
Two separate mechanisms, and we're careful not to blur them.
Identity is key-based. Each agent has a cryptographic keypair, and every AGX message is signed with it. Elladex verifies that the agent's key is published at a known location on its organization's own domain, so a listing is tied to domain control, not just to a form someone filled out.
Trust is a decision the receiving organization makes. Elladex gives organizations the information they need but it doesn't confer trust. The organization chooses which peers its gateway accepts requests from, and that list is enforced at the gateway.
5. How do policy controls prevent unauthorized agent actions or data access?
At the boundary, the AGX gateway only accepts work from approved peers, so an unknown or unlisted sender never reaches an agent at all.
Inside the organization, our control plane governs what agents may do. We recommend that work arrive at an “ingestion agent” that validates requests and routes them to narrowly scoped task agents, each with its own limits on tools and data. The permission model is per partner and per action: a partner approved to request invoice status can't reach the agent that initiates payments, even by asking nicely. Those policies are versioned and reviewed like code, and every routing and execution decision is logged.
6. What challenges arise when autonomous agents conduct business across organizational boundaries?
We’ve solved the challenges of agents communicating securely to other agents by creating AGX. Now that communication has been enabled safely, organizations need to know who is sending them the requests on the other end, which Elladex solves.
With discovery and trust established, autonomous agents need to be tightly scoped so that they only perform very specific functions, and they only accept very specific requests. No different than how companies have separations of duties with their employees. External agents that make requests that are not allowed, are logged and alerted. This allows the organization to decide whether to keep working with those agents or revoke their connections and permissions.
7. How could Elladex shape the future of agent-to-agent commerce and collaboration?
Today, each company has to build or own every capability that its agents need, and without agent-to-agent commerce, humans continue to act as roadblocks. If specialized agents can be found and engaged safely across organizations, that changes things like how a lender's agent can engage a verification provider's agent, or how a property manager's agent can dispatch to a plumbing contractor’s agent, for example, without either side building a custom integration or exposing itself to the open Internet. Our belief is that the organizations who adopt autonomous agent to agent communications first will be the ones who are able to grow the fastest, because they will have eliminated unnecessary delays that cost them and their customers time and money.
On commerce specifically, we see the payment and checkout standards being built by the large platforms as complementary. AGX is the secure path between organizations; what travels on it can be an A2A task today and a standardized order or payment mandate tomorrow.