There is no honest industry figure — so measure your own.
Security leaders evaluating a purpose-built reliance layer usually ask for the number first: what does redundant re-verification cost today, and what does a false claim cost when an agent acts on it? We will not manufacture one. There is no credible, independent figure for the cost of inter-agent re-verification, and quoting a fabricated benchmark would not survive your own procurement review.
What Signura provides instead is a way to establish your own baseline. Every reliance event is logged, so once your agents run against the exchange you can compare the metered cost of relying on a signed attestation with what a fresh, from-source verification of the same fact would take. The case rests on your traffic, not on our adjectives.
Attribution is the property your regime actually needs.
Shared-credential and service-account logging tells you which credential was used, not which entity acted. Under attribution requirements that expect an action to trace to a verified actor, that gap is the exposure. Signura binds each reliance event to a verified agent identity and to the specific attestation it verified, so an action attributes to an entity you can name rather than to a pool of shared secrets.
When a decision is later questioned, the evidence record shows which attestation was verified, which issuer stood behind it, and that the claim was unaltered at the moment the agent acted. That is the difference between an audit trail your reviewers can rely on and one they have to reconstruct.
On waiting for an incumbent to bundle it in.
A reasonable instinct is to wait for an identity provider you already run to add transferable reliance to its stack. Two things make waiting costly. First, the dependency is present now: even a small set of issuers attesting to common facts — licence validity, policy status, certification, a granted permission — creates value for relying agents without waiting for ecosystem-wide adoption.
Second, Signura is built on the ratified W3C Verifiable Credentials 2.0 substrate rather than a proprietary protocol, so the attestations and evidence you accumulate stay standards-based and inspectable regardless of which inter-agent protocol prevails. If a future protocol internalises reliance and revocation natively, standards conformance is what keeps the corpus portable rather than stranded.
What is not yet built.
Signura is early. The exchange runs an issuer service, a reliance and verification API, a freshness and revocation engine, an evidence ledger and a governance console, against a narrow set of high-frequency common facts and a small group of design partners. Broad self-serve issuer onboarding, standardised schemas across many fact types, and audit exports into external governance systems are on the path, not in hand.
We hold no SOC 2, ISO 27001, HIPAA, FedRAMP or PCI attestation today. This page states what the system does so a reviewer can check it rather than take our word for it.