← Portfolio
04 Governance & Security Beta

SILO.RED

Runtime security and governance for AI agents, below the API.

An AI agent with valid credentials doesn't look like an attacker. It looks like work. Malware tools look for malware; AI firewalls and tool gateways see only the traffic routed through them. SILO.RED watches the agent process itself, on the host, on macOS, Linux and Windows: what it opens, spawns and connects to. It scores that behaviour against the agent's own normal, responds in proportion, and keeps a record a board, auditor or regulator can use.

+ Runtime security and governance for AI agents, below the API
+ Running on macOS, Linux and Windows, with a live control plane
+ 630,000 lines of code, plus 150,000 of documentation
+ Observe, restrict, isolate, terminate: a graded response, with people approving the serious steps
+ Evidence a board, an auditor or a regulator can read

The layer

Govern. SILO.RED is the layer that keeps autonomous agents accountable: behaviour watched as it happens, a response in proportion to the evidence, and a record that satisfies boards, auditors and regulators.

The problem

AI agents now run with production credentials on servers and on developers’ laptops. When one goes wrong, through prompt injection, a poisoned tool or plain drift, no single action looks like an attack. It uses valid access, through approved software, doing things that resemble work. Taken together, the actions are the attack.

In 2026 this stopped being hypothetical. Autonomous agents have been used in real intrusions, and a European data protection authority has acknowledged the first breach notification attributed to a fully autonomous agent. Agent monitoring is now a compliance question as well as a security one.

EDR asks “Is this malware?” SILO.RED asks “Is this agent behaving like itself?”

Below the API

Almost every AI-security product sits above the operating system: in a proxy, a gateway, an identity system or a posture scanner. Each assumes the agent’s actions pass through a point the vendor controls. A compromised agent process doesn’t have to. SILO.RED sits where the actions actually happen, on the host, and works alongside gateways and identity tools rather than replacing them.

How it works

Recognise every agent and what it does. Score it against its own normal. Respond in proportion, with people approving anything destructive. Record every decision as evidence. Layers check each other: the operating system’s view is compared with what the firmware measured and what a second process sees from outside, and a disagreement between them is the finding. We say plainly what that does not prove: layers agreeing is never proof of a clean machine.

Governance a board can read

Every board now has a policy for AI. Almost none can show that its agents follow it. SILO.RED answers the questions a board, auditor or regulator actually asks: which agents are running, what each may do, whether it is staying within that, who approved the serious actions, and whether all of that can be proved.

What runs today

This is a working product, not a concept. Clients run on macOS, Linux and Windows; the Cortex control plane and its dashboard are live; regional instances federate over mutual TLS; licensing, payment and distribution are built. SILO.RED is tested continuously by its own red team and by a simulated estate of agents, cloud hosts and gateways reporting to a real control plane.

We also say what is not done yet. The Windows kernel driver is built and ready for Microsoft certification, and the macOS build for Apple notarisation; both are the first things the current round pays for. We do not publish a detection rate until one has been measured and independently checked.

For investors

SILO.RED is raising to turn a working product into a company with customers. Read the executive brief or the moonshot, request a full briefing, or see the investor overview.

Screenshots