SILO.RED
Runtime security and governance for AI agents, below the API.
An AI agent with valid credentials doesn't look like an attacker. It looks like work. Malware tools look for malware; AI firewalls and tool gateways see only the traffic routed through them. SILO.RED watches the agent process itself, on the host, on macOS, Linux and Windows: what it opens, spawns and connects to. It scores that behaviour against the agent's own normal, responds in proportion, and keeps a record a board, auditor or regulator can use.
The layer
Govern. SILO.RED is the layer that keeps autonomous agents accountable: behaviour watched as it happens, a response in proportion to the evidence, and a record that satisfies boards, auditors and regulators.
The problem
AI agents now run with production credentials on servers and on developers’ laptops. When one goes wrong, through prompt injection, a poisoned tool or plain drift, no single action looks like an attack. It uses valid access, through approved software, doing things that resemble work. Taken together, the actions are the attack.
In 2026 this stopped being hypothetical. Autonomous agents have been used in real intrusions, and a European data protection authority has acknowledged the first breach notification attributed to a fully autonomous agent. Agent monitoring is now a compliance question as well as a security one.
EDR asks “Is this malware?” SILO.RED asks “Is this agent behaving like itself?”
Below the API
Almost every AI-security product sits above the operating system: in a proxy, a gateway, an identity system or a posture scanner. Each assumes the agent’s actions pass through a point the vendor controls. A compromised agent process doesn’t have to. SILO.RED sits where the actions actually happen, on the host, and works alongside gateways and identity tools rather than replacing them.
How it works
Recognise every agent and what it does. Score it against its own normal. Respond in proportion, with people approving anything destructive. Record every decision as evidence. Layers check each other: the operating system’s view is compared with what the firmware measured and what a second process sees from outside, and a disagreement between them is the finding. We say plainly what that does not prove: layers agreeing is never proof of a clean machine.
Governance a board can read
Every board now has a policy for AI. Almost none can show that its agents follow it. SILO.RED answers the questions a board, auditor or regulator actually asks: which agents are running, what each may do, whether it is staying within that, who approved the serious actions, and whether all of that can be proved.
What runs today
This is a working product, not a concept. Clients run on macOS, Linux and Windows; the Cortex control plane and its dashboard are live; regional instances federate over mutual TLS; licensing, payment and distribution are built. SILO.RED is tested continuously by its own red team and by a simulated estate of agents, cloud hosts and gateways reporting to a real control plane.
We also say what is not done yet. The Windows kernel driver is built and ready for Microsoft certification, and the macOS build for Apple notarisation; both are the first things the current round pays for. We do not publish a detection rate until one has been measured and independently checked.
For investors
SILO.RED is raising to turn a working product into a company with customers. Read the executive brief or the moonshot, request a full briefing, or see the investor overview.
Screenshots