Executive brief · Governance & Security
SILO.RED — runtime security and governance for AI agents.
SILO.RED watches what every AI agent on a machine actually does, scores it against its own normal, responds in proportion, and gives the board evidence its AI policy is being followed. It is a working product, running today on macOS, Linux and Windows, below the API.
The problem
AI agents now run with production credentials on servers and developers' laptops. When one goes wrong, through prompt injection, a poisoned tool or plain drift, no single action looks like an attack: it uses valid access, through approved software. In 2026 autonomous agents were used in real intrusions, and a European regulator acknowledged the first breach notification attributed to one.
EDR asks “Is this malware?”
SILO.RED asks “Is this agent behaving like itself?”
Below the API
Almost every AI-security product sits above the operating system: in a proxy, a gateway, an identity system or a posture scanner. Each assumes the agent's actions pass through a point the vendor controls; a compromised agent process doesn't have to. SILO.RED watches the process itself, on the host, and works alongside gateways and identity tools rather than replacing them.
How it works
- Recognise Finds every AI agent on the machine and what it spawns, calls and touches. Baselines are learned per agent, on the host.
- Score The Trust Deficit Score adds up behaviour across credentials, egress, persistence, memory and evasion. It rises with evidence and decays with time.
- Respond Observe at 15, restrict at 40, isolate at 70, terminate at 90. Destructive steps wait for an operator.
- Record Every decision is kept as tamper-evident evidence: an inventory of agents, a compliance status for each, and a report for the board.
- Survive The monitor has to outlast the thing it monitors: kernel anti-tamper on Windows, Apple Endpoint Security on macOS, and a record of who tried to stop it.
What runs today
Clients on macOS, Linux and Windows; the Cortex control plane and its dashboard live, with regional instances federating over mutual TLS; licensing, payment and distribution built; the control plane deployable on AWS, Azure, GCP or private servers. Tested continuously by its own red team and a simulated estate reporting to a real control plane.
Not yet: the Windows kernel driver is built and ready for Microsoft certification, and the macOS build for Apple notarisation, both funded by the current round. No detection rate is published until one has been measured and independently checked. NVIDIA Inception member.
The category
The category formed in the last twelve months, and formed above the operating system. Platform vendors are buying early: Palo Alto bought Protect AI and CyberArk, Check Point bought Lakera, Alphabet bought Wiz. The layer where agents actually act is still close to empty.
- $2.8bn → $7.7bn — Spending on securing AI, 2026 to 2028 (Gartner)
- $3.6bn — Raised by the ten largest agentic-AI-security start-ups in 2026
- Above the OS — Where almost all of that money sits: proxies, gateways, identity and posture
The product runs. The round turns it into a company with customers. For the full deck, a live demo and the technical detail, request a briefing.
SILO.RED · Agencie.io Labs · part of Agencio APAC Pte Ltd · Proprietary & confidential beyond this brief.