Safe infrastructure for AI agents
Let agents break things safely
Run AI coding agents in isolated containers. Credentials are injected at the network layer — never in environment variables. Every run captures logs, HTTP traces, and a tamper-proof audit trail.
View documentation →Policy engine for AI agent tool calls. Declarative rules that deny, redact, or log tool calls. Works standalone or with Moat.
View documentation →Credential-injecting TLS-intercepting proxy. The TLS proxy that powers Moat's network-layer credential injection. Usable standalone for any HTTPS client.
View documentation →Principal Engineer at TheGP, helping startups at critical moments, while exploring what it means to be AI native.
CTO at Neptune. Previously led the Go open source project and security for Stripe Link.