X
Xtrom
ProductSecurityBlogCareersConsole ↗← Home
About

Runtime firewall + NHI governance for AI agents.

Xtrom is the deterministic runtime firewall and non-human-identity governance plane for AI agents. We make untrusted data structurally unable to trigger a sensitive action — a guarantee, not a guess — and are the system of record for every agent identity, its entitlements, its credentials, and its audit trail.

Why we exist

Agents ingest untrusted content — a web page, a file, a tool response — and then act with real cloud, code, and production credentials. Prompt injection & agent hijacking is now the #1 agentic risk (OWASP ASI01). Content filters must recognize the attack; we make it a data-flow violation blocked structurally at the tool-call boundary using taint / information-flow control.

Our wedge is privileged coding & ops agents (Claude Code, Cursor, Copilot, Devin, CI, internal MCP). The same system scales to govern every non-human identity — Connect → Discover → Govern → Enforce → Monitor → Respond → Prove.

Our approach

Detectors score. The action boundary is the guarantee. We treat the model as untrusted and enforce deterministically with taint/IFC + signed policy bundles: least-privilege capabilities, prod-destructive step-up, secret-egress allowlist, human approvals.

Deterministic over probabilistic

Signed, versioned policy bundles + taint/IFC. The security-critical layers are auditable and reproducible.

Customer-owned data plane

Runs in your VPC on any cloud (EKS/AKS/GKE + pluggable JIT backends). We receive privacy-scrubbed metadata only.

Open core

Engine, gateway, policy, JIT and SDKs are Apache-2.0. The commercial control plane is the system of record.

Design-partner driven

We ship against real, privileged-agent workloads — policy generality is spec'd by the first partner's real rules.

The team

Xtrom is an early-stage company founded on deep security-platform experience — detection pipelines, SOC operations, and cloud security. That's the exact muscle this problem demands, and it's our unfair advantage against both governance-only startups and slower suite incumbents.

We're assembling a small, senior founding team. If securing AI agents is the problem you want to work on, see open roles.

Want to shape the platform?

Join the Charter Design Partner Program — free 60-day pilot, live in under a day.

Request early access →
HomeAboutSecurityPrivacyTermsDPAEULAAUPSLACareersBlogContact © 2026 Xtrom, Inc.