Xtrom is the deterministic runtime firewall and non-human-identity governance plane for AI agents. We make untrusted data structurally unable to trigger a sensitive action — a guarantee, not a guess — and are the system of record for every agent identity, its entitlements, its credentials, and its audit trail.
Agents ingest untrusted content — a web page, a file, a tool response — and then act with real cloud, code, and production credentials. Prompt injection & agent hijacking is now the #1 agentic risk (OWASP ASI01). Content filters must recognize the attack; we make it a data-flow violation blocked structurally at the tool-call boundary using taint / information-flow control.
Our wedge is privileged coding & ops agents (Claude Code, Cursor, Copilot, Devin, CI, internal MCP). The same system scales to govern every non-human identity — Connect → Discover → Govern → Enforce → Monitor → Respond → Prove.
Signed, versioned policy bundles + taint/IFC. The security-critical layers are auditable and reproducible.
Runs in your VPC on any cloud (EKS/AKS/GKE + pluggable JIT backends). We receive privacy-scrubbed metadata only.
Engine, gateway, policy, JIT and SDKs are Apache-2.0. The commercial control plane is the system of record.
We ship against real, privileged-agent workloads — policy generality is spec'd by the first partner's real rules.
Xtrom is an early-stage company founded on deep security-platform experience — detection pipelines, SOC operations, and cloud security. That's the exact muscle this problem demands, and it's our unfair advantage against both governance-only startups and slower suite incumbents.
We're assembling a small, senior founding team. If securing AI agents is the problem you want to work on, see open roles.
Join the Charter Design Partner Program — free 60-day pilot, live in under a day.