zero-trust agent runtime

Install it today.
Ship a production agent tomorrow.

Gibson is the runtime that gets an AI agent past a security review. The agent can only do what a named person granted it. Every action lands on a timeline you can replay. Run Gibson in our cloud or in your own cluster.

1 dayto your first production agentNevermore access than the human who granted itOurs or yourswe host the runtime, or you do

what this is

Every team rows the same way, but with the agent development framework they prefer.

You do not need every team to agree on a framework. You need them to check in to the same runtime. The ADK gets each team there in a morning, in the language they already use, and the runtime does the rest.

The ADK gives each team

  • A scaffold with the contract written down, so Claude Code or Cursor writes the component.
  • Local validation before anything touches the runtime.
  • One command to check in. One command to see the grants the agent holds.
  • SDKs in Go, TypeScript and Python, and a LangChain adapter.
  • MCP tools brought in as components.

The runtime gives the company

  • One identity model for every agent.
  • One grant model, bounded by the person who granted it.
  • One typed mission format, so a bad mission fails at submit.
  • One timeline per tenant, and replay of any run.
  • One graph, so teams build on each other's findings.
  • One console for all of it.

Every team keeps its framework and its code. What they give up is a different way to do the same thing on every team. Security reviews one runtime, and the answer covers every agent that checks in to it.

replay

Answer “what did the agent do?” for any moment, with proof.

An agent runs for hours or days and makes hundreds of decisions. Gibson keeps every one of them in order, and can show you the agent's exact view of the world at any moment in that run. An auditor asks what it knew before it acted. You drag to that moment and they watch.

Sample mission. Demo data, not a customer run.

gibson world replay · GetFrameAt(seq)tenant world · isolated
mission: prove an exploitable path to the tenant key store
timelinefolded 0 / 41
00mission.started mission: prove an exploitable path to the tenant key store
01host.observed edge-gw (10.0.0.1): perimeter gateway
02decision.requested brain: 1 host, no services, what next?
03llm_call.observed decider, claude, 1 completion
04token.used +1,180 tokens
05decision.completed chose: enumerate services behind edge-gw
06work.dispatched tool: portscan edge-gw
07host.observed web-01 (10.0.2.5): reachable via edge-gw
08host.observed web-02 (10.0.2.6): reachable via edge-gw
09work.completed scan complete: 2 web hosts, ports 80/443
10belief.scored priority: web-01 0.18 up to 0.34
11decision.requested brain: which surface first?
12llm_call.observed decider, claude, 1 completion
13token.used +1,540 tokens
14decision.completed chose: probe web-01 app surface
15work.dispatched agent: recon web-01
16host.observed api-01 (10.0.3.10): internal, linked from web-01
17belief.scored priority: api-01 0.20 up to 0.52
18credential.observed reused service credential exposed on web-01
19work.completed recon complete: api-01 proxies internal metadata
20finding.raised SSRF on api-01 /proxy reaches cloud metadata
21decision.requested brain: pivot from api-01?
22llm_call.observed decider, claude, 1 completion
23token.used +2,020 tokens
24decision.completed chose: reach data tier with recovered cred
25work.dispatched agent: pivot to data tier
26host.observed db-primary (10.0.4.2): reachable from api-01
27belief.scored priority: db-primary 0.30 up to 0.64
28finding.raised reused DB credential grants read on db-primary
29host.observed ad-dc (10.0.6.1): observed, off the goal path
30work.completed pivot complete: broker endpoint referenced in db
31belief.scored priority: vault-broker 0.40 up to 0.88 (goal)
32decision.requested brain: can the key store be reached?
33llm_call.observed decider, claude, 1 completion
34token.used +2,460 tokens
35decision.completed chose: prove reach to vault-broker
36work.dispatched agent: reach key store
37credential.observed broker token recoverable via db read
38work.completed reach proven end to end
39finding.raised critical: path to tenant key store proven
40mission.done goal reached: exploitable path proven, 3 findings
frame 0 = fold(timeline, 0)mission not yet started
0
hosts
0
findings
0
tokens
mission.startedlive world · 41

Drag the playhead or press play. Scrub back and a finding disappears, because the agent had not found it yet.

why agents stall

The prototype works. That was never the hard part.

Each team's agent works on a laptop. Here is what it does the moment it touches production, and what Gibson does instead.

It runs on a shared service account.

Today

Someone pasted a service account token into the agent's config. The agent now has every permission that account has, on every call, and nobody can say which ones it used.

With Gibson

A named person grants the agent read, write or execute on specific things. The grant cannot exceed what that person holds. Every call records which grant it used.

It leaves no record you can replay.

Today

The agent writes to a log file. Three teams write three log formats. When an auditor asks what the agent did on Tuesday, someone greps and guesses.

With Gibson

Every prompt, tool call and write goes into one ordered record per tenant. Replay any run, move by move, and it returns the same result every time.

It runs generated code on the host.

Today

The model writes a script and the agent runs it, on the same machine that holds production credentials. Nobody reviews the script first.

With Gibson

Work that declares untrusted input runs in its own microVM, with its own kernel and a declared egress list. A code change from the coding agent arrives as a commit on a branch, and a human reviews it.

It sends your data to someone else's cloud.

Today

Each team picked its own model provider and its own place to host the agent. Customer data now leaves your boundary by several paths, and nobody signed off on any of them.

With Gibson

One chart installs the runtime into your own cluster, with your own models and your own keys, up to fully air-gapped. Or let zeroroot host it.

one agent, every desk

The same practice for every team. The same runtime for every desk.

An agent crosses many desks before it runs: the developer who wrote it, security, platform, operations, compliance, and whoever owns the data it touches. Today each desk builds its own control, in its own tool, and none of them see each other. What makes that stop is the practice underneath. Every team scaffolds, checks in, grants and runs an agent the same way, so a control set by one desk reaches every agent, whichever team built it. The framework each team uses does not change: LangChain, CrewAI, or a loop of your own in Go, TypeScript or Python. Your AI coding agent does one short integration pass with the ADK, and the agent checks in like every other.

Developer

holds the agent

Writes the agent in the framework they already use. Runs one short integration pass with the ADK and checks it in once. The path back to production does not run through us.

Security

holds the grant

Delegates read, write and execute by name. Security cannot delegate more than it holds. Deny wins wherever two grants disagree.

Platform

holds the boundary

Chooses where the runtime lives: hosted, or their own cluster, up to fully air-gapped. Chooses where agents run: a laptop, CI, a box on the network, or in the cluster.

Operations

holds the budget and the timeline

Sets what an agent may spend before it stops. Reads an append-only timeline of what the agent did. Any run replays move by move.

the whole path, seven steps

From an empty cluster to an agent you can replay.

01Pick where it runsours, or yours02Build or adaptbuild new, or one integration pass03Check in and grantidentity, then a ceiling04Launch missionstyped at submit, not at runtime05They actmicroVM or refusal06It lands in one graphshared, per tenant07Replay any of itmove by move
step 01

Pick where it runs

Start on the hosted runtime and there is nothing to stand up. Point agents at it and go. When it has to be yours, install the same runtime into your own Kubernetes with one chart. The chart pins every first-party image by digest, down to a fully air-gapped install. Or let zeroroot host it.

hosted, nothing to runhelm install gibsonair-gapped
step 02

Build or adapt

Build agents on the ADK, or bring an agent you already have. Your AI coding agent reads the ADK contract and does one short integration pass: check-in, model calls through the runtime, tools declared. From then on the runtime identifies and budgets every model call.

Go, TypeScript and Python SDKsOpenAI-compatible seamMCP tools
step 03

Check in and grant

An agent checks in once with a persistent host key. After that it acts on credentials that expire in 55 seconds, and it never caches them. A named human delegates read, write and execute. That human can never delegate more than they hold.

Ed25519 host key55-second tokensgrant ceilingdeny wins
step 04

Launch missions

A mission is a typed work graph. A wrong agent name or a missing field fails when you submit the mission, not three steps into a production run. The model decides the path. The runtime checks the shape up front.

CUE-typedpausableresumable
step 05

They act

Work that declares untrusted input runs in a microVM with a declared egress allowlist, or the runtime refuses the call. The harness is emit-only. An agent sees only the slice of the world its mission was given.

Firecracker / Katadeclared egressemit-only harness
step 06

It lands in one graph

Everything an agent discovers lands in your tenant's own graph: hosts, services, findings, evidence, and any entities and relationships of your own. The runtime keeps it, and the SDK queries it. The next mission, and the next team, start from that graph instead of from zero.

append-onlydatabase per tenantno cross-tenant path
step 07

Replay any of it

The runtime attributes and keeps every prompt, tool call and write. Replay a mission step by step and it comes back the same every time. That is the difference between an audit answer and a shrug.

deterministicattributableexportable

how an agent checks in

Two commands, and the agent has an identity.

An agent's first act is to prove which host it is. After that, the agent signs every act. Each act is short-lived and bounded by the person who granted it.

  1. 01Bootstrap onceA one-time credential authenticates the first check-in. The agent never uses it again.
  2. 02Keep a host keyA persistent Ed25519 key pair sits on disk at 0600. The host ID is the JWK thumbprint of its public key.
  3. 03Sign every callAn ephemeral agent key signs a token per call. The token expires in 55 seconds, and the agent never caches it.
  4. 04Upgrade in clusterInside a SPIRE-enabled cluster the transport upgrades to mTLS. Identity does not change. The same grant still governs.
pipeline-warden · check-inevery command and printed field is the CLI's own
# a human, signed in, provisions the machine identity
$ gibson agent enroll --name pipeline-warden --kind agent
principal_id:  01JB6…9WQ
bootstrap_token: eyJhbGci…
gibson_url:    api.zeroroot.ai

# the agent completes the capability-grant handshake itself.
# one-time token in, host key and runtime credential out.
$ gibson component register --token -
component register: registered agent "pipeline-warden" (agent_id=01JB6…9WQ)
  runtime credential: ~/.gibson/agent/pipeline-warden.runtime.json

# from here every call is signed with a token that lives 55 seconds.
$ gibson mission submit release-guard.cue
01JB7…4KD

agents you already built

Keep the framework. One short integration pass brings the agent under the boundary.

Scaffold a component with the ADK. Your AI coding agent reads the contract in AGENTS.md and wraps the agent you already have: it adds the check-in, routes model calls through the runtime, and declares the tools. Validate, register, run. The framework and the logic stay yours.

  • Works with LangChain, CrewAI, AutoGen, LlamaIndex, or your own loop, in Go, TypeScript or Python
  • One integration pass, done by Claude Code or Cursor against the ADK contract
  • Checked in once, so it acts under an identity and a grant like any agent built here
  • From then on every model call carries its identity and spends against its budget
  • Its tools come in over MCP as components, with declared secrets and egress
one integration pass
$ gibson component init my-agent --kind agent
$ claude
> Wrap our LangChain agent as a Gibson component.
> Read AGENTS.md first.

# the coding agent reads the contract, adds the
# check-in, routes model calls through the runtime,
# and declares the tools. your logic is untouched.

$ gibson component validate
$ gibson component register --token -
$ gibson component run

where it runs

The runtime lives in Kubernetes. Your agents live wherever the work is.

Gibson Runtime, Gibson Console and the execution environment run together in one Kubernetes cluster, in any cloud or on your own metal. Your agents do not have to be in that cluster. They check in from wherever they already run. The one choice you make is who runs the cluster.

Who runs the cluster
your agents, wherever the work isLaptopgibson component runCIa pipeline principalYour networka box behind the firewallYour clusterin-cluster componentscheck inKubernetes · zeroroot's cloudzeroroot's Kubernetes. We operate it.Kubernetes · AWS · Google Cloud · Azure · on-premYour Kubernetes. Any cloud, or your own metal, up to air-gapped.Execution environmentSetec microVMs, one per tool runGibson Runtimeidentity · grants · missions · timelineGibson Consolemissions, grants, replay

agentsYour agents run on your machines and check in over the network.

executionUntrusted work runs in microVMs we operate, or the runtime refuses it.

agentsYour agents check in over the network, or run inside the cluster over mTLS.

executionUntrusted work runs in your microVMs. You own that boundary.

Who runs the clustereither one, and you can change your mind

Where your agents runall of these, at once

Laptop

The same agent, checked in with the same host key, granted only what you work on right now.

CI

Runs as a first-class principal. The runtime attributes its actions to the pipeline, not to whoever owns the token.

Anywhere on your network

A box behind your firewall, checked in over the network. No cluster, no install.

Your cluster

In your own Kubernetes. When the runtime runs there too, components upgrade to mTLS transport. The grant model does not change.

what is actually enforced

Controls, not certificates.

Every row below is a mechanism in shipped code, stated with its boundary. Where something is advisory rather than enforced, this page says so.

Shipped controls, each with its boundary and whether it is enforced, structural or conditional
Agent identityA persistent Ed25519 host key, and per-call tokens that expire in 55 seconds. The agent never caches them.enforced
Delegation ceilingA granter can only grant capabilities the granter already holds. Deny wins.enforced
Untrusted executionWork that declares untrusted input runs in a microVM, or the runtime refuses it. Code that declares itself trusted runs in process.conditional
EgressA component declares where it may talk. The microVM boundary and cluster policy enforce that declaration. When a plugin runs as a bare process on a laptop, egress is advisory.conditional
Tenant isolationA separate graph database per tenant. Not a filter on a shared one.structural
AuditAn append-only timeline per tenant. Replay rebuilds a mission rather than queries a log.structural

how to start

We are accepting a small number of design partners.

You bring a workload and the environment it has to run in. We work alongside your team until the first agents are live in it. You keep everything we build.

What you get

  • Your first agents live in your own environment
  • Our engineers alongside your team, not behind a ticket queue
  • Everything we build is yours: open protocols, your cluster, no exit penalty
  • A direct line into what we build next

What we ask

  • A real workload, not a test environment
  • Access to the people who own the boundary it has to run inside
  • Permission to say publicly that it worked, when it does

Bring the workload you are not allowed to put an agent on.