zero-trust agent runtime
Install it today.
Ship a production agent tomorrow.
Gibson is the runtime that gets an AI agent past a security review. The agent can only do what a named person granted it. Every action lands on a timeline you can replay. Run Gibson in our cloud or in your own cluster.
what this is
Every team rows the same way, but with the agent development framework they prefer.
You do not need every team to agree on a framework. You need them to check in to the same runtime. The ADK gets each team there in a morning, in the language they already use, and the runtime does the rest.
The ADK gives each team
- A scaffold with the contract written down, so Claude Code or Cursor writes the component.
- Local validation before anything touches the runtime.
- One command to check in. One command to see the grants the agent holds.
- SDKs in Go, TypeScript and Python, and a LangChain adapter.
- MCP tools brought in as components.
The runtime gives the company
- One identity model for every agent.
- One grant model, bounded by the person who granted it.
- One typed mission format, so a bad mission fails at submit.
- One timeline per tenant, and replay of any run.
- One graph, so teams build on each other's findings.
- One console for all of it.
Every team keeps its framework and its code. What they give up is a different way to do the same thing on every team. Security reviews one runtime, and the answer covers every agent that checks in to it.
replay
Answer “what did the agent do?” for any moment, with proof.
An agent runs for hours or days and makes hundreds of decisions. Gibson keeps every one of them in order, and can show you the agent's exact view of the world at any moment in that run. An auditor asks what it knew before it acted. You drag to that moment and they watch.
Sample mission. Demo data, not a customer run.
Drag the playhead or press play. Scrub back and a finding disappears, because the agent had not found it yet.
why agents stall
The prototype works. That was never the hard part.
Each team's agent works on a laptop. Here is what it does the moment it touches production, and what Gibson does instead.
It runs on a shared service account.
Today
Someone pasted a service account token into the agent's config. The agent now has every permission that account has, on every call, and nobody can say which ones it used.
With Gibson
A named person grants the agent read, write or execute on specific things. The grant cannot exceed what that person holds. Every call records which grant it used.
It leaves no record you can replay.
Today
The agent writes to a log file. Three teams write three log formats. When an auditor asks what the agent did on Tuesday, someone greps and guesses.
With Gibson
Every prompt, tool call and write goes into one ordered record per tenant. Replay any run, move by move, and it returns the same result every time.
It runs generated code on the host.
Today
The model writes a script and the agent runs it, on the same machine that holds production credentials. Nobody reviews the script first.
With Gibson
Work that declares untrusted input runs in its own microVM, with its own kernel and a declared egress list. A code change from the coding agent arrives as a commit on a branch, and a human reviews it.
It sends your data to someone else's cloud.
Today
Each team picked its own model provider and its own place to host the agent. Customer data now leaves your boundary by several paths, and nobody signed off on any of them.
With Gibson
One chart installs the runtime into your own cluster, with your own models and your own keys, up to fully air-gapped. Or let zeroroot host it.
one agent, every desk
The same practice for every team. The same runtime for every desk.
An agent crosses many desks before it runs: the developer who wrote it, security, platform, operations, compliance, and whoever owns the data it touches. Today each desk builds its own control, in its own tool, and none of them see each other. What makes that stop is the practice underneath. Every team scaffolds, checks in, grants and runs an agent the same way, so a control set by one desk reaches every agent, whichever team built it. The framework each team uses does not change: LangChain, CrewAI, or a loop of your own in Go, TypeScript or Python. Your AI coding agent does one short integration pass with the ADK, and the agent checks in like every other.
Developer
holds the agent
Writes the agent in the framework they already use. Runs one short integration pass with the ADK and checks it in once. The path back to production does not run through us.
Security
holds the grant
Delegates read, write and execute by name. Security cannot delegate more than it holds. Deny wins wherever two grants disagree.
Platform
holds the boundary
Chooses where the runtime lives: hosted, or their own cluster, up to fully air-gapped. Chooses where agents run: a laptop, CI, a box on the network, or in the cluster.
Operations
holds the budget and the timeline
Sets what an agent may spend before it stops. Reads an append-only timeline of what the agent did. Any run replays move by move.
the whole path, seven steps
From an empty cluster to an agent you can replay.
Pick where it runs
Start on the hosted runtime and there is nothing to stand up. Point agents at it and go. When it has to be yours, install the same runtime into your own Kubernetes with one chart. The chart pins every first-party image by digest, down to a fully air-gapped install. Or let zeroroot host it.
Build or adapt
Build agents on the ADK, or bring an agent you already have. Your AI coding agent reads the ADK contract and does one short integration pass: check-in, model calls through the runtime, tools declared. From then on the runtime identifies and budgets every model call.
Check in and grant
An agent checks in once with a persistent host key. After that it acts on credentials that expire in 55 seconds, and it never caches them. A named human delegates read, write and execute. That human can never delegate more than they hold.
Launch missions
A mission is a typed work graph. A wrong agent name or a missing field fails when you submit the mission, not three steps into a production run. The model decides the path. The runtime checks the shape up front.
They act
Work that declares untrusted input runs in a microVM with a declared egress allowlist, or the runtime refuses the call. The harness is emit-only. An agent sees only the slice of the world its mission was given.
It lands in one graph
Everything an agent discovers lands in your tenant's own graph: hosts, services, findings, evidence, and any entities and relationships of your own. The runtime keeps it, and the SDK queries it. The next mission, and the next team, start from that graph instead of from zero.
Replay any of it
The runtime attributes and keeps every prompt, tool call and write. Replay a mission step by step and it comes back the same every time. That is the difference between an audit answer and a shrug.
how an agent checks in
Two commands, and the agent has an identity.
An agent's first act is to prove which host it is. After that, the agent signs every act. Each act is short-lived and bounded by the person who granted it.
- 01Bootstrap onceA one-time credential authenticates the first check-in. The agent never uses it again.
- 02Keep a host keyA persistent Ed25519 key pair sits on disk at 0600. The host ID is the JWK thumbprint of its public key.
- 03Sign every callAn ephemeral agent key signs a token per call. The token expires in 55 seconds, and the agent never caches it.
- 04Upgrade in clusterInside a SPIRE-enabled cluster the transport upgrades to mTLS. Identity does not change. The same grant still governs.
# a human, signed in, provisions the machine identity
$ gibson agent enroll --name pipeline-warden --kind agent
principal_id: 01JB6…9WQ
bootstrap_token: eyJhbGci…
gibson_url: api.zeroroot.ai
# the agent completes the capability-grant handshake itself.
# one-time token in, host key and runtime credential out.
$ gibson component register --token -
component register: registered agent "pipeline-warden" (agent_id=01JB6…9WQ)
runtime credential: ~/.gibson/agent/pipeline-warden.runtime.json
# from here every call is signed with a token that lives 55 seconds.
$ gibson mission submit release-guard.cue
01JB7…4KDagents you already built
Keep the framework. One short integration pass brings the agent under the boundary.
Scaffold a component with the ADK. Your AI coding agent reads the contract in AGENTS.md and wraps the agent you already have: it adds the check-in, routes model calls through the runtime, and declares the tools. Validate, register, run. The framework and the logic stay yours.
- Works with LangChain, CrewAI, AutoGen, LlamaIndex, or your own loop, in Go, TypeScript or Python
- One integration pass, done by Claude Code or Cursor against the ADK contract
- Checked in once, so it acts under an identity and a grant like any agent built here
- From then on every model call carries its identity and spends against its budget
- Its tools come in over MCP as components, with declared secrets and egress
$ gibson component init my-agent --kind agent
$ claude
> Wrap our LangChain agent as a Gibson component.
> Read AGENTS.md first.
# the coding agent reads the contract, adds the
# check-in, routes model calls through the runtime,
# and declares the tools. your logic is untouched.
$ gibson component validate
$ gibson component register --token -
$ gibson component runthe platform
Three pieces.
Install them in your own cluster, up to fully air-gapped, or let zeroroot host them. There is no separate edition to buy, and no feature that only exists in someone else's cloud.
Gibson Runtime
The server your agents check in to. It holds each agent's identity and grant, runs missions, decides where work executes, and writes every event to the timeline.
Elastic License 2.0Gibson Console
The web UI on top of the runtime. Create and watch missions, set grants and budgets, browse the knowledge graph, read traces, and replay any run.
Apache-2.0Execution environment
Where untrusted work runs. Setec puts each tool run in its own microVM, on its own kernel, with the egress the component declared. The runtime dispatches into it and reads the result back.
open source
The half you build on is open, and stays open.
Everything you write agents with is Apache-2.0. Read it, fork it, audit it, and keep running it wherever you take it.
ADK
Build agents, tools and plugins. The gibson CLI.
Elastic License 2.0Zerocool
A coding agent built on opencode. A developer can drive it, but it is built to run on its own: the runtime dispatches work to it, from a mission or from a non-coding agent, and its changes arrive as commits a human reviews.
Apache-2.0Bridge
Brings any MCP-compliant tool in as a component.
where it runs
The runtime lives in Kubernetes. Your agents live wherever the work is.
Gibson Runtime, Gibson Console and the execution environment run together in one Kubernetes cluster, in any cloud or on your own metal. Your agents do not have to be in that cluster. They check in from wherever they already run. The one choice you make is who runs the cluster.
agentsYour agents run on your machines and check in over the network.
executionUntrusted work runs in microVMs we operate, or the runtime refuses it.
agentsYour agents check in over the network, or run inside the cluster over mTLS.
executionUntrusted work runs in your microVMs. You own that boundary.
Who runs the clustereither one, and you can change your mind
Where your agents runall of these, at once
Laptop
The same agent, checked in with the same host key, granted only what you work on right now.
CI
Runs as a first-class principal. The runtime attributes its actions to the pipeline, not to whoever owns the token.
Anywhere on your network
A box behind your firewall, checked in over the network. No cluster, no install.
Your cluster
In your own Kubernetes. When the runtime runs there too, components upgrade to mTLS transport. The grant model does not change.
by industry
Regulated industries, inside your own boundary.
what is actually enforced
Controls, not certificates.
Every row below is a mechanism in shipped code, stated with its boundary. Where something is advisory rather than enforced, this page says so.
| Agent identity | A persistent Ed25519 host key, and per-call tokens that expire in 55 seconds. The agent never caches them. | enforced |
|---|---|---|
| Delegation ceiling | A granter can only grant capabilities the granter already holds. Deny wins. | enforced |
| Untrusted execution | Work that declares untrusted input runs in a microVM, or the runtime refuses it. Code that declares itself trusted runs in process. | conditional |
| Egress | A component declares where it may talk. The microVM boundary and cluster policy enforce that declaration. When a plugin runs as a bare process on a laptop, egress is advisory. | conditional |
| Tenant isolation | A separate graph database per tenant. Not a filter on a shared one. | structural |
| Audit | An append-only timeline per tenant. Replay rebuilds a mission rather than queries a log. | structural |
how to start
We are accepting a small number of design partners.
You bring a workload and the environment it has to run in. We work alongside your team until the first agents are live in it. You keep everything we build.
What you get
- Your first agents live in your own environment
- Our engineers alongside your team, not behind a ticket queue
- Everything we build is yours: open protocols, your cluster, no exit penalty
- A direct line into what we build next
What we ask
- A real workload, not a test environment
- Access to the people who own the boundary it has to run inside
- Permission to say publicly that it worked, when it does
read the thing itself