zero-trust agent runtime
Enterprise Ready Zero Trust
Agent Fleets at Scale
Gibson is the runtime that gets a fleet of AI agents past a security review. Each agent acts under a grant from a named person, runs untrusted work in its own microVM, and writes every action to a timeline you can replay. The fleet writes what it finds into one graph and reads it back on the next pass. Run it in our cloud or in your own cluster.
the graph
Agents come and go. The graph is what your company keeps.
An agent that starts from zero every run relearns your estate every run. Gibson agents write what they find into one graph and read it back on the next pass. How sure the fleet is about each claim lives on the graph node itself.
Kubernetes, Helm, Argo CD, Terraform, Cilium, Karpenter, CloudNativePG, Velero, Prometheus.
- Day 0
- A Kubernetes cluster.
helm install gibson - Day 1
- Build and check in your agents.
- Day 2
- The fleet runs. Replay any of it.
Any Kubernetes. Ours, or yours up to air-gapped.
- Three surfaces, one sign-in. A person uses the console, the CLI or Zerocool, the plugin set for Claude Code and opencode. Zitadel signs them in once, and every surface carries that session.
- Every request enters at the edge. Envoy terminates TLS. ext-authz checks the session and the grant. The console never opens a channel to the harness.
- The harness records before it acts. A mission is typed at submit. Each event appends to the Timeline first. The audit row lands with it, or the action fails.
- Work runs in a sandbox. Setec launches a Firecracker microVM for the node, or resumes a bank member. The sandbox gets its own identity and the network of its node.
- Calls come back through the harness. Model calls go out through the gateway with the agent's identity. Tool calls hit the MCP server, which checks the grant first. Connectors run as pods, and the harness is the only MCP client.
- Work lands as a merge request. The coding agent commits to a branch. The GitLab plugin opens the merge request. Your engineer merges. Your pipeline deploys.
- The graph gets richer. Every observation folds into the World and projects into the graph. The planner reads it and ranks the next move. Replay any frame.
What runs where
Application, deployment, image, package, host. The agents build it as they work. “Is this package exposed” is a graph query, not a meeting.
What was found, and how sure we are
Each finding carries its priority, the rule that gave it, and a belief learned from settled outcomes in your environment. Facts, hypotheses and beliefs stay distinct by construction.
What was done about it
Fix commits, merge requests and verdicts hang off the finding. Who created the mission and who enrolled the agent are recorded.
What the next team starts from
A new mission reads the graph on its first turn. A belief version goes live only when it scores no worse on your own settled bets.
03 runtime, inside the harness
Who may act, and what to do next.
The harness answers two questions. Who is asking, and are they allowed? What should the fleet do next? The first is one identity and one permission check on every call. The second is the planner reading the graph and handing the model a short list of moves to pick from.
Identity and authorization, one call
Missions, the planner and the graph, one tick
replay
Answer “what did the agent do?” for any moment, with proof.
An agent runs for hours or days and makes hundreds of decisions. Gibson keeps every one of them in order, and can show you the agent's exact view of the world at any moment in that run. An auditor asks what it knew before it acted. You drag to that moment and they watch.
Sample mission. Demo data, not a customer run.
Drag the playhead or press play. Scrub back and a finding disappears, because the agent had not found it yet.
one agent, every desk
The same practice for every team. The same runtime for every desk.
An agent crosses many desks before it runs: the developer who wrote it, security, platform, operations, compliance, and whoever owns the data it touches. Today each desk builds its own control, in its own tool, and none of them see each other. What makes that stop is the practice underneath. Every team scaffolds, checks in, grants and runs an agent the same way, so a control set by one desk reaches every agent, whichever team built it. The framework each team uses does not change: LangChain, CrewAI, or a loop of your own in Go, TypeScript or Python. Your AI coding agent does one short integration pass with the ADK, and the agent checks in like every other.
Developer
holds the agent
Writes the agent in the framework they already use. Runs one short integration pass with the ADK and checks it in once. The path back to production does not run through us.
Security
holds the grant
Delegates read, write and execute by name. Security cannot delegate more than it holds. Deny wins wherever two grants disagree.
Platform
holds the boundary
Chooses where the runtime lives: hosted, or their own cluster, up to fully air-gapped. Chooses where agents run: a laptop, CI, a box on the network, or in the cluster.
Operations
holds the budget and the timeline
Sets what an agent may spend before it stops. Reads an append-only timeline of what the agent did. Any run replays move by move.
the whole path, seven steps
From an empty cluster to an agent you can replay.
Pick where it runs
Start on the hosted runtime and there is nothing to stand up. Point agents at it and go. When it has to be yours, install the same runtime into your own Kubernetes with one chart. The chart pins every first-party image by digest, down to a fully air-gapped install. Or let zeroroot host it.
Build or adapt
Build agents on the ADK, or bring an agent you already have. Your AI coding agent reads the ADK contract and does one short integration pass: check-in, model calls through the runtime, tools declared. From then on the runtime identifies and budgets every model call.
Check in and grant
An agent checks in once with a persistent host key. After that it acts on credentials that expire in 55 seconds, and it never caches them. A named human delegates read, write and execute. That human can never delegate more than they hold.
Launch missions
A mission is a typed work graph. A wrong agent name or a missing field fails when you submit the mission, not three steps into a production run. The model decides the path. The runtime checks the shape up front.
They act
Work that declares untrusted input runs in a microVM with a declared egress allowlist, or the runtime refuses the call. The harness is emit-only. An agent sees only the slice of the world its mission was given.
It lands in one graph
Everything an agent discovers lands in your tenant's own graph: hosts, services, findings, evidence, and any entities and relationships of your own. The runtime keeps it, and the SDK queries it. The next mission, and the next team, start from that graph instead of from zero.
Replay any of it
The runtime attributes and keeps every prompt, tool call and write. Replay a mission step by step and it comes back the same every time. That is the difference between an audit answer and a shrug.
where it runs
The runtime lives in Kubernetes. Your agents live wherever the work is.
Gibson Runtime, Gibson Console and the execution environment run together in one Kubernetes cluster, in any cloud or on your own metal. Your agents do not have to be in that cluster. They check in from wherever they already run. The one choice you make is who runs the cluster.
agentsYour agents run on your machines and check in over the network.
executionUntrusted work runs in microVMs we operate, or the runtime refuses it.
agentsYour agents check in over the network, or run inside the cluster over mTLS.
executionUntrusted work runs in your microVMs. You own that boundary.
Who runs the clustereither one, and you can change your mind
Where your agents runall of these, at once
Laptop
The same agent, checked in with the same host key, granted only what you work on right now.
CI
Runs as a first-class principal. The runtime attributes its actions to the pipeline, not to whoever owns the token.
Anywhere on your network
A box behind your firewall, checked in over the network. No cluster, no install.
Your cluster
In your own Kubernetes. When the runtime runs there too, components upgrade to mTLS transport. The grant model does not change.
by industry
Regulated industries, inside your own boundary.
Bring the workload you are not allowed to put an agent on.
Forty minutes. We show a fleet working it inside a boundary your security team would sign, in your environment or ours.