All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Secure Agentics develops Adrian, open-source software that reviews an AI agent’s reasoning and planned actions and can alert, pause an action for human approval, or block it. It targets teams running autonomous agents and production AI systems, including those in regulated environments and critical national infrastructure. Founded in 2025, Secure Agentics gives Adrian away free and is building a version for businesses, which chief executive Max Corbridge says is how it will earn revenue. He told the Jersey Evening Post of just under 4,000 downloads in Adrian’s first five weeks. The paper says the company raised money before launch and is raising its next round. Adrian works with agent tools from Anthropic, OpenAI and LangChain, so one deployment can monitor agents built with any of them.
| Description | Secure Agentics builds Adrian, open-source runtime security software that sits inside AI agents, reviews their reasoning and actions as they run, and can alert on or block harmful actions before they execute. | [f1] |
|---|---|---|
| Founded | 2025 | [f2] |
| HQ | London, United Kingdom | [f2] |
| Product | What it does |
|---|---|
| Adrian | Open-source SDKs and backend that capture an AI agent's tool calls and reasoning, classify each event against security policies, and alert on, pause, or block risky actions. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Coding and Orchestration Tools AI coding tools and agentic orchestration tools on user devices, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Traffic Paths to external and self-hosted AI services, MCP tool channels, agent-to-agent calls, model-registry downloads, and egress to unapproved AI services. AI gateways, LLM routers, and MCP gateways steer traffic along those paths. The steering decisions and their inputs belong here too: routing policies, MCP server registries, and agent naming and discovery services. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, an AI bill of materials (AIBOM), and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Adrian monitors AI agents' actions and reasoning traces at runtime, detects malicious or out-of-remit behavior, and can pause or block an action before it runs. These capabilities are mapped to the AI Defense Matrix. [f3]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Secure Agentics names its buyer, teams running autonomous agents in production including regulated and critical-infrastructure settings, and states the pain as agents acting on injected instructions before anyone intervenes. The company and its founder state that pain, and no reviewed source quantifies it, so the problem is present but unproven. [s1, s12, s15] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Adrian’s documentation describes a backend that assembles session context, sends each agent event to a classifier model and returns a verdict, a Block mode that stops actions before they execute, and a self-hosted stack with a bundled local model. The Apache 2.0 repository ships that stack for inspection. No independent benchmark or technical evaluation of Adrian appears in the cited sources, and the Black Hat honorable mention comes from a pitch contest, so the record holds concrete vendor-side detail without the outside validation rung 4 needs. [s25, s24, s5, s10] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is agents gaining tool access and autonomy, which Adrian’s May 2026 launch ties to prompt injection the company expects to persist. Demand evidence in the reviewed sources is indirect, a February 2026 government-backed LASR cohort that includes Secure Agentics plus press interest. [s1, s15, s19, s12] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Max Corbridge’s offensive-security record is independently documented, with Petri crediting him in 2023 with a Microsoft Teams vulnerability discovery, and the Jersey Evening Post says co-founder Steve Street, whom it refers to as the late Steve Street, had founded Mindgard. That is verifiable relevant experience, and the reviewed sources do not independently document multiple prior builds or exits for the current team. [s23, s2, s22, s11] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 2/5 | Adrian ships free with no paid tier, and the company’s references to early enterprise customers, central government and tier-1 banks name no organization. Its chief executive reports just under 4,000 downloads in five weeks, which is adoption of free software, and the LASR cohort and Black Hat honorable mention are recognition. [s15, s22, s11, s19, s10] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | Secure Agentics shipped Adrian as open source in May 2026 and has released SDK updates since. The Jersey Evening Post reports a successful first fundraise before the launch and a next round under way. The cited sources contain no funding amount, round date or investor name, so the size of the capital behind that output is unknown. [s5, s15, s11] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Plexal describes a monitoring and control platform for agentic AI, and SE Radio frames the founder’s work as defending AI agents, a category buyers can recognize. The category is still forming, and Secure Agentics explains its placement against input and output filtering and platform-layer controls. [s19, s20, s12, s3, s15] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Adrian connects to LangChain, the Anthropic and OpenAI client libraries and Claude Code, so one product can monitor agents built on several vendors’ tools, which a platform owner adding controls only to its own product would not replicate. No accumulated data asset appears in the reviewed sources, and the self-hosted release classifies events with Gemma 4, so the friction stops short of a structural moat. [s27, s24, s26] |
Secure Agentics addresses the risk that an AI agent with access to tools takes a harmful action after an attacker plants instructions in content it reads. Its homepage lists the teams it builds for as those running autonomous agents, multi-step agent swarms and production AI systems, including high-trust or regulated environments and critical national infrastructure.
The company argues that the defense has to act before an agent executes. Its homepage calls prompt injection architectural and says it will likely never be solved. The SE Radio show notes for Max Corbridge’s August 2026 episode describe agents as a new and largely undefended attack surface.
The reviewed sources describe the pain in the words of the company and its founder, and none of them quantifies it. Plexal’s announcement of a Laboratory for AI Security Research (LASR) cohort, sponsored by Cisco and HM Government, frames the wider need as the safe deployment of AI in high-stakes environments. [s1, s12, s19]
Adrian wraps an AI agent’s runtime through an SDK and sends each tool call, output and reasoning step to a backend that classifies it. The documentation says the backend assembles context across the agent’s session, sends each event to a classifier model and returns a verdict.
Adrian runs in three modes. Audit mode only reports alerts, and the documentation names it the default for most deployments. Human Review mode pauses potentially harmful actions until a person approves or rejects them, and Block mode stops actions the classifier deems malicious without human oversight. Alerts go to Slack and Discord, and approvals run through the dashboard at launch.
Integrations cover LangChain and the Anthropic client in Python, OpenAI clients through a TypeScript SDK, and a Claude Code plugin that classifies every tool call. The backend runs as a free hosted service on AWS infrastructure or self-hosted, where a bundled container serves the Gemma 4 model. The code is public on GitHub under the Apache 2.0 license.
Secure Agentics supplies the performance figures itself. The documentation cites a detection gain of around 35% that lab research by OpenAI and DeepMind found from combining behaviour and reasoning analysis. The hosted service documentation quotes roughly 100 to 600 ms per event classification. [s25, s4, s27, s24, s5]
Secure Agentics positions Adrian against monitoring that reads only an agent’s inputs or outputs. Its product page contrasts input and output filtering without reasoning access with analysis of reasoning traces before execution. The launch post says the security controls the team saw on the market operated almost entirely at the platform layer.
Open source is the second part of the positioning. The product page claims that no other open-source toolkit monitors and controls agents before they execute, a statement the company makes about itself. The documentation also contrasts Adrian’s reasoning-based approach with machine learning classifiers trained to spot patterns in their training data.
Black Hat’s judging panel listed Secure Agentics among the honorable mentions in its USA 2026 Startup Spotlight Competition, alongside four finalists selected to pitch at the event. The competition is open to startups five years old or less with fewer than 50 employees. [s3, s15, s4, s10]
Secure Agentics distributes Adrian as free open-source software. Its launch post of May 2026 says there is no paid tier and that the hosted backend is free forever under a fair-use policy. The GitHub repository records the open-source release on May 11, 2026 and a later Python SDK release to version 1.2.1.
The reviewed sources refer to enterprise customers without naming them. The launch post mentions optimization work with early enterprise customers and testing in energy, healthcare, service desk, e-commerce and coding. Max Corbridge told SE Radio about conversations with customers, and an IOActive speaker biography describes the company as helping central government and tier-1 banks adopt AI.
Max Corbridge told the Jersey Evening Post in August 2026 that Adrian had just under 4,000 downloads in its first five weeks. He also said the team is building a version of the product for businesses and that it is how the company will generate revenue.
Plexal and Black Hat supply the independent signals. Plexal named Secure Agentics to its LASR cohort on AI supply chain security in February 2026 and listed it among the LASR representatives it announced for its RSA delegation. Black Hat named it an honorable mention in its USA 2026 Startup Spotlight. [s15, s5, s12, s22, s11, s19, s20, s10]
Max Corbridge, the chief executive and co-founder, comes from offensive security. Petri reported in June 2023 that he and Tom Ellson of the JUMPSEC Labs red team discovered a Microsoft Teams flaw that could let attackers deliver malware to Teams users through federated chat. An IOActive speaker biography adds that he was a principal consultant and head of adversary simulation before founding the company.
He also speaks publicly on agent security. SE Radio, a podcast from the IEEE Computer Society and IEEE Software magazine, interviewed him in August 2026. The Jersey Evening Post profiled his move from legally breaking into banks to building a security monitoring system for AI.
Steve Street co-founded the company. The about page lists him as chief operating officer and says he co-founded Mindgard, an AI red-teaming company. The Jersey Evening Post’s August 2026 profile says Max Corbridge founded the business with the late Steve Street, and Companies House records his resignation as a director on 19 June 2026. [s2, s23, s22, s12, s11, s18]
Secure Agentics Ltd is a private limited company registered in London and incorporated on 16 July 2025. Its trust centre page is a privacy notice that covers UK and EU data protection law and routes data-subject requests to a legal representative’s portal. No security attestation appears on the probed surfaces.
The documentation describes how Adrian handles data. Self-hosted deployments send nothing to Secure Agentics. For the hosted service, Adrian redacts personal data in two layers, and stored events may be used for product improvement unless the customer opts out. The hosted classifier runs in an isolated environment with no tool, MCP or internet access. [s17, s7, s26]
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Secure Agentics offers Adrian as free open-source software that customers install inside their agents and operate themselves. In the documented default, alert-only mode, Adrian reports on agents without pausing their actions, and the modes that pause an action for a verdict are optional. The company’s edge is the engineering behind that verdict, since Adrian reads an agent’s reasoning and classifies each step fast enough to pause it, across agent tools from several vendors. A customer leaving Adrian would remove its SDK wiring.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Secure Agentics delivers SDKs and a backend that the customer’s team installs, configures with per-agent policies and alert thresholds, and operates, so the customer owns the outcomes. The hosted backend is a free managed service for running that software. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Customers wire Adrian’s SDK into their agents, write plain-English policies describing each agent, and route alerts to Slack or Discord, so leaving means removing that wiring and configuring alert routes elsewhere. The switching mechanism is documented, and the cited record does not size the migration or show non-portable state. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The trust centre page is a privacy notice covering UK and EU GDPR with a data-subject request portal, and no security attestation appears on the probed surfaces. No cited source names a regulation that requires this product or an authorization only Secure Agentics holds. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Adrian’s backend assembles context across an agent’s session and has a language model classify each event in real time. The documented expected latency on hosted GPUs is roughly 100 to 600 ms per event. The classifier is hardened against prompt injection and isolated from tools and the internet. Classifying events in real time requires ML engineering. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Buyer profile scores the buyer class the product is built and sold for. Max Corbridge told SE Radio that the company works with insurance companies running 17,000 agents in production, and his IOActive speaker biography describes Secure Agentics as helping central government and tier-1 banks adopt AI. Both accounts come from the company’s side and name no customer, and the Jersey Evening Post reports a business version still in development. The regulated-enterprise buyer class is credibly addressed, which meets rung 3. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | In Human Review mode, Adrian pauses potentially harmful actions until a person approves or rejects them. In Block mode, Adrian checks actions before execution and automatically blocks those classified as malicious. Audit mode is alert-only and is the documented default for most deployments. The reviewed sources show no deployment running in the blocking path, so Adrian is a platform with application features whose blocking of actions is optional. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The hosted service may store customer events for product improvement unless a customer opts out, and no cited source shows those events accumulated into a dataset or model the company retains. The self-hosted release sends nothing to Secure Agentics, and the code is published under the Apache 2.0 license. |
Secure Agentics builds for teams that run AI agents with real autonomy, from developers adding it to a LangChain agent with two lines of code to organizations in regulated sectors and critical national infrastructure. Its homepage lists autonomous agents, multi-step agent swarms, edge AI, high-trust or regulated environments and critical national infrastructure among the teams it builds for.
Secure Agentics addresses two segments. The open-source release addresses developers directly, with a two-line install and a free hosted backend. The regulated and infrastructure segment appears in the company’s positioning and in the LASR programme’s focus on monitoring AI at the edge for critical national infrastructure. An IOActive speaker biography also says the company helps central government and tier-1 banks adopt AI. The reviewed sources name no organization in either segment.
Adrian judges an agent’s reasoning as well as its actions. The documentation says most agent monitoring stops at activity logs, and that Adrian also analyses the agent’s reasoning traces to judge what it is about to do next.
The classifier is a language model. The launch post describes an LLM hardened against prompt injection and tuned for safety classifications. Customers describe each agent’s purpose, expected behavior and known risks in plain English so the model can judge contextual risk. The documentation contrasts that approach with machine learning classifiers trained to spot patterns in their training data. The hosted classifier runs isolated from tools, MCP and the internet, and the self-hosted release serves Gemma 4.
Secure Agentics supplies the performance evidence itself. The documentation cites a detection gain of around 35% that lab research by OpenAI and DeepMind found from combining behaviour and reasoning analysis. It gives hosted latency of roughly 100 to 600 ms per event. No independent test of Adrian’s detection appears in the reviewed sources.
Secure Agentics leads with free open-source distribution. Adrian launched publicly in May 2026 under the Apache 2.0 license, and the launch post says the hosted backend is free forever.
The reviewed sources refer to enterprise customers without naming them. The launch post mentions optimization work with early enterprise customers, and Max Corbridge told SE Radio about conversations with customers. He also said on the show that somebody had built out a TypeScript SDK after the Python launch. He told the Jersey Evening Post that Adrian had just under 4,000 downloads in its first five weeks and that a version for businesses is being built to generate revenue.
Plexal and Black Hat supply the independent signals. Plexal describes Secure Agentics as a developer of monitoring and control software for agentic AI. Black Hat named it an honorable mention in its USA 2026 Startup Spotlight Competition.
Adrian is free. The launch post says there is no paid tier and no Pro upsell, and that the hosted backend is free forever under a fair-use policy. The documentation describes the self-hosted release as an open-source option for teams that prefer to run it locally or need data sovereignty.
No price list appears in the cited sources, and the company’s /pricing path returns a 404 page. Max Corbridge told the Jersey Evening Post in August 2026 that the team is building a version for businesses and that it is how the company will generate revenue.
Customers run Adrian in one of two ways. Secure Agentics runs the hosted backend on managed AWS infrastructure and server-grade GPUs. The self-hosted release brings up a Go backend, a Next.js dashboard and a model container with a single Docker Compose command after a one-shot bootstrap.
The customer’s team operates the product. Teams choose Audit, Human Review or Block mode, set alerting thresholds and notification preferences per deployment, and handle approvals through the dashboard. The GitHub repository records the open-source release on May 11, 2026 and a later Python SDK release to version 1.2.1.
Secure Agentics Ltd is a London company incorporated on 16 July 2025. Its trust centre page is a privacy notice covering UK and EU data protection law, with data-subject requests routed to a legal representative’s portal. No security attestation appears on the probed surfaces.
The documentation covers data handling and the classifier’s own defenses. Self-hosted deployments send no data to Secure Agentics. The hosted service applies two layers of personal-data redaction, and stored events may be used for product improvement unless the customer opts out. The hosted classifier runs with no tool, MCP or internet access, which the documentation says bounds the damage if it is compromised.
Adrian plugs into the agent tools developers already use. Supported integrations are LangChain and the Anthropic client in Python, OpenAI clients through a TypeScript SDK, and a Claude Code plugin that hooks every tool call with no code to write. The company lists OpenClaw, the OpenAI Agents SDK and CrewAI as integrations it is exploring.
The GitHub repository publishes the SDKs, backend and deployment files under the Apache 2.0 license. Alerts go to Slack and Discord.
Max Corbridge, the chief executive and co-founder, brings offensive-security experience. Petri reported in June 2023 that he and Tom Ellson of the JUMPSEC Labs red team discovered a Microsoft Teams flaw that could let attackers deliver malware through federated chat. An IOActive speaker biography says he was a principal consultant and head of adversary simulation before founding the company.
He speaks publicly on agent security, including an August 2026 SE Radio interview and a Jersey Evening Post profile.
Steve Street co-founded the company, and the about page lists him as chief operating officer and a co-founder of the AI red-teaming company Mindgard. The Jersey Evening Post’s August 2026 profile says Max Corbridge founded the business with the late Steve Street, and Companies House records his resignation as a director on 19 June 2026.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Secure Agentics homepage | official | 2026-09-23 |
| f2 | Companies House: SECURE AGENTICS LTD overview | regulatory | 2026-09-23 |
| f3 | AI Defense Matrix Catalog mapping | other | 2026-09-23 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.