Skip to content
Home

zeroroot

A zero-trust runtime for AI agents that enforces named-person grants, isolates untrusted tool runs in microVMs, and records every action to a replayable timeline

The product is a zero-trust runtime for AI agents that enforces identity, delegated grants, and auditable execution to pass security review. It addresses uncontrolled agent actions by requiring a named person grant, isolating tool runs in microVMs, and recording every action to a replayable timeline. It is for developers, IT and security teams in B2B organizations including defense, government, financial services, healthcare and critical infrastructure. It is delivered as SaaS or self-hosted in the customer's Kubernetes cluster, including fully air-gapped, with open source ADK, CLI and components.

Key features

  • Zero-trust agent runtime with identity and grants
  • Grants limited to named-person delegation
  • Missions as typed work graphs checked at submit
  • Dispatch policy: microVM, in-process, or refused
  • MicroVM per tool run on own kernel
  • Declared egress per component
  • Timeline logging every agent event
  • Replay any run move by move
  • Knowledge graph of hosts, paths, findings
  • Console to create and watch missions
  • Set grants and budgets in console
  • Browse traces and knowledge graph
  • Six controls: enforced, conditional, structural
  • ADK and gibson CLI to build agents
  • Zerocool coding agent with reviewable commits
  • Bridge for MCP-compliant tools as components
  • Kubernetes-based runtime and execution environment
  • Self-hosted or vendor-hosted deployment
  • Air-gapped and no-egress deployment option
Social posts
  • No social media activity detected
GTM channels
  • Partner program
  • Marketplace
  • Docs
ICP
  • Software developers
  • Security teams
  • IT teams