zeroroot
A zero-trust runtime for AI agents that enforces named-person grants, isolates untrusted tool runs in microVMs, and records every action to a replayable timeline
The product is a zero-trust runtime for AI agents that enforces identity, delegated grants, and auditable execution to pass security review. It addresses uncontrolled agent actions by requiring a named person grant, isolating tool runs in microVMs, and recording every action to a replayable timeline. It is for developers, IT and security teams in B2B organizations including defense, government, financial services, healthcare and critical infrastructure. It is delivered as SaaS or self-hosted in the customer's Kubernetes cluster, including fully air-gapped, with open source ADK, CLI and components.
Key features
- Zero-trust agent runtime with identity and grants
- Grants limited to named-person delegation
- Missions as typed work graphs checked at submit
- Dispatch policy: microVM, in-process, or refused
- MicroVM per tool run on own kernel
- Declared egress per component
- Timeline logging every agent event
- Replay any run move by move
- Knowledge graph of hosts, paths, findings
- Console to create and watch missions
- Set grants and budgets in console
- Browse traces and knowledge graph
- Six controls: enforced, conditional, structural
- ADK and gibson CLI to build agents
- Zerocool coding agent with reviewable commits
- Bridge for MCP-compliant tools as components
- Kubernetes-based runtime and execution environment
- Self-hosted or vendor-hosted deployment
- Air-gapped and no-egress deployment option
- No social media activity detected
- Partner program
- Marketplace
- Docs
- Software developers
- Security teams
- IT teams