Skip to main content

About Sondera

Built for the teams turning agents on.

Sondera is an AI agent security company building the enforcement layer for autonomous behavior.

Why we exist

Autonomy shipped faster than the controls for it

Agents crossed from copilots to coworkers in a single product cycle. They take real actions in real systems — and the security around them was built for software that only ever suggested.

"The agent incidents we see today aren't from prompt injection and hijacking. They're from authorized humans asking authorized agents to do legitimate tasks."
Josh Devon { Co-founder & CEO }

Sondera exists to close that gap: to make what you intend the thing that actually runs, every time, with the proof to back it.

  1. Agents act, they don't just answer

    A model that writes text can be reviewed. An agent that moves money, edits data, and calls tools acts before anyone reads a word.

  2. The risk is behavioral, not who's logged in

    Most incidents aren't hijacked agents — they're authorized agents doing authorized-looking things nobody meant to allow. Identity can't see that. Behavior can.

  3. Trust has to be provable, not promised

    "It should be safe" doesn't survive an audit. Autonomy ships when you can show exactly what was allowed, what was blocked, and on whose rule.

The lab · Secure Trajectories

Proof, not promises

Enforcement is only as good as the research behind it. We study how agents fail in the open, publish what we find, and turn it into policy you can check before an action runs.

Founding team

Security builders. Platform operators.

A small team that has spent careers in threat intelligence, ML security, and formal methods — now pointed at the hardest problem in agentic AI.

  • Josh Devon

    Josh Devon

    Co-Founder and CEO

    Co-founded Flashpoint. Two decades building security businesses from earliest stage to public-market scale.

  • Matt Maisel

    Matt Maisel

    Co-Founder and CTO

    Engineering leader at BlackBerry Cylance, Obsidian Security, and NetRise.

  • Tyler Predale

    Tyler Predale

    Co-Founder and COO

    Former IT and security operations leader at Flashpoint.

Experience built across

Companies the founding team has built security at

  • Flashpoint Security markets
  • NetRise Software supply chain
  • AWS Cloud scale
  • Obsidian Security SaaS security
  • Cylance AI security
  • Databricks Data platforms

Backed by

Investors who understand the category.

  • Decibel
  • Runtime
  • Aviso

Angel investors

Security leaders in the room.

Obsidian
Ben Johnson
CTO
Flashpoint
Josh Lefkowitz
CEO
Duo
Jon Oberheide
CTO
GreyNoise
Ash Devata
CEO
Zscaler
Deepen Desai
CISO

Advisor perspective

Built for high-stakes autonomy.

  • “Building AI agents for high-stakes environments demands more than improved prompts; it requires a resilient architecture capable of distinguishing between intended instructions and adversarial inputs. Sondera’s action-layer interception provides the technical foundation for trustworthy, mission-ready AI.”

    Amyn Jan { Defense and National Security Executive, Sondera Advisor }
  • “As agents move from co-pilots to autonomous workers, the traditional boundaries of user and machine identity collapse. We need a control plane that treats agent behavior as the primary unit of risk. Sondera provides the deterministic infrastructure required to manage this new, autonomous workforce at scale.”

    Kevin Walsh { CISO }

How we work

The principles behind the product

The same convictions run through the lab and the platform. They're why Sondera behaves the way it does.

Determinism

Deterministic, outside the model

We don't ask a model to police a model. Enforcement runs outside the context window as a hard rule — so prompt injection and drift can't argue their way past it.

Recoverability

Steer, don't block

A denied action isn't a dead end. Sondera hands the agent the reason it was stopped, so it can find a safe way to finish the job.

Rehearsal

Prove it before you ship it

Nothing goes live on a hunch. A policy earns production by surviving replay against real and adversarial trajectories first.

Openness

Build in the open

Our research, docs, and code are public. Security that asks for blind trust isn't security — so we show our work.

Work with Sondera

Give agents boundaries they cannot talk their way around.

Bring the agent you don't yet trust in production. We'll show you what it takes to enforce your policy on every action — and prove it.