Josh Devon
Co-Founder and CEO
Co-founded Flashpoint. Two decades building security businesses from earliest stage to public-market scale.
About Sondera
Sondera is an AI agent security company building the enforcement layer for autonomous behavior.
Why we exist
Agents crossed from copilots to coworkers in a single product cycle. They take real actions in real systems — and the security around them was built for software that only ever suggested.
"The agent incidents we see today aren't from prompt injection and hijacking. They're from authorized humans asking authorized agents to do legitimate tasks."
Sondera exists to close that gap: to make what you intend the thing that actually runs, every time, with the proof to back it.
A model that writes text can be reviewed. An agent that moves money, edits data, and calls tools acts before anyone reads a word.
Most incidents aren't hijacked agents — they're authorized agents doing authorized-looking things nobody meant to allow. Identity can't see that. Behavior can.
"It should be safe" doesn't survive an audit. Autonomy ships when you can show exactly what was allowed, what was blocked, and on whose rule.
The lab · Secure Trajectories
Enforcement is only as good as the research behind it. We study how agents fail in the open, publish what we find, and turn it into policy you can check before an action runs.
Founding team
A small team that has spent careers in threat intelligence, ML security, and formal methods — now pointed at the hardest problem in agentic AI.
Co-Founder and CEO
Co-founded Flashpoint. Two decades building security businesses from earliest stage to public-market scale.
Co-Founder and CTO
Engineering leader at BlackBerry Cylance, Obsidian Security, and NetRise.
Co-Founder and COO
Former IT and security operations leader at Flashpoint.
Experience built across
Security markets Backed by
Angel investors
Advisor perspective
“Building AI agents for high-stakes environments demands more than improved prompts; it requires a resilient architecture capable of distinguishing between intended instructions and adversarial inputs. Sondera’s action-layer interception provides the technical foundation for trustworthy, mission-ready AI.”
“As agents move from co-pilots to autonomous workers, the traditional boundaries of user and machine identity collapse. We need a control plane that treats agent behavior as the primary unit of risk. Sondera provides the deterministic infrastructure required to manage this new, autonomous workforce at scale.”
How we work
The same convictions run through the lab and the platform. They're why Sondera behaves the way it does.
Determinism
We don't ask a model to police a model. Enforcement runs outside the context window as a hard rule — so prompt injection and drift can't argue their way past it.
Recoverability
A denied action isn't a dead end. Sondera hands the agent the reason it was stopped, so it can find a safe way to finish the job.
Rehearsal
Nothing goes live on a hunch. A policy earns production by surviving replay against real and adversarial trajectories first.
Openness
Our research, docs, and code are public. Security that asks for blind trust isn't security — so we show our work.
Work with Sondera
Bring the agent you don't yet trust in production. We'll show you what it takes to enforce your policy on every action — and prove it.