Skip to content
a company · est. 2026

Enforcement infrastructure for the agent era.

Lictorate is a company building the runtime layer that sits between AI agents and the systems they touch — so a confident model never becomes a catastrophic one. We start with one product, deeply.

2026founded
1product, public
thesis

The trust boundary moved — and almost no one is guarding it.

For thirty years, the line between human intent and system action sat at the keyboard. Models with tools removed the gap. The security model has not caught up.

01 / OBSERVATION

Agents act, not suggest.

Tool calls. Browser control. Code execution. The agent reads, decides, and reaches into real systems — the same loop, no person between the intent and the consequence.

02 / GAP

Detection is too late.

Audit logs and evals record what already cost you something. An audit without enforcement is a confession, not a control. Agents need a firewall, not just an IDS.

03 / WHERE WE FIT

The runtime is where authority lives.

Not the model. Not the prompt. Not the framework. The line must hold in the runtime — deterministic, auditable, and unable to be argued with by a long enough message.

principles

Detection is too late. Authority comes before action.

Three rules we hold to. They shape every API, default, and release.

what we ship

One product, deeply. The runtime first.

Lictorate is the company. The products below are how the thesis reaches the world. We start narrow on purpose — and the core stays open, forever.

live · v0.6 released

AgentGuard

open-source runtime firewall for AI agents

View GitHub

Protect, rate-limit, and audit AI workloads with isolated tenant policies at 0.53 ms p99 latency. Drop in our LLM API Proxy or MCP Gateway, write your YAML rules, and get fully stateful enforcement powered by a write-behind embedded SQLite store.

Core
Go 1.22 (0.53ms p99 latency)
State
Embedded SQLite (Zero-config)
Policy
Multi-tenant YAML
Gateways
MCP · LLM API · SDKs
multi-tenant managed proxy

AgentGuard Cloud

fleet routing, central dashboard, team audit sync

waitlist open

For teams managing multiple agents in production. Shared policy libraries, global rate limits, live SSE action feeds for central human approposals, and exportable SOC-ready audit logs. The core proxy stays open; this is the control plane.

who

Fast. Infrastructure-focused. Security-first.

Lictorate is, today, one founder and a runtime. Mail goes to a person. Pull requests are read. We are deliberately focused on building the definitive routing layer for AI agents.

Cauã Ferraz· founder · backend & systems

Backend and systems engineer. Started Lictorate to build the enforcement layer the agent stack is missing — the boring, load-bearing kind of infrastructure, the kind you only notice when it isn’t there.

Authority before the act.

That’s the whole company in five words. If you’re building with agents and want centralized guardrails across your fleet, join the waitlist.