Skip to content
a company · est. 2026

Enforcement infrastructure for the agent era.

Lictorate is a company building the runtime layer that sits between AI agents and the systems they touch — so a confident model never becomes a catastrophic one. We start with one product, deeply.

2026founded
1product, public
thesis

The trust boundary moved — and almost no one is guarding it.

For thirty years, the line between human intent and system action sat at the keyboard. Models with tools removed the gap. The security model has not caught up.

01 / OBSERVATION

Agents act, not suggest.

Tool calls. Browser control. Code execution. The agent reads, decides, and reaches into real systems — the same loop, no person between the intent and the consequence.

02 / GAP

Detection is too late.

Audit logs and evals record what already cost you something. An audit without enforcement is a confession, not a control. Agents need a firewall, not just an IDS.

03 / WHERE WE FIT

The runtime is where authority lives.

Not the model. Not the prompt. Not the framework. The line must hold in the runtime — deterministic, auditable, and unable to be argued with by a long enough message.

principles

Detection is too late. Authority comes before action.

Three rules we hold to. They shape every API, default, and release.

what we ship

One product, deeply. The runtime first.

Lictorate is the company. The products below are how the thesis reaches the world. We start narrow on purpose — and the core stays open, forever.

open source · v1.0.0

AgentGuard

open-source runtime firewall for AI agents

View GitHub

Wire-level enforcement at the protocol boundary: put AgentGuard on the wire — as an MCP gateway or an LLM API proxy — write YAML rules, and every tool call is allowed, denied, or held for human approval at 0.53 ms p99. Stateful, multi-tenant, and audited — zero-config SQLite on a single node, or PostgreSQL for shared state across replicas.

Core
Go 1.25 (0.53 ms p99, measured)
State
SQLite (single-node) · PostgreSQL (multi-node)
Policy
Multi-tenant YAML
Enforcement
MCP gateway · LLM API proxy · SDKs
hosted · multi-tenant · in design

AgentGuard Cloud

fleet routing, central dashboard, team audit sync

waitlist open

For teams managing multiple agents in production. Shared policy libraries, global rate limits, live action feeds for central human approvals, and exportable SOC-ready audit logs. The core firewall stays open; this is the control plane.

who

Fast. Infrastructure-focused. Security-first.

Lictorate is, today, one founder and a runtime. Mail goes to a person. Pull requests are read. We are deliberately focused on building the enforcement layer for AI agents — the firewall between an agent and the systems it touches.

Cauã Ferraz· founder · backend & systems

Backend and systems engineer. Started Lictorate to build the enforcement layer the agent stack is missing — the boring, load-bearing kind of infrastructure, the kind you only notice when it isn’t there.

Policy precedes action.

lex antecedit actum

That’s the whole company in three words. If you’re building with agents and want centralized guardrails across your fleet, join the waitlist.