Skip to main content

Refractal

Refractal provides security infrastructure for high-assurance AI, offering a control plane that enforces policy on agent tool calls, data access, and model swaps in real time. The platform hooks into agent actions, evaluates them against compliance rules, and blocks, flags, or escalates events while maintaining an append-only, cryptographically signed audit ledger. It integrates with observability tools like Langfuse and OpenTelemetry, enabling teams to stress test, protect, and remain compliant across production AI deployments.

San Francisco, United States · HQ
Founded 202691K+ followers
Updated yesterday

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

AI agents now act autonomously—browsing, querying, and executing transactions—creating new attack surfaces that are structurally vulnerable to prompt injection, jailbreaks, and data exfiltration. Each model carries different security policies, leaving companies without a unified layer to enforce safety and compliance across their agentic systems.

Solution

Refractal builds security infrastructure for high-assurance AI, positioning itself as a control plane for non-deterministic systems. It sits between agents and the tools, data, and users they interact with, enforcing policy at the point of action rather than after the fact. The platform operates through a four-stage pipeline: hooks trigger before key actions (tool calls, data reads, model swaps), rules are evaluated with minimal latency, events are blocked, flagged, or escalated based on severity, and all actions are recorded in an append-only, cryptographically signed audit ledger. This allows organizations to stress test agents before deployment, protect them in production, and maintain regulatory compliance through deterministic, testable, and versioned rules.

Target Audience

Primary customers are security, compliance, and ML engineering teams at enterprises deploying high-assurance AI agents that require strict governance, auditability, and protection against adversarial attacks.

Features

  • Real-time hook system that captures identity, intent, and context before agent actions such as tool calls, data reads, and model swaps
  • Policy engine that compiles rules from regulatory posture into deterministic, testable, and versioned evaluations with minimal latency
  • Action routing based on severity, including blocking, flagging, or escalating critical events to on-call compliance teams
  • Append-only, cryptographically signed audit ledger mapped to named controls for compliance reporting
  • Integration with major observability stacks, including Langfuse, LangSmith, and OpenTelemetry, for tracing, evals, and telemetry
  • Designed to run on top of existing infrastructure, enforcing policy without replacing the underlying AI stack
This profile is AI-generated and may contain inaccuracies.