2

prior acquisitions, same founding team

3

co-founders, in the room every day

2010

Smobile acquired by Juniper Networks

2016

InAuth acquired by American Express

Mission

Make every AI agent in a bank accountable, observable, and reversible.

Banks are about to deploy AI agents that move money, decide credit, talk to customers, and call internal systems on behalf of operators they cannot reliably identify. The risk surface is not the model. It is the agent. BladeRun gives banks a runtime governance layer for that surface, with the cryptographic provenance, federation, and operator-grade controls that the rest of the stack assumes.

Why this company exists now

The AI agent attack surface mirrors mobile banking, 2010.

A new compute surface enters the bank. The fraud teams discover that none of the existing controls translate. There is a two-year window where everyone deploys, the attacks land, and one or two control-plane companies become the standard. Mobile banking went through this from 2009 to 2012. AI agents are going through it now.

2010 / Mobile

What happened with mobile banking.

Banks shipped mobile apps. Fraud followed within twelve months. The web-fraud stack did not transfer, different signal surface, different identity model, different attack shape. Smobile shipped a runtime control plane for that surface. Two years later it was a category, and the founders sold the company to Juniper.

  • New surface, same problem shape. Identity, runtime control, evidence chain.
  • Two-year category window. The control plane that ships first becomes the default.
  • Federation matters. Cross-bank signal sharing was the unlock, and it stayed an unlock at InAuth.
2026 / AI agents

What is happening with AI agents now.

Banks are shipping AI agents, copilots, conversational, multi-agent orchestrators, autonomous research, agentic commerce on the merchant side. Fraud is following on the same calendar. The web and mobile stacks do not transfer. BladeRun is the runtime control plane for this surface. The founding cohort is being built right now.

  • The agent is the principal. Identity at runtime, not at deploy time.
  • Inspect every call. Prompt, response, MCP endpoint, tool call. Under 15ms.
  • Federation, designed in. One-way signal hashes from day one. No retrofit.
Market

$13.5B

agentic AI security market by 2032, up from $1.65B in 2026.

Growth

42%

CAGR, faster than any adjacent security segment.

Consolidation

8

platform acquisitions in one consolidation wave, Lakera, Pangea, CalypsoAI, Aim, and more.

Founders

Three co-founders. Two prior acquisitions. One domain.

We have built this kind of company before. The team that shipped Smobile and InAuth is the same team building BladeRun, with the same operating cadence and the same insistence on shipping product the bank can actually deploy.

Co-founder & CEO

Mike Patterson

Chief Executive Officer

Mike led Smobile through to the Juniper acquisition and ran the runtime security business inside InAuth before American Express. He runs the founding cohort directly, every design partner conversation, every roadmap call. His job at BladeRun is to make sure the platform that ships matches what the regulated institutions actually need to deploy in production.

prev · CEO Smobile (acq. Juniper) · GM InAuth (acq. Amex)
Co-founder & CTO

Paul Marsolan

Chief Technology Officer

Paul is the platform architect. He shipped the runtime engine for Smobile, the device-trust core inside InAuth, and is now responsible for the BladeRun Gateway, Sentinel SDK, Overseer behavioral engine, and the cryptographic primitives behind the Federation Network. He owns the architecture decisions that determine whether the platform survives ten years of bank deployment.

prev · CTO Smobile · principal engineer InAuth
Co-founder & CSO

Chris Moos

Chief Security Officer

Chris owns the threat model, the regulator and auditor surface, and the security review path that every Tier 1 bank runs vendors through. He led security at InAuth, has stood in front of every major US and EU bank security review board, and now runs the BladeRun side of the VRA, ARB, and InfoSec workstreams for the design partner cohort.

prev · CSO InAuth
Company history

Same founders. Three companies. Same domain.

Each shift has the same shape: a new compute surface, a fraud wave inside two years, and a runtime control plane that becomes the standard. We are at the start of the third one.

2008 to 2010

Smobile

Runtime security for the mobile platform shift. The first mobile banking apps shipped without a runtime control plane. Smobile built it, acquired by Juniper Networks in 2010.

2011 to 2016

InAuth

Device trust and federation for global banking. Mobile fraud landed; the same team built the device-trust layer that scaled across Tier 1 banks, acquired by American Express in 2016.

2024

BladeRun founded

Same three co-founders. New surface: AI agents calling LLM providers, MCP endpoints, and internal systems on behalf of operators the bank cannot reliably identify at runtime.

2026

Design partner cohort

Three to five Tier 1 banks join the closed design partner program. Founding Federation seats issued. Enterprise GA pricing and reference architectures follow in 2027.

Operating principles

How we run this company.

A short list. We have published it for the design partner cohort and we hold ourselves to it in writing.

Owner-position language, always.

We do not say "your bank failed." We say "here is the surface that needs governance and here is what we ship to govern it." Every conversation, internal or external.

Ship to the regulated institution, not to the demo.

We will not promise a feature that cannot survive a Tier 1 bank VRA. Every release ships with the deployment artifacts and the audit trail required to land in production.

Federation is privacy-first, by construction.

One-way signal hashes, k-anonymity, double-blind membership. The Federation contract is reviewed on a separate signoff path so the platform contract is not gated by federation legal review.

The founders read every customer email.

Every inbound email is read by Mike, Paul, or Chris. We will scale operations as the company grows, but founder-customer access remains an inherent part of the relationship at every tier.

Reversible, audited, and contained.

Every BladeRun control is reversible by routing rule or policy flip. Every action is audited end-to-end. Every containment is per-agent first, fleet-wide second, and surgical by default.

One platform, no tier-gating on coverage.

Detection coverage, redaction classes, and Federation rule channels are not pay-to-unlock. The same components ship in every deployment regardless of tier.

Investors & advisors

Quiet for now. Announced with the design partner cohort.

2026 cohort · announcementpending

Investor and advisor announcements are coming with the design partner cohort. We are deliberately quiet on the cap table and the advisor bench until the founding bank cohort is set. Both will be announced together so the institutions joining the program have full visibility on the company's backing and governance at the moment they sign on.

Talk to the founders

The same team. A third time.

If you ran a bank security review against Smobile or InAuth, you have already worked with us. We would like to do that again, this time on the surface that actually matters next.