prior acquisitions, same founding team
co-founders, in the room every day
Smobile acquired by Juniper Networks
InAuth acquired by American Express
Banks are about to deploy AI agents that move money, decide credit, talk to customers, and call internal systems on behalf of operators they cannot reliably identify. The risk surface is not the model. It is the agent. BladeRun gives banks a runtime governance layer for that surface, with the cryptographic provenance, federation, and operator-grade controls that the rest of the stack assumes.
A new compute surface enters the bank. The fraud teams discover that none of the existing controls translate. There is a two-year window where everyone deploys, the attacks land, and one or two control-plane companies become the standard. Mobile banking went through this from 2009 to 2012. AI agents are going through it now.
Banks shipped mobile apps. Fraud followed within twelve months. The web-fraud stack did not transfer, different signal surface, different identity model, different attack shape. Smobile shipped a runtime control plane for that surface. Two years later it was a category, and the founders sold the company to Juniper.
Banks are shipping AI agents, copilots, conversational, multi-agent orchestrators, autonomous research, agentic commerce on the merchant side. Fraud is following on the same calendar. The web and mobile stacks do not transfer. BladeRun is the runtime control plane for this surface. The founding cohort is being built right now.
agentic AI security market by 2032, up from $1.65B in 2026.
CAGR, faster than any adjacent security segment.
platform acquisitions in one consolidation wave, Lakera, Pangea, CalypsoAI, Aim, and more.
We have built this kind of company before. The team that shipped Smobile and InAuth is the same team building BladeRun, with the same operating cadence and the same insistence on shipping product the bank can actually deploy.
Mike led Smobile through to the Juniper acquisition and ran the runtime security business inside InAuth before American Express. He runs the founding cohort directly, every design partner conversation, every roadmap call. His job at BladeRun is to make sure the platform that ships matches what the regulated institutions actually need to deploy in production.
Paul is the platform architect. He shipped the runtime engine for Smobile, the device-trust core inside InAuth, and is now responsible for the BladeRun Gateway, Sentinel SDK, Overseer behavioral engine, and the cryptographic primitives behind the Federation Network. He owns the architecture decisions that determine whether the platform survives ten years of bank deployment.
Chris owns the threat model, the regulator and auditor surface, and the security review path that every Tier 1 bank runs vendors through. He led security at InAuth, has stood in front of every major US and EU bank security review board, and now runs the BladeRun side of the VRA, ARB, and InfoSec workstreams for the design partner cohort.
Each shift has the same shape: a new compute surface, a fraud wave inside two years, and a runtime control plane that becomes the standard. We are at the start of the third one.
Runtime security for the mobile platform shift. The first mobile banking apps shipped without a runtime control plane. Smobile built it, acquired by Juniper Networks in 2010.
Device trust and federation for global banking. Mobile fraud landed; the same team built the device-trust layer that scaled across Tier 1 banks, acquired by American Express in 2016.
Same three co-founders. New surface: AI agents calling LLM providers, MCP endpoints, and internal systems on behalf of operators the bank cannot reliably identify at runtime.
Three to five Tier 1 banks join the closed design partner program. Founding Federation seats issued. Enterprise GA pricing and reference architectures follow in 2027.
A short list. We have published it for the design partner cohort and we hold ourselves to it in writing.
We do not say "your bank failed." We say "here is the surface that needs governance and here is what we ship to govern it." Every conversation, internal or external.
We will not promise a feature that cannot survive a Tier 1 bank VRA. Every release ships with the deployment artifacts and the audit trail required to land in production.
One-way signal hashes, k-anonymity, double-blind membership. The Federation contract is reviewed on a separate signoff path so the platform contract is not gated by federation legal review.
Every inbound email is read by Mike, Paul, or Chris. We will scale operations as the company grows, but founder-customer access remains an inherent part of the relationship at every tier.
Every BladeRun control is reversible by routing rule or policy flip. Every action is audited end-to-end. Every containment is per-agent first, fleet-wide second, and surgical by default.
Detection coverage, redaction classes, and Federation rule channels are not pay-to-unlock. The same components ship in every deployment regardless of tier.
Investor and advisor announcements are coming with the design partner cohort. We are deliberately quiet on the cap table and the advisor bench until the founding bank cohort is set. Both will be announced together so the institutions joining the program have full visibility on the company's backing and governance at the moment they sign on.
If you ran a bank security review against Smobile or InAuth, you have already worked with us. We would like to do that again, this time on the surface that actually matters next.