ThirdKey builds tools for secure, privacy-first, and verifiable AI agents.
Our flagship project is Symbiont — a zero-trust runtime for autonomous AI agents with policy enforcement, cryptographic identity, and sandboxed execution.
🌐 Featured Project: Symbiont
Symbiont is a zero-trust runtime for autonomous AI agents with Cedar policy authorization, inter-agent communication governance, ToolClad declarative tool contracts, multi-tier sandboxing (Docker → gVisor → Firecracker), and a declarative DSL.
- 🔐 Cedar policy engine, CommunicationPolicyGate, cryptographic audit trails
- 🧩 Declarative DSL with tree-sitter parsing,
symbi init/run/upCLI - 🛠️ ToolClad integration — declarative
.clad.tomltool contracts with typed validation - 🕸️ Inter-agent governance, ORGA reasoning loop, SchemaPin/AgentPin identity
- ⚙️ Written in Rust for maximum performance and safety
👉 Explore the code: github.com/ThirdKeyAI/Symbiont
- ThirdKey Research Hub — Read our whitepapers, designs, and future vision.
- ThirdKey Homepage — Overview of our mission and team.
| Project | Description |
|---|---|
| 🔐 SchemaPin | Cryptographic protocol for signing AI tool schemas and policies |
| 🪪 AgentPin | Domain-anchored cryptographic identity for AI agents |
| 👃 AgentSniff | Detect AI agents operating on your network |
| 🛡️ ToolClad | Declarative tool interface contracts for agentic runtimes (oneshot, session, browser) |
| 🕶️ AgentNull | Reference implementation of a restricted LLM agent for security testing |
| 📦 VectorSmuggle | Covert data exfiltration via vector embeddings (research prototype) |
- 🌐 Website: thirdkey.ai
- 🔬 Research: research.thirdkey.ai
- 🧠 Symbiont: symbiont.dev
ThirdKey.ai — Infrastructure for AI you can trust.