AI Safety &
Resilience.
As agents gain access to code, data, money and critical workflows, security moves from perimeter defense to runtime control. We invest in the infrastructure that keeps autonomous systems observable, constrained and recoverable.
Security becomes
the adoption layer.
More capable agents create real productivity — but only if organizations can trust what they access, what they execute and what happens when they fail. The control layer can become as foundational to AI adoption as identity and endpoint security became to cloud computing.
AI red teaming
Security testing shifts from periodic human pentests toward continuous, AI-native adversarial systems that can discover, validate and prioritize attacks at machine speed.
What we look for
Systems that turn offensive security into a continuous feedback loop across applications, agents and infrastructure — with evidence of exploitability rather than endless vulnerability lists.
Continuous offensive security
Felicis frames Terra Security around replacing slow, episodic penetration testing with continuous AI-augmented offensive security.
Read source →AI scales the attacker too
Sequoia’s Corma thesis argues that AI is increasing offensive capability and that defenders need purpose-built AI systems that can reason and respond at similar speed.
Read source →Agent control
The defining enterprise problem is no longer just “is this model safe?” It is “what is this agent allowed to access, execute and spend — and can we prove and stop it in real time?”
What we look for
The identity, permission and runtime policy layer for non-human actors. Winning platforms should sit directly in the execution path, not only generate dashboards after the fact.
Agent access is the bottleneck
Sequoia’s Cymphony thesis identifies control over agent data access — what agents can reach and what they did — as a major constraint on enterprise AI adoption.
Read source →Identity built for humans does not fit agents
a16z’s Keycard thesis argues that agent fleets require a new permissions and identity architecture because human IAM assumptions break under autonomous, fast-changing actors.
Read source →The missing category is the control loop
Felicis’s CISO research describes AI security budget as growing while the operational control layer remains immature and unconsolidated.
Read source →Secure AI infrastructure
The AI stack itself becomes critical infrastructure: inference, tools, plugins, model supply chains, sandboxes, secrets and compute all become new attack surfaces.
What we look for
Security systems embedded into the infrastructure on which AI runs — especially where they can enforce policy at execution time or protect shared agent ecosystems and supply chains.
AI creates a new software supply chain
Sequoia’s Air thesis focuses on the plugins, skills and external components imported by agents as a new supply-chain security problem.
Read source →AI infrastructure is entering a massive buildout
a16z’s Machine Age Fund explicitly targets the physical and systems infrastructure on which AI runs — chips, memory, networking, storage and full systems.
Read source →Enterprise agents need a secure runtime layer
Felicis describes Runlayer as a missing control layer between enterprise productivity gains and unresolved runtime security.
Read source →What has to be true.
The product should enforce or influence agent behavior in real time, not only observe risk after the action is complete.
We prefer problems tied to a clear buyer — CISO, platform security, identity, infrastructure or AI governance — with measurable downside avoided.
Distribution improves when the product owns identity, policy, runtime, telemetry or a critical integration surface.
Security should improve with usage through attack data, policy feedback, workflow context or proprietary execution signals.
Investor and market signals
Public investor theses and portfolio examples are included as market signals only. They are not Freedom Vault portfolio companies unless explicitly stated elsewhere.
