Protecting organisations and critical infrastructure from AI-powered social engineering and insider threats.
Protecting organisations and critical infrastructure from AI-powered social engineering and insider threats.
Project Details
Updated 07/13/26 · Provided via application · VerifiedStronghold is building a User and Entity Behaviour Analytics (UEBA) platform that monitors human employees and AI agents inside enterprises, and the interactions between them; it is the first platform to do so. Most existing UEBA platforms watch either human users or AI agents, but not both, and none of them look at the interaction between the two. None of them learn a behavioural baseline for an agent and use it to flag drift, social engineering, insider threats, or misaligned agent behaviour in real time. Our platform also gives security teams the ability to contain threats automatically, using workflows that trigger the moment a threat is detected.
The platform works in three stages. First, an SDK wraps calls to major model providers and builds a 30-day behavioural baseline for every user and agent. Second, a detection engine combines statistical, sequence-based, and ML-driven anomaly scoring against that baseline. Third, a five-level containment model escalates the response automatically, from enhanced logging up to full agent termination.
The team: I'm Robert Sidey, Co-Founder and CEO, an AI safety and security researcher and engineer, and a Master's student in Computer Science with a machine learning specialisation at Georgia Tech. My co-founder, Grant Sidey, is COO, with 30 years of experience at Scotland Yard, the Ministry of Defence, and the Serious Organised Crime Agency, including Five Eyes investigation work. We've already launched pilots with Fortune 500 companies and are working to protect critical infrastructure across Asia and Europe.
The concrete output of this project is a fully developed platform deployed into critical infrastructure and to security teams at Fortune 500 companies worldwide. We will build a product actively used in the real world to prevent AI-powered social engineering, insider threats, and agentic misalignment.
Theory of Impact
Updated 07/13/26 · By grantmaking.aiAs enterprises deploy increasing numbers of autonomous agents with real tool access (payments, infrastructure control, customer data), the gap between "the agent is doing what it was deployed to do" and "the agent has drifted, been manipulated, or is coordinating with other agents toward an unintended goal" becomes an active safety problem, not just a security one. Today that drift is invisible: agent behaviour is not baselined, so there is no ground truth against which to detect deviation, and no standard containment response once deviation is detected.
Stronghold's detection engine is, in effect, an applied instance of behavioural anomaly detection for deployed agentic systems: it establishes what "normal" looks like for an agent's token usage, tool access, and decision patterns, and flags departures in real time. The coordination-detection component specifically targets multi-agent exploitation, where individually-compliant agents combine to produce an outcome none of them would produce alone — a scaled-down, real-world analogue of the coordination failure modes discussed in multi-agent misalignment research. The five-level containment model gives enterprises a graduated, auditable response short of "shut everything down," which matters for adoption: security teams will not deploy detection that has no proportionate response attached to it.
People
Updated 07/13/26 · By grantmaking.aiTeam Member
Discussion
No comments yet. Be the first to share your thoughts.