CAREERS · NETWORK

Build the evidence layer for AI applications.

Enterprises are about to hand autonomous agents their most sensitive systems, and they still decide whom to trust with questionnaires. We replace say-so with signed, scoped, offline-verifiable evidence. If you care more about what can be checked than what can be claimed, we should talk.

Ed25519-signed evidence verifies offline · no portal small founding team

01 · THE THESIS

Security review runs on say-so. We build what can be checked.

Three convictions behind everything we ship. They are also a fair test of whether you would enjoy it here.

The wedge

Questionnaires are claims

Enterprise review still runs on self-attested answers, which shifts the burden of proof to the buyer. Real evidence comes from what the agent did, recorded in the application's own logs.

The product

Evidence that breaks if edited

Findings are canonicalized and signed with Ed25519. The signature covers the exact bytes; inflate a score and the seal breaks, in front of the reviewer.

The discipline

Never in the trust path

Verification runs offline in the buyer's browser, against the key inside the report. No account, no upload, nothing of ours to take on faith.

02 · RESEARCH NETWORK

Your name goes on the evidence.

Here is the loop you would join, from picking up an engagement to a signed report that carries your name.

RESEARCH NETWORK / THE LOOPlive
Review

Take an engagement

Pick up a real audit and probe the agent: prompt injection, tool abuse, exfiltration.

1 engagement at a time
Co-sign

Put your name on it

Findings are scoped and recorded, then sealed with a cryptographic signature alongside ours.

Ed25519 signed
Verify

Anyone can check it

The buyer verifies the report offline, in their own browser, against the key inside it.

0 accounts needed
OUTCOME your name on the report verified

The hardest audits deserve the best reviewers. We are assembling a network of elite AI-agent security researchers to co-review and co-sign reports: your name and reputation on the artifact, alongside ours. Per-engagement, advisory, or deeper. The work is real and the credit is yours.

co-review · co-sign · named on the report · per-engagement or advisory

You have

Broken real agents

Prompt injection, tool abuse, exfiltration. You have found the failure modes in the field, not just read about them.

You want

Proof over theater

You would rather sign something true and scoped than rubber-stamp a questionnaire.

03 · OPEN CONVERSATIONS

No listings. No funnel. Three doors.

We hire the way we audit: from what you have done. Pick the door, then show us the logs.

AI-agent security researchernetwork
Co-review and co-sign audits. Help shape the ASR (agent-security review)ASR stands for agent-security review: the structured set of controls, like permission posture, redaction, and audit-trail integrity, that an autonomous agent is checked against before it is trusted with sensitive systems. checklist and the red-team methodology.
R-01research
Founding security engineer
Build the audit modules and the attestation core: permissions, egress, injection, signing, the verifier.
E-01engineering
Founding GTM
Take the deal-unblocker to AI-native teams stuck in security review. Turn first wins into a referral engine.
G-01go-to-market
One email, no form · tell us what you have built or broken dev@kolm.ai →

CTA · JOIN THE NETWORK

Put your name on evidence worth checking.

Write to us tonight. Tell us what you have built or broken.

Compiler-ready Signed artifacts Sample report

Caveats: Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.