Agents have a mind of their own. You have ACRA.

AI agents do not behave like traditional software. Securing them requires a new approach.

Atlasops lead
ACRA · enclave/revenueegress · declared only0 denies
Morning. Pipeline is synced and the renewal board is clean.
Message Atlas…
Slack#revenue
at
atlasAPP08:44

Standup notes posted. 2 blockers cleared.

allowed · api.slack.com · declared
HubSpotcontacts
Anna Reyesanna@meridian.co · renews 12 Sep
J. Okaforj.okafor@helios.io · renews 15 Sep
M. Chenm.chen@nordwind.de · renews 19 Sep
allowed · reading at-risk accounts…
web.searchapi.firecrawl.dev

"Q3 renewal benchmarks — mid-market SaaS"

Renewal pricing pressure, Q3 · survey
Churn drivers 2026 · note
Usage-based renewals · report
allowed · api.firecrawl.dev · declared

Never give agents access unless you're in control.

An agent is a model with at least one tool and a goal. That combination is like a new employee who was handed your credentials, your network, and a shell, and who works at machine speed.

01

Agents combine access that wasn't meant to be combined.

A user's permissions. A tool. The network. Each was approved on its own. Together they are a new actor most stacks have nowhere to put, so the agent inherits the widest access nearby.

02

Agents are non‑deterministic.

A test tells you what the agent did once. Not what it will do with a new prompt, a new document, or a poisoned input. If you cannot predict the actions, you have to limit what they can reach. Which hosts. Which services. Which files. Which other agents.

03

Agents act faster than review can happen.

An agent can chain a dozen tool calls in the time a human reads one alert. A control that arrives after the action has already lost. The boundary has to exist before the first call.

ACRA gives you authority over your agents.

You approve an enclave once and every workload inside inherits its policies.

01Deploy ACRA.

acra install posture v1 · ready

ACRA extends the Kubernetes you already run. Install the control plane on your cluster. You hold the keys. After handover, Valarian has no path in.

02Create an enclave.

ACRA New enclave research · created
Members · 12 invited
Egress allowlist · 3 hosts
Model · in-cluster · pinned

A new enclave inherits identity, policy and audit. You declare the members, the hosts, the model and the files. There is no path to another enclave unless you grant one.

03Launch agents.

enclave/research Workloads
research-agentrunning
valarie.researchrunning
ledger-agentstarting

It starts with the paths you named. Declare the image, the dependencies and the hostnames. A missing provider, and it does not start.

04Watch it run.

enclave/research Network 2 denies · recorded
api.slack.com· research-agentforwarded
169.254.169.254· ledger-agentdropped
postgres.ledger.svc· ledger-agentforwarded

Declared paths run at full speed. The rest is refused and named. No gateway in the path. Every refusal is written down with the workload's name on it.

Your sovereign intelligence stack.

ACRA isn't a sandbox. It defines the world your agents can reach, then gets out of the way so you can run at full speed.

▼ authorityevidence ▲
L4workloads
Declared dependencies are reached at full speed, in-cluster, with no gateway in the path. The agent, its tools, and its model run as workloads. What was declared is a real path on your runtime. What was not declared does not exist to them.
consumes
L3enclave
The enclave is the blast-radius boundary. No path to another enclave unless someone declared one. Own namespace, own identity, own storage. Platform operators can create and destroy the enclave. They cannot enter it. Two agents in the same enclave reach only what that enclave was declared to reach.
isolates
L2control plane
L2 is the source of authority: identity, policy, reachability. It is out of the datapath. It can create the enclave and tear it down. It cannot execute a workload or read enclave data. The agent inherits the asking user's access, never a shared god-account. Every change to reachability is an audit event.
decides
L1acra core
L1 enforces in the datapath. If L2 is down, Core keeps the last valid policy. Admission, identity, network, and secrets are applied beneath the workload. The agent cannot see the allowlist, so it cannot edit it. Fail-closed: you cannot change policy, the policy does not disappear.
enforces
L0infrastructure
L0 is substrate. It holds no keys and makes no security decisions. Same posture on a hyperscaler, in a national DC, or on-prem. The cloud is where it runs, not who it trusts.
provisions

The agent lives at L4, with its tools and the work it was given. The thing that stops it lives at L1. There is no path between them, so an agent cannot rewrite an allowlist it cannot see, and it cannot climb into the control layer because the control layer is not on its plane. That is the argument of the picture.

Deploy infrastructure
you control.

Company

About Careers

Resources

Blog Contact

Compliance

Privacy
Established 2020 · London

Control infrastructure for high-consequence systems.
© 2026 Valarian · London

Made in the UK