Governance spans the path and the plane above it.
Local enforcement sits in the tool path. Trust roots, signed policy, identity, and attestation remain outside the agent-controlled session so it cannot rewrite its own rules.
Company
mistwire builds controls for organizations that want the leverage of coding agents without turning policy, identity, and evidence into optional afterthoughts.
Why mistwire exists
So that the rules an agent is asked to follow and the rules it is unable to break come from the same signed source, because either kind alone leaves a gap that is unkind to systems and unkind to the user.
Some rules live where the agent can read them: the signed skills and instructions it loads before work, which shape what it tries to do. Those are probabilistic, because a model follows what it reads most of the time. Some rules live where the agent cannot reach them: hooks that check each request before it runs, and a service that compares what is installed against what it signed. Those are deterministic. Governance is both, installed from one signed source.
We never look at your hardware, your memory, or your operating system. We look at one folder we created, the files we put in it, and the requests an agent makes through the hooks in it. That is the whole surface, and it is small on purpose.
Today the alpha installs signed policy and hooks on your machine that check each request before it runs. That already means the rules are yours to read, signed, versioned, and verifiable by anyone you choose to show them to. Next, more of the deterministic layer moves outside the agent’s harness entirely, so there is nothing to step around because the route was never there. Next
Anyone running software on hardware you do not control can lie about it. Our answer is to make a lie visible rather than to pretend it cannot happen: an independent witness, outside the agent’s own trust domain, so that a false claim is caught rather than merely blamed. That witness is planned, not shipped, and we say so. Next
We show a real read even when it is unflattering, and nothing at all rather than a number we invented. We ship rules that actually fire, and we publish what is not built as carefully as what is. The proof has to survive someone who has no reason to trust us, because that person is your auditor, and they are the only audience that matters.
We build all of this at the least cost to the people using it and the least footprint on the systems running it. It is kind to digital systems to have good ways of managing digital infrastructure, and anything less is debt handed to whoever comes next. The same instinct shapes what we keep: as little of your data as the job allows, because that is how trust is won.
Governance for coding and agent sessions is the product today. Foil, which moves the network boundary itself, comes second. After that comes the runtime the agent lives in, which means rethinking how a system decides what to trust without breaking how the internet talks. We say the order out loud so you can hold us to it.
Local enforcement sits in the tool path. Trust roots, signed policy, identity, and attestation remain outside the agent-controlled session so it cannot rewrite its own rules.
Safe cases can move quickly, dangerous cases stop, and uncertain requests stay with the host and human.
The current product governs coding and agent sessions. Foil will bring moving-boundary protection to tailored enterprise environments.
Our values
mistwire.io was built around a set of convictions about how software should work, how companies should operate, and what it means to build something worth trusting. They shaped the architecture and governance from the beginning.
mistwire.io believes in kindness. We build software and automations that are kind to the users and kind to the systems they run on. A system so computationally expensive to operate that it defeats its own purpose is unfair to users and unkind to the architecture supporting it.
We focus on lean, lightweight, modular, and useful features—tools and systems that feel natural and easy to use. Complexity that serves the user is welcome. Complexity that serves the product roadmap at the user’s expense is not.
Autonomous AI agents that can modify live infrastructure are powerful—and that power requires a clear hierarchy. At mistwire.io, humans are always at the top of it. Our agents reason, decide, and act, but they do so within boundaries that human operators set, and they cannot override the consent model that governs them.
Automation should extend human capability, not replace human judgment. Human primacy is an architectural constraint, not something that should be accidentally configured away.
We believe that a security system you cannot interrogate is a security system you cannot trust. Explainability is a design constraint because opacity is a form of disrespect—toward users, regulators, and the people whose systems we are trusted to protect.
Governance decisions should be explained in plain language, with the evidence and limitations available for inspection. Claims must stay bounded by what the current system actually records and verifies.
We don’t believe a business relationship should be structured so that one party wins by making the other party more dependent, more vulnerable, or less informed. mistwire.io builds products and relationships where the value is real, the terms are honest, and the customer’s success is the measure of ours.
We don’t gate capabilities that make customers safer behind premium tiers. We don’t build lock-in as a retention strategy. We earn continued trust by continuing to deserve it.
Our direction for shared defense is that when one mistwire customer encounters a new threat, other participating customers can benefit from that knowledge without exposing the originating customer’s private material. A safer network for one should mean a safer network for all.
Customers who prefer to operate independently must be able to opt out. We respect that choice. The broader federated-threat-intelligence model belongs to the Foil enterprise direction and is not a claim about the current Governance alpha.
These values are mistwire’s non-negotiables. They apply to the architecture, the governance documents, and the way we treat every person who works with us or depends on what we build.
The team
We bring security engineering, enterprise operations, and human-centered product design together to make governed agent work practical.

Founder & Chief Executive Officer
Technology and security executive with 20 years spanning agentic AI security, military cyber operations, cloud transformation, and enterprise infrastructure leadership. Paul founded mistwire to make autonomous action governable from the session to the enterprise boundary.
“The attacker needs to be right once. The defender needs to be right every time. mistwire inverts that asymmetry.”

Co-Founder & Chief Operating Officer
Builder of autonomous defense systems with 20+ years across defense cyber operations, Zero Trust architecture, cloud security, and enterprise risk leadership. Quinton leads operational strategy, product execution, partnerships, and commercialization.
“Autonomous defense begins when security stops reacting to threats and starts shaping the conditions attackers depend on.”

Product Manager — Governance (Interim)
Product leader focused on AI governance, digital identity, and trustworthy human-agent systems. Jiyae brings human-centered design, responsible AI, and regulatory fluency to making governed agent experiences clear, usable, and enterprise-ready.