Basefield

Everyone will have agents working for them, and not just one. They’ll use different agents to read their mail, file expenses, pay vendors, write code, and trade their portfolios. That work requires real access to business systems: email, files, customer records, and bank accounts.

Anything an agent reads can influence its behavior. Attackers plant instructions in pull requests, support tickets, and forms to steal API keys, access tokens, and customer data. In one of OpenAI’s own red-team tests, a planted email convinced an agent asked to draft an out-of-office reply to send a resignation letter to the user’s CEO instead. The pattern is the same: attackers supply the instructions, and agents supply the access.

Filters, confirmations, and sandboxes lower the odds of something going wrong. But none of them can tell you what an agent will never do. One failure is enough.

Basefield takes a different approach. It continuously monitors your agent's actions using a dynamic task-based policy expressed in mathematical logic. With Basefield, your agents work freely and safely, without forcing you to hand-write policies or reason about edge cases. Every action is proven safe before it happens, and no interaction with untrusted emails or web content can ever compromise safety.

We’re starting with small teams running several agents. If that’s you, we’d like to show you.
Amber lattice with seven moving agents.