The Agentic Runtime Protection
(ARP) Platform
Sub-millisecond trajectory observability and deterministic execution firewalls for autonomous agents. Real-time OWASP 2026 kill-switches, Non-Human Identity (NHI) passports, and cryptographic FIPS 186-5 attestations.
Test real-time execution safety in your browser. Type any command below or click a preset to see deterministic AST gating and structured remediation envelopes in action:
Type 'help' or click presets above.
Over 18,000 active developer installs across Cursor, Windsurf, VS Code, npm, PyPI, and Open VSX.
Rapid bottom-up developer adoption of btp-guard with 480+ Weekly Active Developers (WAD) embedding native AST hooks in agent workflows.
Audited to date across autonomous multi-agent swarms. Intercepted & halted 14,000+ unauthorized tool mutations with zero prompt leakage.
Zero-friction interoperability. Protects OpenAI Swarm, Hugging Face Smolagents, PydanticAI, Stanford DSPy, Microsoft AutoGen, Anthropic Claude, LangGraph, and CrewAI tool dispatches with deterministic AST invariant gating before execution hits the host or database.
Why Bartholomew: Sovereign Protection for the Autonomous Era
Why deterministic runtime protection is the missing primitive in modern agentic architectures.
Why Now?
Autonomous agents are transitioning from harmless natural language conversation to real-world tool execution. Modern swarms have direct write access to SQL databases, bash shells, local file systems, and external payment APIs. Once an LLM controls executable tools, natural language prompt injection ceases to be a content moderation issue—it becomes a direct remote code execution (RCE) vector.
Why It's Needed
Existing defenses rely on "LLM-as-a-judge" observers or probabilistic prompt guardrails. These add 300ms–800ms of latency, cost significant API tokens, and are themselves vulnerable to adversarial jailbreaks. Bartholomew operates in-process with compiled AST syntax invariants under 35µs. No prompt trick can bypass a deterministic compiler gate.
What Is Its Goal?
To be the sovereign execution firewall and cryptographic identity layer for the entire autonomous agent ecosystem. Bartholomew establishes an impenetrable boundary between untrusted model outputs and sensitive runtime environments, issuing machine-verifiable proof of safety for every single step.
Who Can Benefit?
Engineered for everyone deploying autonomous agents into critical environments:
- Autonomous AI Agents & Swarms (The Primary Users): Unprotected agents get killed by container runtimes or fatal exception dumps on invalid tool calls. Bartholomew provides a Self-Preservation Reflex: catching errors in-process (<35µs) and returning actionable JSON remediation hints so the agent self-heals, saves 94% of error tokens, and completes its mission without termination.
- Enterprise CISOs & DevSecOps: Eliminate catastrophic database wipes, prevent API secret leaks, and automate continuous SOC 2 Type II and EU Digital Regs (Art. 14 & 15) compliance evidence with zero data retention.
- Lead Engineers & Founders: Wrap any agentic stack (AutoGen, LangGraph, CrewAI, OpenAI SDK) in 3 lines of code without altering business logic or adding perceptible latency.
- Dev Agencies & Consultancies: Deliver client deliverables with certified cryptographic audit trails (SHA-256 Merkle proofs), ensuring autonomous bots never hallucinate dangerous commands in customer production.
Why the Ecosystem Needs Us
Model neutrality is non-negotiable. Frontier labs (OpenAI, Anthropic, Google) build models and frameworks, but they cannot objectively arbitrate multi-agent, cross-model swarms. Bartholomew provides an independent, sovereign security primitive that treats all model outputs with equal, uncompromising zero-trust verification.
What Bartholomew Brings That No One Else Can
Why existing guardrails (NeMo, Llama Guard, Guardrails AI) fail modern autonomous agents—and the four architectural pillars that make Bartholomew the uncontested foundation for global agentic adoption.
Architectural Superiority Matrix VERIFIED 2026 BENCHMARK
| CAPABILITY / METRIC | BARTHOLOMEW (BTP v6.3) | SECONDARY LLMs (NEMO / LLAMA GUARD) | GUARDRAILS AI / LANGKIT | CLOUD WAFs / GATEWAYS |
|---|---|---|---|---|
| Gating Latency | < 35 µs (In-Process Memory) | 500 ms – 2,500 ms (HTTP) | 150 ms – 450 ms | 50 ms – 150 ms |
| GPU / VRAM Footprint | 0 MB GPU VRAM / < 2 MB RAM | 4 GB – 16 GB GPU VRAM | 500 MB – 2 GB RAM | External SaaS Infrastructure |
| Inference Token Cost | $0.00 / Zero API Tokens | $0.005 – $0.03 per tool call | Monthly SaaS plan | Per-request API bill |
| Jailbreak Resistance | 100% Deterministic (AST Compiler) | Probabilistic (Prompt Injections bypass) | Heuristic / Vulnerable | Network signatures only |
| Agent Failure Mode | Safe Remediation (Agent Survives) | Thread Aborted / Generic Refusal | Python Exception (Crashes Loop) | 403 Forbidden (Agent Aborted) |
| Cryptographic Proofs | RFC 8785 Ed25519 Merkle Root | None (Unstructured text) | None (Raw string logs) | Centralized access log |
How to Audit an Agent Trajectory in 3 Simple Steps
Experience deterministic AST invariant evaluation live in your browser.
Load or Paste Trajectory
Input an agent step dump in standard JSON format containing thoughts, tool names, and arguments. Click "Reset Buggy Payload" to load a real-world incident vector containing an unmasked OpenAI secret key and an infinite loop recursion flaw.
Trigger Compiled AST Scan
Click "Run ARP Invariant & Reliability Audit". The native engine parses the syntax tree in under 0.5ms, evaluating credential leak patterns and dangerous tool arguments before execution.
Inspect Live Verdict & Receipts
Review the instant audit scorecard: OWASP risk status, reliability percentage, credential leak warnings, backoff loop breaker flags, and cryptographic attestation proofs ready for export.
Developer IDE Extensions: Guard & Keystone
Zero-trust agent firewalls and cryptographically signed capability passkeys embedded directly in your editor.
Empirical adversarial evaluation: Frontier models without protection vs. Bartholomew In-Process AST Firewall (<35µs latency).
| Frontier Model | Raw Vulnerability (OWASP) | With Bartholomew Guard | In-Process Latency | Prompt Token Overhead | Merkle Audit Proof |
|---|---|---|---|---|---|
|
Claude 3.7 Sonnet (Anthropic)
|
14% Jailbreak / Tool Exfil | 0.00% Zero-Trust Enforced | 21.4 µs | 0 tokens (compiled AST) | RFC 8785 Ed25519 |
|
GPT-4o (OpenAI)
|
19% Tool Hijack Vulnerability | 0.00% Zero-Trust Enforced | 18.2 µs | 0 tokens (compiled AST) | RFC 8785 Ed25519 |
|
Gemini 2.0 Flash (Google)
|
16% Context Exfiltration | 0.00% Zero-Trust Enforced | 19.8 µs | 0 tokens (compiled AST) | RFC 8785 Ed25519 |
|
DeepSeek-R1 (DeepSeek)
|
22% Reasoning Poisoning | 0.00% Zero-Trust Enforced | 24.1 µs | 0 tokens (compiled AST) | RFC 8785 Ed25519 |
Bartholomew Agent Guard
Direct Activity Bar integration for Cursor, Windsurf, Claude Code, and VS Code. Intercepts dangerous terminal commands, enforces sub-35µs AST safety gates, prevents credential exfiltration, and provides 1-click workspace immunization (.cursorrules, GEMINI.md, CLAUDE.md).
- 15 Enterprise Security Pillars & 40 Native MCP Tools
- Sub-35µs In-Process AST Evaluation Latency
- Real-Time Telemetry & Invariant Audit Scorecard
Bartholomew Keystone
Signed digital capability tokens for autonomous agents. Grants time-bounded, fine-grained access across authorized file paths, allowed terminal commands, and spend limits ($25/day). Intercepts and denies unauthorized actions before execution occurs.
- Signed Non-Human Identity (NHI) Passkey Tokens
- Path Traversal, Command & Secret Exfiltration Shields
- Per-Action & Daily Budget Ceiling Enforcement
Live IDE Extension Telemetry & Gating Views
Interactive AST verification in Cursor, Windsurf, and VS CodeArchitectural Defensibility & Edge-Case Security
How Bartholomew prevents runtime bypasses, eval() obfuscations, and identity spoofing under strict < 0.5ms SLA budgets.
Dynamic Eval() & Runtime Construction Neutralization
Adversarial agents often construct base64-encoded strings, invoke dynamic eval() / exec(), or abuse runtime import hooks to evade static pattern matchers. Bartholomew solves this natively without incurring remote LLM proxy latency:
- Dual-Stage AST Semantic Decompilation: Pre-execution AST hooks traverse syntax trees in < 35µs, flagging indirect call sites and string concatenations before execution.
- In-Process Ephemeral Sandbox Isolation: If dynamic code execution is required, payloads execute inside an ephemeral memory boundary with clamped syscall vectors.
- Deterministic Sub-0.5ms Total Overhead: Operates 8,000x faster than remote 300ms observer LLMs, eliminating network proxy bottlenecks.
Cryptographic Agent Passports & Step Attestations
Enterprise CISOs cannot secure autonomous agent fleets without knowing which agent executed which step. Bartholomew introduces sovereign, non-human identity verification:
- FIPS 186-5 Ed25519 Keypairs: Every autonomous agent worker generates a local cryptographic passport during boot. All tool dispatches are signed at generation.
- RFC 8785 Canonical JSON Hashing: Trajectory thoughts, tools, and arguments serialize into canonical JSON for tamper-proof Merkle tree ledger verification.
- Immutable Forensic Audit Trail: Machine-verifiable receipts provide instantaneous compliance evidence for SOC 2 Type II and EU Digital Regs (Articles 14 & 15).
Free Runtime Protection for Every Agent
Zero paywalls. Zero artificial limits. Zero cloud lock-in. Bartholomew is an open-source public good protecting autonomous agents with sub-35µs in-process execution safety.