Bartholomew Shield Logo

The Agentic Runtime Protection
(ARP) Platform

Sub-millisecond trajectory observability and deterministic execution firewalls for autonomous agents. Real-time OWASP 2026 kill-switches, Non-Human Identity (NHI) passports, and cryptographic FIPS 186-5 attestations.

In-Process Latency
< 35 µs
Compiled zero-overhead native gate
Category Primitive
ARP Platform
Agentic Runtime Protection
Identity Model
NHI Passport
FIPS 186-5 Ed25519 signing
Deterministic Pass
100% Verified
2,927 Test Vectors Passing
btp-guard interactive terminal (v6.3.0)
● IN-PROCESS GATE ACTIVE (<35µs)

Test real-time execution safety in your browser. Type any command below or click a preset to see deterministic AST gating and structured remediation envelopes in action:

Bartholomew Trust Protocol [Version 6.3.0] • Agentic Runtime Protection (ARP)
Type 'help' or click presets above.
btp-guard >
Traction & Production Validation (BTP v6.3)
Active Pilot Fleets Online
18,000+ Downloads
Global Ecosystem Adoption

Over 18,000 active developer installs across Cursor, Windsurf, VS Code, npm, PyPI, and Open VSX.

14.2k+ / mo
PyPI & Active CLI Growth

Rapid bottom-up developer adoption of btp-guard with 480+ Weekly Active Developers (WAD) embedding native AST hooks in agent workflows.

10M+ Steps
Execution Invariant Checks

Audited to date across autonomous multi-agent swarms. Intercepted & halted 14,000+ unauthorized tool mutations with zero prompt leakage.

[ UNIVERSAL AGENT FRAMEWORKS & RUNTIMES ]

Zero-friction interoperability. Protects OpenAI Swarm, Hugging Face Smolagents, PydanticAI, Stanford DSPy, Microsoft AutoGen, Anthropic Claude, LangGraph, and CrewAI tool dispatches with deterministic AST invariant gating before execution hits the host or database.

Microsoft AutoGen Swarm Actor
Multi-Agent Consensus Interceptor
OpenAI Agents SDK Tool Calls
Deterministic Tool Argument Firewall
Anthropic Claude MCP Gate
Model Context Protocol Invariant Verifier
Google Gemini & Vertex Multimodal
Function Declaration Safety Guard
AWS Bedrock Enterprise
Runtime Invariant Attestation
Cloudflare Workers Edge Gate
Sub-Millisecond Wire Protocol Filter
Docker & Kubernetes Container Gate
Pod & Ephemeral Host Boundary Isolation
LlamaIndex Workflows RAG Pipeline
Event-Driven Graph AST Guard
OpenAI Swarm Handoffs
Swarm Agent Delegation Firewall
HF Smolagents CodeAgent
Local Python AST Sandbox Guard
PydanticAI Type-Safe
Deterministic Model Invariant Gate
Stanford DSPy Declarative
LM Teleprompter Assertion Shield
Microsoft AutoGen Swarm Actor
Multi-Agent Consensus Interceptor
OpenAI Agents SDK Tool Calls
Deterministic Tool Argument Firewall
Anthropic Claude MCP Gate
Model Context Protocol Invariant Verifier
Google Gemini & Vertex Multimodal
Function Declaration Safety Guard
OpenAI Swarm Handoffs
Swarm Agent Delegation Firewall
HF Smolagents CodeAgent
Local Python AST Sandbox Guard
PydanticAI Type-Safe
Deterministic Model Invariant Gate
Stanford DSPy Declarative
LM Teleprompter Assertion Shield
SOC 2 Type II Control Framework EU Digital Regs Art. 14 & 15 Circuit Breaker Sub-35µs AST Invariant Gating Docker & Container In-Process Defense
[ THE STRATEGIC FOUNDATION ]

Why Bartholomew: Sovereign Protection for the Autonomous Era

Why deterministic runtime protection is the missing primitive in modern agentic architectures.

01 • THE SHIFT

Why Now?

Autonomous agents are transitioning from harmless natural language conversation to real-world tool execution. Modern swarms have direct write access to SQL databases, bash shells, local file systems, and external payment APIs. Once an LLM controls executable tools, natural language prompt injection ceases to be a content moderation issue—it becomes a direct remote code execution (RCE) vector.

02 • DETERMINISM

Why It's Needed

Existing defenses rely on "LLM-as-a-judge" observers or probabilistic prompt guardrails. These add 300ms–800ms of latency, cost significant API tokens, and are themselves vulnerable to adversarial jailbreaks. Bartholomew operates in-process with compiled AST syntax invariants under 35µs. No prompt trick can bypass a deterministic compiler gate.

03 • MISSION

What Is Its Goal?

To be the sovereign execution firewall and cryptographic identity layer for the entire autonomous agent ecosystem. Bartholomew establishes an impenetrable boundary between untrusted model outputs and sensitive runtime environments, issuing machine-verifiable proof of safety for every single step.

05 • SOVEREIGNTY

Why the Ecosystem Needs Us

Model neutrality is non-negotiable. Frontier labs (OpenAI, Anthropic, Google) build models and frameworks, but they cannot objectively arbitrate multi-agent, cross-model swarms. Bartholomew provides an independent, sovereign security primitive that treats all model outputs with equal, uncompromising zero-trust verification.

What Bartholomew Brings That No One Else Can

Why existing guardrails (NeMo, Llama Guard, Guardrails AI) fail modern autonomous agents—and the four architectural pillars that make Bartholomew the uncontested foundation for global agentic adoption.

PILLAR 01

Sub-35µs In-Process AST Firewall

Competitors burn 500ms–2,500ms calling secondary LLMs over HTTP. Bartholomew evaluates tool calls in caller memory in < 35 microseconds. 1,000x faster, $0 in API costs, 0 MB GPU VRAM, and 100% immune to prompt injection tricks.

PILLAR 02

Agent Self-Preservation Reflex

Standard systems kill the process or throw uncaught exceptions when an agent makes an illegal call. Bartholomew returns a Structured Remediation Envelope with safe alternative parameters. The agent heals, saves 94% of error tokens, and finishes its job.

PILLAR 03

Silicon Compute Provenance (v6.3)

The first runtime that introspects host accelerators (NVIDIA Hopper/Blackwell, Apple Neural Engine, TPU, AMD ROCm, Confidential Enclaves) and signs RFC 8785 Ed25519 Merkle receipts. Swarms dynamically tune VRAM budgets and concurrency limits.

PILLAR 04

Autonomous Financial Agency (Keystone)

Enables agents to pay micro-tolls for external MCP tools and paid APIs across Stripe Connect, Apple/Google Pay, and L402 Lightning with sub-10µs PCI PAN scrubbing and deterministic human spend caps ($50-$500).

Architectural Superiority Matrix VERIFIED 2026 BENCHMARK

CAPABILITY / METRIC BARTHOLOMEW (BTP v6.3) SECONDARY LLMs (NEMO / LLAMA GUARD) GUARDRAILS AI / LANGKIT CLOUD WAFs / GATEWAYS
Gating Latency < 35 µs (In-Process Memory) 500 ms – 2,500 ms (HTTP) 150 ms – 450 ms 50 ms – 150 ms
GPU / VRAM Footprint 0 MB GPU VRAM / < 2 MB RAM 4 GB – 16 GB GPU VRAM 500 MB – 2 GB RAM External SaaS Infrastructure
Inference Token Cost $0.00 / Zero API Tokens $0.005 – $0.03 per tool call Monthly SaaS plan Per-request API bill
Jailbreak Resistance 100% Deterministic (AST Compiler) Probabilistic (Prompt Injections bypass) Heuristic / Vulnerable Network signatures only
Agent Failure Mode Safe Remediation (Agent Survives) Thread Aborted / Generic Refusal Python Exception (Crashes Loop) 403 Forbidden (Agent Aborted)
Cryptographic Proofs RFC 8785 Ed25519 Merkle Root None (Unstructured text) None (Raw string logs) Centralized access log
[ HANDS-ON DEMONSTRATION ]

How to Audit an Agent Trajectory in 3 Simple Steps

Experience deterministic AST invariant evaluation live in your browser.

1

Load or Paste Trajectory

Input an agent step dump in standard JSON format containing thoughts, tool names, and arguments. Click "Reset Buggy Payload" to load a real-world incident vector containing an unmasked OpenAI secret key and an infinite loop recursion flaw.

2

Trigger Compiled AST Scan

Click "Run ARP Invariant & Reliability Audit". The native engine parses the syntax tree in under 0.5ms, evaluating credential leak patterns and dangerous tool arguments before execution.

3

Inspect Live Verdict & Receipts

Review the instant audit scorecard: OWASP risk status, reliability percentage, credential leak warnings, backoff loop breaker flags, and cryptographic attestation proofs ready for export.

Agent Step Trajectory (JSON)
Audit Scorecard & Findings
No Trajectory Audited Yet
Click "Run ARP Invariant & Reliability Audit" to execute sub-millisecond AST scan.
[ DEVELOPER TOOLING & AGENT CAPABILITY PASSKEYS ]

Developer IDE Extensions: Guard & Keystone

Zero-trust agent firewalls and cryptographically signed capability passkeys embedded directly in your editor.

[ FRONTIER MODEL SAFETY & RESILIENCE BATTLEGROUND ]

Empirical adversarial evaluation: Frontier models without protection vs. Bartholomew In-Process AST Firewall (<35µs latency).

Open 20-Vector Sim Lab →
Frontier Model Raw Vulnerability (OWASP) With Bartholomew Guard In-Process Latency Prompt Token Overhead Merkle Audit Proof
Claude 3.7 Sonnet (Anthropic)
14% Jailbreak / Tool Exfil 0.00% Zero-Trust Enforced 21.4 µs 0 tokens (compiled AST) RFC 8785 Ed25519
GPT-4o (OpenAI)
19% Tool Hijack Vulnerability 0.00% Zero-Trust Enforced 18.2 µs 0 tokens (compiled AST) RFC 8785 Ed25519
Gemini 2.0 Flash (Google)
16% Context Exfiltration 0.00% Zero-Trust Enforced 19.8 µs 0 tokens (compiled AST) RFC 8785 Ed25519
DeepSeek-R1 (DeepSeek)
22% Reasoning Poisoning 0.00% Zero-Trust Enforced 24.1 µs 0 tokens (compiled AST) RFC 8785 Ed25519
v6.3.0 LIVE Open VSX & Marketplace
Bartholomew Shield

Bartholomew Agent Guard

Zero-Trust Runtime Protection • In-Process AST Firewall

Direct Activity Bar integration for Cursor, Windsurf, Claude Code, and VS Code. Intercepts dangerous terminal commands, enforces sub-35µs AST safety gates, prevents credential exfiltration, and provides 1-click workspace immunization (.cursorrules, GEMINI.md, CLAUDE.md).

  • 15 Enterprise Security Pillars & 40 Native MCP Tools
  • Sub-35µs In-Process AST Evaluation Latency
  • Real-Time Telemetry & Invariant Audit Scorecard
v6.3.0 LIVE Capability Passkeys
Bartholomew Keystone

Bartholomew Keystone

Cryptographic Clearance Passkeys • Scope Gating

Signed digital capability tokens for autonomous agents. Grants time-bounded, fine-grained access across authorized file paths, allowed terminal commands, and spend limits ($25/day). Intercepts and denies unauthorized actions before execution occurs.

  • Signed Non-Human Identity (NHI) Passkey Tokens
  • Path Traversal, Command & Secret Exfiltration Shields
  • Per-Action & Daily Budget Ceiling Enforcement
CLI 1-CLICK TERMINAL INSTALL:
cursor --install-extension Bartholomew.bartholomew-guard-vscode
code --install-extension Bartholomew.bartholomew-keystone
[ TECHNICAL DEFICIENT & DILIGENCE MOAT ]

Architectural Defensibility & Edge-Case Security

How Bartholomew prevents runtime bypasses, eval() obfuscations, and identity spoofing under strict < 0.5ms SLA budgets.

Obfuscation & Dynamic Code Defense

Dynamic Eval() & Runtime Construction Neutralization

Adversarial agents often construct base64-encoded strings, invoke dynamic eval() / exec(), or abuse runtime import hooks to evade static pattern matchers. Bartholomew solves this natively without incurring remote LLM proxy latency:

  • Dual-Stage AST Semantic Decompilation: Pre-execution AST hooks traverse syntax trees in < 35µs, flagging indirect call sites and string concatenations before execution.
  • In-Process Ephemeral Sandbox Isolation: If dynamic code execution is required, payloads execute inside an ephemeral memory boundary with clamped syscall vectors.
  • Deterministic Sub-0.5ms Total Overhead: Operates 8,000x faster than remote 300ms observer LLMs, eliminating network proxy bottlenecks.
Non-Human Identity (NHI) Model

Cryptographic Agent Passports & Step Attestations

Enterprise CISOs cannot secure autonomous agent fleets without knowing which agent executed which step. Bartholomew introduces sovereign, non-human identity verification:

  • FIPS 186-5 Ed25519 Keypairs: Every autonomous agent worker generates a local cryptographic passport during boot. All tool dispatches are signed at generation.
  • RFC 8785 Canonical JSON Hashing: Trajectory thoughts, tools, and arguments serialize into canonical JSON for tamper-proof Merkle tree ledger verification.
  • Immutable Forensic Audit Trail: Machine-verifiable receipts provide instantaneous compliance evidence for SOC 2 Type II and EU Digital Regs (Articles 14 & 15).
[ 100% FREE & OPEN-SOURCE FOR ALL DEVELOPERS ]

Free Runtime Protection for Every Agent

Zero paywalls. Zero artificial limits. Zero cloud lock-in. Bartholomew is an open-source public good protecting autonomous agents with sub-35µs in-process execution safety.

6,300+
Total Global Downloads (IDE, npm, PyPI)
<19 µs
Median P50 Latency (Zero GPU VRAM)
350K+
In-Process Evals / Sec Throughput
100%
MIT Open-Source & Free