About Faramesh

Building the runtime layer for AI agents.

We're a small team building the governance and enforcement layer that AI agents need before they're trusted with anything that matters. Open source at the core, designed for production from day one.

Why we built this

System prompts aren't security.

Every team building AI agents runs into the same wall. Your model is non-deterministic, the tools it can call are real, and the only thing standing between agent intent and production impact is a paragraph in a system prompt asking it nicely.

That isn't really security. It's a suggestion, and models can be tricked, confused, or just ignore instructions when the context window gets long enough. We've watched companies ship agents into production with this exact setup and then scramble when something inevitably goes wrong.

So we started Faramesh. The answer isn't another wrapper around the model, it's a runtime layer that sits between the agent and the things it can actually do. Every tool call gets checked against policy before it runs, and the agent doesn't get to negotiate. That's the only model we think holds up when real systems are on the line.

Founders

The team behind the work.

Amjad Fatmi

Amjad Fatmi

Co-founder & CEO

Amjad leads product and engineering. Author of the Action Authorization Boundary research and architect of FPL, the policy language that powers Faramesh.

Brian Hall

Brian Hall

Co-founder & CCO

Brian leads commercial strategy and customer development. Came from deploying production AI automations where unconstrained agent behavior was a daily problem.

What we believe

Principles we work by.

Four ideas that shape every product decision we make.

01

Open source by default.

The core is MPL-2.0 licensed. Self-hostable, inspectable, and yours to run on your own infrastructure. Trust comes from being able to read the code, not from us telling you to trust us.

02

Runtime over detection.

Detection-based tools tell you what already happened. We block the action before it runs. Prevention is the only model that works at agent speed, and the only one that works in regulated environments.

03

Evidence, not claims.

Every authorization decision is logged, hash-chained, and replayable. Auditors don't take our word for it, they verify the trail themselves. Compliance becomes something you can show, not something you have to argue.

04

Boring infrastructure.

The best security tools fade into the background. They run, they log, they don't get in your way, and they don't ask for your attention. That's what we're building, and that's the bar we hold ourselves to.

Get in touch

Buildingagentsinproduction?

We're working with teams shipping AI agents at scale. If you're running into governance problems we can help with, we'd like to hear about it.

Open source. Self-hosted or cloud. No credit card required.