We build frontier AI systems, and we bound what they are allowed to do.
Alnair is a frontier AI applications and security research lab. One half of the work ships AI into production. The other half asks what happens when it is wrong, and builds the bound.
Two halves of one problem
Most groups working on applied AI do not work on its containment, and most groups working on AI safety have never shipped a production system. We think that separation is a mistake. Knowing where an agent actually breaks in a live deployment is what tells you which bounds are worth building, and building the bound is what tells you which deployments were never safe to attempt.
Applications. Agentic systems in production: reasoning over governed enterprise data, multi-step workflows that touch real systems of record, generative pipelines, and the evaluation harnesses that establish whether any of it is working.
Security research. What an agent can cause once it holds authority you deliberately granted, and how to bound that in a way you can evidence afterwards. This is where Endstop comes from.
Selected engagements
Client names are withheld under the terms of the relevant agreements. The descriptions are accurate.
| Client | Profile | Nature of work |
|---|---|---|
| A top-two global semiconductor capital-equipment manufacturer | S&P 500 · roughly $28B annual revenue · ~36,500 staff | Applied AI in a high-precision manufacturing environment |
| An enterprise AI execution and governed-data platform | Serves a $300B health and wellness group and a $160B retailer among others | Agentic execution over operational data; platform engineering |
| An AI-native interactive-experience platform | Models author and revise executable code that runs live in end-user browsers | Controlled execution of arbitrary LLM-generated code in a production runtime |
The spread is deliberate. Semiconductor manufacturing, enterprise operations and consumer generative systems fail in materially different ways, and the security research is better for having seen all three.
The third engagement is the direct antecedent of our research. A platform where a model writes code that executes immediately, in a runtime a stranger is using, is the containment problem in its least forgiving form: there is no review step to insert, no operator to approve the effect, and the blast radius is whatever the runtime was permitted to touch. Working on that in production is what convinced us the bound has to live somewhere the model cannot reach.
Our founder is a Techstars alumnus. Alnair itself has not been through the programme.
Research: Endstop
Agents now run code, move money and drive actuators faster than anyone reviews what they do. The exposure is generally not that a model wrote the code; it is that no one approved the effect before it happened.
Containment does not solve this. A sandbox bounds where computation can reach, which is a different question from what legitimately granted authority can do once it gets there. An agent does not have to escape anything, and it certainly does not have to go rogue. It only has to be tricked while holding permissions somebody correctly gave it.
Endstop is our answer: a hardware gate holding the authority, so actuator lines or signing keys terminate at the gate rather than at the machine running the model. The agent proposes; only the gate acts. Its trusted core is machine-checked and running today. The full specification, the standards posture, and the research record — including six conclusions we published and later reversed — are public.
How we engage
Applied work
Agentic systems in production: architecture, build, evaluation harnesses, and the operational plumbing that decides whether a pilot survives contact with real data.
Security work
Threat modelling for a specific deployment, safety-case structure for a model in a physical or financial control loop, and architecture review of an existing containment design.
Security engagements stand on their own and require no commitment to the hardware. That is usually how a relationship starts.
Work with us
Tell us what your model is allowed to do.
We take on a small number of engagements at a time, on either side of the work: shipping an agentic system, or bounding one that already ships.
Direct email reaches the person doing the work rather than a queue.
Contact
| info@alnair.dev | |
| Telephone | +1 650-645-0171 |
| Entity | Alnair LLC |
| Address | 310 Comal Street, Suite 262, Austin, TX 78702, USA |
| Research | endstop.systems |