CASE 02 · PRIVATE BETA

Keel

Run untrusted agents. Keep the keys.

2026

PROJECT INFOS

A runtime for agent code you did not write, that never hands it your secrets or your budget.

Three AI products we had shipped each rebuilt the same fragile plumbing: a sandbox, a cost meter, an event stream. Keel is that plumbing done once, properly. It runs agent code written by someone else without trusting it, on a single rule: the agent gets capabilities, never credentials. It can use a secret without ever seeing it. Every run has a spend ceiling and a kill switch that fails closed, so an agent that misbehaves costs a capped amount and nothing more. Developers ship in one command and watch their agents work in an operator console. Keel is in private beta and already carries a production workload.

PLATFORM ARCHITECTURE
AGENT CAPABILITY SECRET CEILING
An agent can use a secret without ever being able to read it

WHAT IT PROVES

  1. 01

    An agent can use a secret without ever being able to read it

  2. 02

    An agent that runs away hits a spend ceiling instead of your bill

  3. 03

    One command ships an agent, in TypeScript, Python or Java

SCOPE

  • PLATFORM ARCHITECTURE
  • AGENT RUNTIME
  • SECURITY MODEL
  • POLYGLOT SDKS
  • OPERATOR CONSOLE

STACK

  • TYPESCRIPT
  • JAVA / QUARKUS
  • PYTHON
  • NATS
  • ZOD
NEXT PROJECT Lode