About

Securing the agentic workforce

AI-FW is built by Securetron Inc., an identity and trust company in Toronto, Canada. The gateway is the product of that work: trust established at the identity layer, enforced at the inference boundary.

Why AI-FW exists

Securetron's work began with a narrow, hard problem: extending phishing-resistant identity to non-human operators, including AI agents, IoT devices and operational technology. Certificates, enrolment and lifecycle management for software that acts on its own, without a person present to authenticate.

That work began as an extension of Securetron's PKI Trust Manager, the platform behind Securetron's phishing-resistant MFA, and then outgrew it. Two things pushed it further: the rise of agentic AI, and Securetron's own requirement to secure AI usage internally. What existed on the market covered pieces of the problem, but nothing covered the whole of it. Data loss prevention, guardrails, prompt compression, identity and access management, governance and risk were separate conversations, and in most products several were missing.

So the team built it from the ground up, for the requirement that matters most: the highest level of protection and governance for agentic AI, in the customer's own environment. Development started at the end of 2025, and AI-FW now runs in production for enterprises, governments and defence.

What we hold to

Four positions that shape the product, and that we are happy to be measured against in a review.

Defence in depth

One control is never the answer for AI traffic. Identity, inspection, policy, routing and audit each have to hold, and each has to keep working when the others are unhappy.

Identity for non-human operators

Agents, IoT and OT devices are the operators now. They need the same rigour as people: their own credentials, their own lifecycle, and revocation that does not disturb the fleet.

Judge meaning, not just keywords

Policy that only matches strings fails on the first rephrasing. Semantic analysis lets policy be written the way the requirement is actually stated.

Security before features

If inspection cannot run, the request is refused. Availability policy exists to keep the service up, never to route around the control.

Who we build for

Organisations that need a complete answer for AI rather than a partial one: enterprises running AI at scale, governments, and defence. The common thread is not curiosity about AI, it is a regulatory requirement and an audit that has to be satisfied with evidence. AI-FW is judged on whether it survives that scrutiny.

  • Security and platform teams that must account for every model call
  • Identity teams extending trust to autonomous, non-human operators
  • Regulated organisations that need decisions recorded without storing content

Company details

Legal entity
Securetron Inc.
Registered office
Toronto, Ontario, Canada
Incorporated
6 November 2016
Corporation number
997427-0
Business number
743145328RC0001
Governing legislation
Canada Business Corporations Act

Certifications, security posture and data handling are documented on the trust page.

Find us

Securetron also builds PKI Trust Manager, the platform behind its phishing-resistant MFA.

Talk to the team that built it

Bring your requirement, your regulators and your environment. We will map it to a deployment plan and a proof of concept you run yourself.