Skip to main content
A slate storm cloud breaking over a bright horizon and a deep blue river.

About raxIT

We build the security layer for AI agents.

raxIT started in Sydney in December 2025. We help engineering teams put agents into production with evidence their risk owners can sign.

Small Hulls, Already Out. A scatter of homemade rafts adrift in mid channel below an empty mooring frame lying bare on the bank.
Small Hulls, Already Out. A scatter of homemade rafts adrift in mid channel below an empty mooring frame lying bare on the bank.

Why we started

A zero-day hit, and we spent days helping customers patch. The part that stuck was meeting small businesses whose finances were on the line through no fault of their own. They could not afford the tools a large enterprise takes for granted.

Cloud security got bolted on after the fact and everyone paid for it. AI is repeating the pattern, except the systems now act on their own.

What we think is true

Prompt injection is not solved, and you cannot hold a non-deterministic model to a deterministic standard. So stop filtering and change the architecture.

The Driftwood and the Three. A great tangle of driftwood piled on one bank, a single overloaded raft out in the pale water and the same cargo again as three trim rafts in line.

Scope

No single agent holds all the keys. Split the god agent into agents that can each do one thing.

Sign

Authority is bound to the task, not to the agent. A borrowed session carries nothing it was not issued.

Stop

A deterministic policy engine outside the model rules on every action before it runs.

One overloaded raft rigged to every landing, then the same load in three. Adesh presented this argument as Kill the God Agent at AI Engineer Melbourne 2026.

What we build

Permissions are checked one action at a time. Agent risk shows up in sequences of allowed actions, and a permission check cannot see a sequence. So we look at the whole system, before it ships and while it runs.

AI security assessment
Four Stones, No Path Yet. Four dressed stones set in line across the water below a willow thicket, a rope running back to a post on the near shore.
Live today

AI security assessment

Point it at a repository. It finds every agent, tool and MCP server, threat-models each one against the library, and verifies every control in your code with file and line evidence.

Runtime platform
The Markers at the Narrows. A line of small marker posts standing where a dark headland squeezes the river into one narrow passage.
Waitlist

Runtime platform

A policy engine outside the model rules on every tool call, so an allowed action inside a dangerous sequence is still stopped.

Threat intelligence
The Lantern Chain at Dusk. A chain of small lanterns lighting the river upstream toward the last light, an optical telegraph mast on the far rise.
Public, free

Threat intelligence

What has gone wrong with AI systems in the world, generalised into evidence-backed threat patterns and refreshed daily. Open to everyone.

How we work

Every check produces an artifact a risk owner can read. A finding without file and line evidence is an opinion.

The threat intelligence is public. Incident knowledge only compounds when it is shared, so the library that powers our checks is the one anyone can browse.

We publish what we get wrong. The library carries an independently measured error rate, and the edges we have not closed are listed on the page.

Security that blocks the work gets removed. So raxIT holds an action for a decision instead of refusing it.

Who is building it

Adesh Gairola is a security engineer who has worked the whole of governance, risk and compliance from the inside for close to two decades, from building the controls to auditing them to deciding what they are for.

At AWS he moved regulated systems into audited cloud production, then built the AI security practice for Australia and New Zealand from nothing and ran hundreds of assessments for banks, governments and telcos. He shipped the guardrails behind the first generative AI deployments at two of Australia's four major banks, with the control evidence their risk committees signed, and co-authored the AWS reference threat model for AI agents, which combines Microsoft's STRIDE method with the Cloud Security Alliance's MAESTRO framework for agents.

His grounding is in the network. He led a thirty-engineer VPN and firewall team at Cisco supporting the largest carriers in the world, and holds a CCIE in security. He founded raxIT Labs in Sydney in December 2025, presented Kill the God Agent at AI Engineer Melbourne 2026, runs AI Security Circle Sydney and contributes to the OWASP LLM Top 10. More at adeshgairola.com.

Adesh Gairola, founder of raxIT Labs
A dark olive headland over a cream strand and a calm sea.

Run the assessment on one repo.