AI agents don’t just write code anymore. They run commands, install packages, and touch production, thousands of times a day.

Today, I am incredibly excited to announce and unleash our first public offering, Orpheus - the security platform for AI coding agents!

As AI adoption scales all around the world, the highest volume of AI interactions now happens through coding agents like Claude, Cursor and Codex. Those agents are moving faster than any review process was built for. Most security tools were designed to check code after it is written, which is far too late when the agent has already run the command and installed the dependency. By that point, the ROI you adopted AI for is already degraded.

There are new attack surfaces here too. A poisoned README, issue or web page can turn an agent against the very codebase it is working on, with no human watching. Securing agents is a different problem from securing code, and it needs a different kind of control.


How Orpheus Emerged

We initially built Orpheus to solve problems we had internally, scaling our own software and agentic requirements to a completely different level required by an AI security company.

We thought to ourselves:

What if we applied our Verification Layer to AI coding agents? We had already built a layer that verifies AI outputs before anyone acts on them. An agent is a harder version of the same problem, because the output is not text that a human reads and judges, it may be a command that executes. We need a solution for the run-time nature of these workflows.

What if every single action by an agent could be verifiable by our own policies and standards? Every engineering team already has rules about what touches production, which dependencies are acceptable, and which files nobody should be editing on a Friday afternoon. Those rules live in onboarding docs, in code review habits, and mostly in people’s heads. An agent has no access to any of that. Written down as policy, the same rules become enforceable on every single action rather than aspirational goals.

What if we could understand exactly what & when was decided by agents in runtime and realtime when necessary? When an agent does something you did not expect today, you are left scrolling a transcript and guessing at what it was reacting to. That is not an investigation, it is archaeology. A record of what was decided, when, and what the agent was looking at when it decided turns an incident into something you can actually reason about, and it lets you intervene while the session is still open instead of reading about it afterwards.

What if we could bring our AI native experience (from decades of building ML models scaled to millions of users) into agentic workflows? At Fakespot we spent years building models that had to hold up against adversaries who were actively studying them and adapting (Fake review farms, etc). That work teaches you something that is easy to miss from the outside: you cannot apply safety onto a model at the end, because the people trying to break it are working on the parts you did not design for. Agents are now in that same position, and the lesson transfers here as well.

Those were the core questions that we wanted to solve and that is how Orpheus emerged as a product.

Orpheus

Today, Orpheus runs on every developer machine and cloud agent, and verifies every input, output, command and tool call at runtime, blocking the dangerous ones before they reach your code or systems. It works across Claude Code, Codex and Cursor, on Windows, macOS and Linux, local and cloud.

In essence, Orpheus makes the non-deterministic, deterministic, thus allowing for faster AI adoption cycles with higher quality of product development and security + safety.


The Ciphero team is at BlackHat 2026 and would be more than glad to show you Orpheus running on your own agents. It goes live in five minutes, in observe mode, with no code changes. We can’t wait to share this with you!