Whitzard

Security infrastructure for the agentic AI era.

Whitzard connects runtime safeguards, model services, frontier-risk research, and an open technical ecosystem so AI agents can operate within clear, verifiable boundaries.

Who we are

Whitzard is a research-driven AI safety company. We connect frontier AI risk research from NUWA with deployable safety technology in AgentGuard, helping teams evaluate and operate increasingly capable AI systems with appropriate safeguards.

01

Trusted boundaries

Security control must cover the full path from intent to action — not just the endpoint.

02

Verifiable evidence

Every safety claim should be traceable to reproducible evaluation, not asserted.

03

Minimal necessary intervention

Security enables agents to complete tasks, not just block them.

One connected system

Research identifies risk. Protection acts on evidence.

NUWA and AgentGuard connect frontier-risk research with controls that operate inside real agent workflows.

AgentGuardPRODUCTS & SERVICES

Agent runtime security control layer

AgentGuard tracks data, authorization, and action impact continuously — repairing or blocking risk before boundaries are crossed, while letting agents complete their tasks. Available as an open-source community edition and an enterprise deployment.

  • Runtime intelligence across thought, behavior, and data
  • Allow / sanitize / align / degrade / approve / deny decisions
  • Community edition (open source) and enterprise deployment
  1. 01Risk research
  2. 02Evaluation evidence
  3. 03Protection strategy
  4. 04Runtime feedback

Evidence moves into protection. Operational signals sharpen the next evaluation.

NUWAFRONTIER RISK RESEARCH

Shared Risk Evidence and Public Goods for the World

NUWA Frontier AI Safety Lab advances frontier AI risk research and governance through reproducible evidence, evaluation methods, and public goods.

  1. 01How do we define and measure frontier AI risk — autonomy, deception, loss of control?
  2. 02How do we build evaluation environments that make agent cybersecurity capability observable?
  3. 03How do we turn risk understanding into deployable safety models and runtime control?

Runtime control

A boundary that stays with the agent loop.

Follow one real task from intent to external action, with data, authorization, and action impact checked at every interaction boundary.

AgentGuardAgentGuard Interaction Boundary Runtime
Continuous protection
Business task

Summarize renewal risk and send a management brief to an approved external advisor

01Business goalRenewal analysis
02Agent planningDecompose task and select tools
03LLM reasoningBuild retrieval and analysis plan
04Tool callsCRM · contract · knowledge
05ObservationReturn results into context
06Agent re-planningGenerate management brief
07External actionHTTP to approved advisor
AgentGuardInteraction boundary runtime across the agent loop
  • G1LLM Before / After
  • G2Tool Before / After
  • G3Memory Write
  • G4Commit Boundary
Data chainIdentity · contract fields · derived summary
AuthorizationOperations agent · single task · approved target
Action impactRead → create → send
DetectedSensitive fields are about to cross an external boundary
AgentGuardRedact fields · recheck payload · allow safe output

Analysis continues · compliant egress · fully audited

EVIDENCE & UPDATES

Ground every claim in verifiable progress.

Recent result

Fudan Baize ranks second globally in AI attack-defense evaluation

On the international AI safety benchmark CyberGym, the Whitzard agent reached a 91.2% success rate, ranking second globally and first among universities. This result reflects the strength of Whitzard's research foundation in agent cybersecurity.

Fudan Baize WeChat official account

Open ecosystem

Open models, tools, and evaluation infrastructure

WhitzardAgent hosts open-source projects spanning agent development, safety evaluation, thought correction, and behavior-chain auditing.

Explore the open ecosystem →

Product access

Bring verifiable boundaries to your agent system.

Tell us about your environment, current deployment stage, and the security problem you need to solve.