Background Pattern

JADS Playground startup Kyvvu raises € 1.0M in seed funding

Posted on

Kyvvu, a Dutch AI startup, has raised €1 million to fix a security gap that most companies deploying AI agents don’t yet realize they have: an agent can follow every rule it’s given and still cause a breach, simply by combining permitted actions in the wrong order. The pre-seed round was backed by Volta Ventures and the Brabant Development Agency (BOM). Kyvvu, based in Den Bosch, builds a security layer that sits inside AI agents and, in under a millisecond, checks whether each action they’re about to take should actually go through.

This item was first published on the BOM website.

Until recently, enterprises largely used AI to make suggestions. They are now allowing it to act: updating customer records, moving data between systems, issuing refunds and running back office processes end to end. That shift is what makes agents valuable, and it is also what makes them a security problem. An incorrect suggestion is an inconvenience. An incorrect action is an incident, and in banking, insurance and healthcare it is one that has to be reported to the regulator.

The gap is not in what an agent is permitted to do, but in the order in which it chooses to do it. An agent reads a customer record it is permitted to read, and then sends an email it is permitted to send, to an address outside the organisation. Both steps pass their own check. Together they are a data leak. Existing security tools assess one action at a time, and because an agent decides its own route while it is running, no one can predict which sequence it will take. The harmful combination passes straight through. The path is the breach.

Security layer

“The internet only scaled once we built the security layer that made it safe to run real workloads on it. Agents are at exactly that point. They will only be trusted with work that matters once something inside them is checking each action before it happens,” said Jeroen Ghijsen, co-founder and CEO of Kyvvu.

Kyvvu’s Agent Security Kernel (ASK) runs inside the agent itself: every agent has to ASK before it acts. It sees every action the agent takes, whether that is reading data, calling a tool or sending a message, and weighs it against everything the agent has already done in that task before deciding to allow, warn or block. The rules are plain, version controlled policies that a compliance officer can read, not a second model’s judgement, and they stay in the customer’s own systems. The engine is deterministic: the same input produces the same verdict every time. Enforcement happens entirely inside the customer’s environment, so sensitive data never leaves it in order to be checked. Decisions land in under a millisecond, which means the agent runs at full speed.

 

Kyvvu is the kind of company that keeps this region competitive in AI.

Robin Hendrickx
Senior Investment Manager and Teamlead Key Technologies at BOM

The kernel works with any agent framework and is available as source code, so security teams can read exactly what is enforcing their policies. It is already deployed at financial services, insurance and healthcare organisations in the Netherlands, together with Kyvvu’s integration partners.

“Enterprises are deploying agents faster than they can govern them, and the tooling to keep those agents in line simply has not existed,” said Sander Vonk, Managing Partner at Volta Ventures. “We think a runtime control point becomes a hard requirement for running agents at scale, the way endpoint security did before it. We are backing Jeroen, Maurits and the team to define what that looks like.”

“Kyvvu is the kind of company that keeps this region competitive in AI,” said Robin Hendrickx, Senior Investment Manager and Teamlead Key Technologies at BOM. “Every large enterprise putting agents into production is about to run into the same wall, and this team is already on the other side of it, from Den Bosch, with live customers in some of the most heavily regulated sectors in the country.”

EU AI Act

Because every action passes through the same component that can stop it, Kyvvu produces a complete and trustworthy record of what each agent actually did. That record maps directly onto the record keeping, human oversight and robustness obligations of the EU AI Act and onto GDPR accountability requirements. For customers, the audit trail is a byproduct of getting the security right rather than the reason to buy.

Kyvvu has its roots at the Jheronimus Academy of Data Science in Den Bosch, where team members were building agents before most enterprises had put one into production. As the security risks became undeniable, the team went into stealth mode to build the control layer that agents were missing. Its own research, published as Runtime Governance for AI Agents: Policies on Paths (Routledge), showed that the path an agent takes can be governed separately from the permissions of each individual step. The company built its product on that result before going public with it.

“We asked whether the path an agent takes could be governed on its own terms, proved that it could, and then built something a bank can actually run to keep their agents safe,” said Maurits Kaptein, co-founder and CTO of Kyvvu.

The company will use the funding to expand its engineering team, grow its network of integration partners and support enterprise and public sector deployments from Europe outward.


Stay up to date!

Register for our monthly newsletter

Group 5
Group 6
Group 7
JADS