Lilith

Mandatory access control for AI agents. A product of BadCompany.

Agents were built on the newest, tallest stack. More model, more tools, more abstraction. That is playing with fire.

Lilith is the older idea. Its policy engine decides each tool call. Its kernel enforcer makes the decision bind. Two parts. Simple machinery. Highest guarantee.

Policy engine

Authorization on the call itself: principal, action, resource, context. Expressive enough to write the real rule. Formal verification is built in: proven before anything goes live.

Kernel enforcer

We halt syscalls, the lowest operations an OS performs. BPF kernel extensions, verified by the kernel before they attach. Userspace does not get to argue with a deny.

Properties

Product OpenSource Write

BadCompany, 2026. Born out of mesh.(R)

Team | Git