Skip to Main Content

X-Arc

Built at RAISE Summit Hackathon · Jul 4, 2026 · Paris, France

Demo video · www.loom.com/…

We run our autonomous coding agents with --dangerously-skip-permissions, permission prompts kill real autonomy, but turning them off removes the last defense against a poisoned input hijacking the agent. Airlock closes that gap with a two-tier, on-device firewall. Tier 1: Gemma 3 QAT runs 100% locally via Ollama and reads every input, web page, email, and tool result BEFORE the agent does — quarantining prompt-injection and data-exfiltration attempts with the exact malicious span highlighted and the source's trust revoked. The agent never sees them. Tier 2: a network layer enforces a host allowlist and redacts secrets, so nothing exfiltrates even if something slips past. A cloud injection scanner has to upload the very content it's protecting. Airlock never does - every verdict is a local call to 127.0.0.1, nothing leaves your machine. On our held-out corpus, 4B and 12B catch 21/21 attack families; on public deepset/prompt-injections the 12B screener scores 76.5% detection at 5.4% false-positives.

Team