Replica Cyber puts financial AI agents in isolation, with an off switch
Founders Kristopher Schroeder and Ryan Underwood are extending a secure-operations platform into runtime containment for autonomous agents.
By RuntimeWire Staff · Published
Primary source: PR Newswire
Why it matters
Agent security is becoming a heavily funded category. Replica Cyber is betting banks will buy a hard execution boundary, giving its older isolation platform a route into the agent boom.

Replica Cyber co-founders Kristopher Schroeder and Ryan Underwood launched an architecture on August 31 that places autonomous AI agents inside isolated workspaces for banks and other regulated businesses. Replica Cyber says security teams can observe, pause, terminate, and replay an agent's actions without giving it a direct path to the corporate network.
The product announcement turns the founders' counterintelligence background into a timely enterprise pitch. AI agents can autonomously perform high-risk digital work. Schroeder and Underwood want banks to treat that work like malware analysis or a dark web investigation: useful, inherently risky, and best performed somewhere a failure cannot spread.
Schroeder began programming in the late 1980s and spent 17 years at Booz Allen Hamilton, where Replica Cyber says he led a systems-delivery business generating about $40 million annually. His work included open-source intelligence systems, federal pandemic-data collection, and horizon-scanning tools for large companies. Underwood previously worked as a software architect on internet surveillance, telecommunications, attribution, and cyber-counterintelligence programs, including as a chief engineer at Booz Allen.
Their shared thesis predates the agent boom. The founders started the business as Grey Market Labs, a public-benefit corporation built around protecting sensitive online work. Grey Market Labs became Replica Cyber in March 2025, while remaining the legal entity behind the brand.
The boundary is the product
Replica Cyber's new architecture assigns each agent an isolated environment spanning the operating system, applications, network, and data layers. Its existing platform already provides hardware-isolated workspaces for jobs such as fraud investigations, malware analysis, AI testing, threat intelligence, M&A due diligence, and secure collaboration.
The agent product adds runtime control. According to Replica Cyber, administrators can see what an agent is doing, interrupt it, terminate its session, and reconstruct the complete sequence later. That approach aims to contain the consequences of an agent's behavior instead of relying solely on permissions, prompts, or retrospective monitoring.
"An agent that needs an exception is an agent no regulated enterprise should ever run," Schroeder said in the announcement.
That line captures the commercial argument. Security exceptions were manageable when they involved occasional human activity. An autonomous system can repeat the same risky action across thousands of files, accounts, or external services before an analyst reviews a log. Replica Cyber is selling a structural limit on what the agent can reach.
Replica Cyber says its environments have supported production workflows in defense and financial services since 2018. The operational and security performance of the new agent architecture remains a company assertion. Production deployments will have to show that isolation holds across integrations, credentials, data transfers, and the external tools that make agents useful in the first place.
Replica Cyber's product materials say its technology is protected by over 20 patents focused on privacy-by-design and attack-surface reduction. The company has not provided an independently reconciled patent count.
An old security architecture finds a new workload
Replica Cyber's advantage is that Schroeder and Underwood did not have to invent an enterprise isolation platform after autonomous agents became a board-level topic. They are adapting infrastructure originally designed for people conducting dangerous digital work.
The platform provisions disposable or persistent workspaces separated from the user's primary network. Replica Cyber says those environments support full desktop applications, controlled data movement, managed attribution, collaboration, APIs, and audit records. Replica Cyber's company homepage describes administrative controls and workflow automation through scheduled jobs.
That foundation gives Replica Cyber a coherent path into AI security. A fraud team could let an agent collect intelligence from unfamiliar websites, analyze suspicious files, or assemble evidence while keeping the activity inside a controlled workspace. A model-testing group could evaluate an outside system without placing corporate source code or internal credentials directly in its execution environment.
Replica Cyber's May 12, 2026 report says its survey of 200 U.S. cybersecurity leaders found that 32% of organizations had delayed or canceled market expansion, product launches, M&A, or AI deployment because the work could not be conducted securely. The figure is company-sponsored demand evidence, not an independent measure of Replica Cyber's product performance. It still points to the budget that Schroeder and Underwood are pursuing: projects that business leaders want to automate and security teams cannot approve under existing controls.
Agent control is becoming an expensive category
Replica Cyber is entering a market attracting larger pools of capital. Onyx Security launched with $40 million in March 2026 for a control plane that discovers agents, monitors their reasoning, and can block or redirect actions. WitnessAI raised $58 million in January 2026 while expanding its agent-governance products. On August 17, 2026, Fortinet announced its acquisition of Virtue AI to add runtime protection and automated validation to its security portfolio.
Replica Cyber is taking a narrower architectural position: monitoring and policy still matter, but agents performing consequential work need an execution environment separated from production systems. That gives buyers a clear distinction to test against control-plane products that sit closer to the model, tool calls, or policy layer.
Schroeder and Underwood have raised less venture capital than several newer competitors. Replica Cyber announced an $8 million Series A in November 2024, led by Capri Ventures with participation from Blu Ventures and AFG. Replica Cyber had operated as a bootstrapped business before that financing, and no valuation was attached to the round.
The smaller capital base makes the founders' existing platform central to the bet. Replica Cyber can sell the agent architecture through the same isolated-environment model it developed for investigators, intelligence analysts, and other users handling untrusted systems. Banks do not need to accept a newly invented security premise. They need to decide whether a proven form of workload isolation can accommodate autonomous software without making the software too slow or constrained to be worthwhile.
That decision will determine whether Replica Cyber becomes infrastructure for production agents or remains a controlled venue for experimentation. The founders have drawn a hard boundary around autonomous work. Financial institutions now have to decide which agents deserve to operate inside it.