Application and AI agent runtime security
Arcjet
Arcjet builds runtime security that developers embed in applications and AI workflows through a library and API. Its controls detect prompt injection, strip sensitive data, limit token spending by user or organization, and restrict agent tool actions by identity, role and route. Enforcement runs inside the application before the next action, using session and business context. Arcjet Remote Rules lets security teams tune policies with review and approval before production. The approach serves AI application developers managing abuse and compute costs, alongside e-commerce teams addressing scraping and fraud.
Founded in 2023 by CEO David Mytton, Arcjet follows his earlier infrastructure monitoring company, Server Density, which StackPath acquired in 2018. Its engineering work emphasizes security checks within the request path: an optional local sensitive-information detector combines deterministic recognizers for structured data with an on-device model using ONNX inference. Arcjet has also reduced its Rust WebAssembly bot detector’s bundle size while retaining per-request memory isolation.
In 2025, the company reported more than 1,000 developers using Arcjet across more than 500 production applications, processing millions of requests daily. That year, it raised an $8.3 million Series A led by Plural and Ott Kaukver, bringing its reported total funding to $12 million.
1 talk
Newest first1 speaker at AIE
Affiliations reflect their AIE appearances, not necessarily current employment.
Messages from the stage
Checking automated clients
Mytton describes inspecting HTTP user agents, checking source IP addresses with reverse DNS, and deploying open-source proxy defenses. He also introduces emerging HTTP request-signature standards for verifying automated clients.
Affiliations reflect each recorded session, not necessarily current employment.
