Long-horizon investigation
Agents must maintain and revise hypotheses across many tools, systems, and time periods.
We build environments and benchmarks for investigations that unfold over hundreds of steps.
Applied defense, deployed inside the world's critical institutions.
Bollwerk Labs
Bollwerk Labs is an applied defense lab in Zurich, making autonomous intelligence safe enough to deploy with real authority. We build and deploy agents and foundation models alongside the institutions they defend.
Reasoning became cheap, and attackers got the upgrade first. Intrusion, fraud, and deception now run as software: built on demand, run at volume, discarded after one use. The window from first probe to impact has shrunk from days to minutes.
$40B
GenAI-enabled fraud losses projected in the US for 2027.
Source · Deloitte Center for Financial Services
77%
Of global cybersecurity respondents reported an increase in cyber-enabled fraud.
Source · WEF Global Cybersecurity Outlook 2026
90M
Risk professionals whose work AI rewrites within ten years.
Source · Bollwerk analysis, ILO and OECD cross-check
Research
These are the problems the lab exists to solve. We work on them inside real institutions and publish what holds up.
Agents must maintain and revise hypotheses across many tools, systems, and time periods.
We build environments and benchmarks for investigations that unfold over hundreds of steps.
The evidence itself may be deceptive, generated, incomplete, or deliberately poisoned.
We stage synthetic adversarial cases and red-team environments that make failure visible before deployment.
Useful agents must act while respecting permissions, regulations, and institutional risk boundaries.
We run a policy engine that evaluates every consequential action at call time.
A consequential decision must be reconstructable and challengeable after the fact.
We record evidence lineage and replayable traces that preserve sources, policy, reasoning, and human judgment.
Stay close to what we ship.
Occasional product updates, research notes, and threat-intel briefings. Unsubscribe anytime.
The operating layer investigates and governs. The training layer improves. Together they turn each closed case into a stronger system.
Governed multi-agent systems gather evidence, maintain hypotheses, construct the case, and propose the action. Policy evaluates every consequential step. A person makes the call.
Decisions and confirmed threats become training signal. Foundry synthesizes cases for unseen typologies and promotes a new agent only when it beats the last across the institution's history.
Culper runs governed agents inside risk teams. Foundry trains and runs the models underneath, straight from your warehouse. Together they transform the workflow itself: agents absorb the casework, your analysts keep the decisions.
For enterprise risk teams
Autonomous agents that investigate your biggest threats in real time. Every consequential action gated, recorded, and proven.
Explore CulperFor engineers
The machine-learning workbench for risk models. It trains and benchmarks candidates against your own warehouse, with no egress, and ends every run in one recorded decision: promote, keep, or stop.
Explore FoundryFree assessment New
Choose an eight-question triage or the full twenty-two-question assessment, each with one sector-specific question, across seven dimensions of AI-driven threat exposure: payment-instruction integrity, synthetic-media readiness, AI-augmented phishing, AI-aware fraud typologies, security of your own and vendor AI surfaces, AI incident response, and AI inventory / data exposure. Anchored to NIST AI RMF, NIST AI 600-1, OWASP LLM Top 10, FATF digital-identity guidance, and the major operational-resilience frameworks.
8 + 1 or 22 + 1
7
~6-12 min
Free
60 days. Shadow mode. Your data, your policies, your audit team. See how it performs against real traffic before you turn enforcement on.