The people behind oktsec

From open source
to AI agent security.

Oktsec grew out of security research and open-source engineering. We build controls for the tools AI agents use, the actions they can take and the evidence teams need to review their work.

Security for a world that runs on agents.

AI agents change what organizations need to secure. They can act across tools and systems, carry out tasks and pass work to other agents. Preparing for this requires clear limits on their authority, records people can verify and teams who understand when to intervene.

01 / Our vision

A world ready to work with AI agents.

Our vision is a world ready to work with AI agents, with the security controls and practical skills to use them responsibly. Across industries and countries, organizations need both systems they can govern and people prepared to supervise the work they delegate.

02 / Our mission

Make delegated authority enforceable.

Turn the permissions people grant into controls that hold when agents act. Our mission is to carry that authority across tools, systems and other agents: define the limits, enforce them at execution and preserve evidence people can verify.

Founded in Buenos Aires.Building security infrastructure for a global shift.
Meet Gustavo Aragón

The experience behind Oktsec.

Experience
20+ years in technology
Leadership
12 years in technology leadership
International experience
Argentina, Brazil, New Zealand and Hong Kong

Gustavo co-founded Brelo, a fintech startup in São Paulo, where he spent seven years as CTO developing and patenting low-level device-locking technology for loans secured by mobile phones. Today, he works full-time on Oktsec, drawing on that experience alongside his security research and open-source work.

Oktsec · Founder

Building Oktsec to help companies stay in control as AI agents gain access to more tools and systems. Oktsec checks actions against the team’s policies and keeps a verifiable record of each decision. Security assessments and dependency reviews help teams find weaknesses in the workflows they plan to deploy.

Banza/Adcap · CPTO

As Chief Product and Technology Officer, led product and technology in regulated financial services.

Brelo · Cofounder & CTO

Spent seven years building Brelo in São Paulo, Brazil, working with the team on patented device-locking technology for mobile collateral lending.

01
Selected as an Argentine entrepreneur for the 2026 Americas Competitiveness Exchange (ACE), convened by the Organization of American States. Gustavo will join leaders from business, government and research in Barranquilla, Colombia, September 28–October 2. Read the announcement.
02
Security findings reported through Google, Microsoft, Stripe, Cloudflare, AWS and Mercury programs.
03
AgentPay won first place at the Anthropic × Kaszek Latin America hackathon in 2026. The prototype applied deterministic checks to payments between agents.
04
Inaugural Agentic AI Foundation Ambassador and Claude Code Partner. Approved for OpenAI Daybreak Blue and Anthropic Cyber Verification defensive research access.
How we work with customers

What to expect from an engagement.

Agree the scope and permitted tests first. Your team reviews the findings and decides which controls to adopt.

Scoped Assessment

Start with one workflow. Explicit rules of engagement. Findings with executable evidence.

Customer controlled runtime

Enforcement stays in environments you own. No inbound requirement to run Oktsec Control.

Confirm and hold safety

Prove the path without escalating beyond the agreed scope. Keep a full trail after the run.

No secrets in web forms

Use forms to describe the workflow. Do not include secrets, credentials, customer data or source code.

Work you can examine.

Explore the research, customer example and open source projects behind oktsec.

01

Published research

Read the attack analysis, reproduction methods and sources in the research archive.

02

Customer use

See how Certuma combines agent assistance, policy checks and physician review.

Review the workflow you plan to deploy.

Assessment tests the workflow and returns reproduction steps and recommended fixes. Control applies policy to requests during operation.