Arcjet Labs, Inc.
Arcjet is an AI agent runtime security and application security platform. It puts security decisions inside application and agent code to discover agents, enforce policy across actions, prompts, and tool calls, detect prompt injection, redact sensitive information, and block bots and abuse.
At a Glance
- Security and platform teams
- Engineering teams building AI agents, MCP servers, and agentic workflows
- B2B SaaS product and platform teams
- AI and e-commerce companies
- +2 more
AI Tools by Arcjet Labs, Inc.
(1)Arcjet
Runtime Security for AI Agents
Discussions
No discussions yet
Be the first to start a discussion about Arcjet Labs, Inc.
Latest News
Introducing Agent Runtime Security: Observe, Enforce, Audit
The two speeds of AI agent runtime security
SDK releases, security briefing improvements, and a new activity view
Announcing advanced bot signals to detect automation without CAPTCHAs
Products & Services
Runtime security for coding agents and custom agents: discover agents, enforce policy across actions, prompts, and tool calls, and retain evidence for governance and compliance.
Security rules that run inside AI-agent tool handlers, queue consumers, workflow steps, and other application code without requiring an HTTP Request object.
Open-source JavaScript/TypeScript SDK for adding application and AI protections in code, including Shield WAF, bot detection, rate limiting, email validation, signup protection, sensitive-information detection, prompt-injection detection, and content moderation.
Open-source Python SDK supporting asynchronous FastAPI and synchronous Flask applications, with rate limiting, bot detection, email validation, and signup-spam prevention.
Market Position
Arcjet positions itself as developer-first, in-code runtime security rather than an edge-only WAF, network gateway, model wrapper, or observability dashboard. Its official comparisons identify Cloudflare, Datadog AI Guard, Runlayer, Onyx, Pillar, and Lakera as alternatives or competitors; Arcjet differentiates through access to application context, protection of tool calls and queued work that may not traverse HTTP, local-first analysis, and one policy/evidence model for both agents and web applications.
Leadership
Founders
David Mytton
Founder and CEO; previously founded Server Density (acquired), co-founded Console (the console.dev developer-tools newsletter), and researches sustainable computing at the University of Oxford.
Executive Team
David Mytton
Founder and Chief Executive Officer
Previously founded Server Density, co-founded Console, and researches sustainable computing at the University of Oxford.
Founding Story
Arcjet was started after David Mytton observed that production security tooling still behaved like a network appliance while developers were building on Next.js, serverless infrastructure, and increasingly AI agents. The initial vision was to make developer-first, context-aware security an integral part of the application and development workflow rather than a generic perimeter control.
Business Model
Revenue Model
Paid SaaS subscriptions for teams and applications, plus usage-based request fees; Enterprise contracts are custom. New accounts receive a 15-day trial, followed by a free plan capped at 10,000 requests per month.
Pricing Tiers
1 team member, 1-hour log retention, email support, plus usage fees.
2 team members, 24-hour log retention, email and Slack support, plus usage fees.
Unlimited team members, SIEM export, and priority support.
Usage-based pricing shown on the pricing page.
Target Markets
- Security and platform teams
- Engineering teams building AI agents, MCP servers, and agentic workflows
- B2B SaaS product and platform teams
- AI and e-commerce companies
- Developers and startups shipping Next.js, serverless, API, and modern web applications
- Organizations needing SIEM integration, governance, and compliance evidence
- Securing coding agents such as Claude Code, GitHub Copilot, Cursor, and OpenAI Codex
- Protecting custom AI agents, MCP servers, and agentic workflows
- Gating AI-agent tool calls and preventing unauthorized actions
- Preventing prompt injection and PII or secret leakage
- Protecting APIs and AI endpoints
- Blocking malicious bots, scrapers, automated abuse, and fraudulent signups
- Checkr
- Creem
- JD Group
- A content-heavy community-forum customer that reduced serverless cloud costs by 66% using Arcjet protections against malicious bot scraping