About
ExfilPath Pvt. Ltd builds one thing, and builds it properly.
Mission
Make one dangerous question easy to answer.
Teams shipping agents are asked to reason about prompt injection, tool permissions, data boundaries and output handling all at once, usually with tooling that reports each in isolation. The result is a long list and no decision.
ExfilPath collapses that into a single question with an actionable answer: can attacker input reach an action that causes damage? If it can, here is the route and the smallest change that closes it. If it cannot, you are done.
We think that is the smallest useful unit of agent security, and that dashboards, scores and policies are decoration on top of it.
What we do
We build static analysis for AI agent systems. Given source code, ExfilPath produces the map of routes between untrusted input and damaging actions, with the fix for each open route.
What we do not do
We do not sell a dashboard for everything, we do not run your agents, and we do not ask for credentials. One question, answered thoroughly, is the whole product.
How we fund it
Through plans that teams choose after evaluating the platform, not through gated evaluations. That is why analysis is free in early access and priced transparently for general availability.
How we publish
Every detector traces back to a public disclosure or a pattern found in real agent code. The reasoning is on the research pages, with links to primary sources.
How we got here
Four steps, in order.
The observation
Agent code kept passing every scanner
Reviewing agent systems, we kept reaching the same result: the tooling was green, and a careful reader of the code could still draw a line from an inbound message to an outbound request. The tools were answering component questions. The risk was a composition question.
The research
Public breaches confirmed the shape
EchoLeak in Microsoft 365 Copilot and ForcedLeak in Salesforce Agentforce were not misconfigurations. Both were reachable routes through correctly configured systems. That is when we stopped writing warnings and started modelling paths.
The platform
One question, made machine-checkable
ExfilPath encodes that reasoning as 46 detectors across input surfaces, sensitive actions, controls and model boundaries — and reports only what actually connects.
Today
Early access, in the open
The platform is in the hands of engineers, the detector logic is documented publicly, and the research behind every rule is published rather than described. Plans are priced and visible so teams can plan ahead.
Team
Engineers and researchers, answerable for the engine.
Analysis engine
Interprocedural path tracing, language front-ends, and the precision work that keeps findings trustworthy.
Security research
Breaking agent frameworks, turning each break into detectors, and publishing the reasoning.
Product engineering
Making a path finding read like an explanation: traces, diffs, pipeline output and editor surfaces.
We are hiring across all three. Open roles.
Reviewed with security and platform teams in Nepal and beyond
Reviewers
Teams that pressure-tested the work with us.
NovaGrid Systems
Agent platform review
QuantumLeaf Technologies
ML pipeline review
VertexScale Labs
Backend agent review
HyperNova Cloud
Platform engineering review
Early reviews
Engineers who put the platform against their own agents.
“Our scanners were green while an email could still walk a summary straight out to an external host. ExfilPath was the first tool that drew that route instead of handing us another list.”
“The part that changed my mind was the trace through the model call. Everyone talks about prompt injection in the abstract; this showed the exact three lines that made it exploitable.”
“It reads the repository, finds where untrusted text enters, and tells you which action it can reach. We closed two paths with one-line changes the same afternoon.”
“What I want from a security tool is a decision, not a dashboard. Open path or no open path is a decision my team can act on in a release meeting.”
How we build
Four rules we hold ourselves to.
One question, answered well
We are not building a dashboard for everything. We answer whether a route exists and how to close it.
Findings must be arguable
A finding you cannot verify is a finding you will ignore. Every path shows its trace, its controls and its reasoning.
Read code, never run it
Analysis stays static, so assessing an agent is never itself a risk.
Security tooling should be easy to adopt
No credentials, no agents to deploy, no data pipeline. Point it at code and get an answer.
Questions about the company or the platform?
Write to hello@exfilpath.tech and an engineer will answer.