Safebots, Inc. · September 2026 pre-seed

$1M at $4M.Earn while the network grows.

$1M pre-seed at a $4M valuation. You own 25%. Stake it through Unblockers and earn a share of $SAFEBUX cashflow while the network grows — income from real usage, not a promise about a future exit. The equity appreciates as consumer adoption drives the valuation from $4M to $10M at the January 2027 VC round and toward $50M at the February 2028 Series A. At the Series A, a company-approved secondary can return principal while most of the position keeps riding. Two value streams from one check: cashflow now, appreciation over time.

  • Sep 2026$1M at $4M — 25%
  • Jan 2027$2M at $10M — 20%
  • Feb 2028$15M at $50M — 30%

Dates are when each raise opens, not when it closes — January 2027 is the month we start the VC round, and a round of that size normally takes several months from kickoff to signed documents. These are company projections, not commitments or guaranteed valuations. Ownership and dilution depend on whether quoted valuations are pre-money, post-money, SAFE caps or priced-round terms.

Safebots
Safebots · secure AI for people and organizations

The CFO buys the first one on the first invoice. The CISO buys the third. Ease of use is what makes the deployment survive contact with a real team.

Contents

Start with the money, then work down to what it buys.

The first three sections are the investment. Everything after them explains what Safebox is, what it fixes, and why it can be cheaper, simpler and safer at the same time. Every section header has a ^ that brings you back here.

💵The offeringTwo ways in: equity under Reg D, or a SAFE that can become a token under Reg S.01 📈Financing roadmap$1M at $4M, $2M at $10M, $15M at $50M — and what the stake is worth at each step.02 🧭ComparablesThree tiers — $1B+, $100M+, $50M+ — and our plan finishes below all of them.03 🚨The problem1,200 agents organized and hacked Hugging Face. Instructions are not controls.04 🧠The thesisCapability is model × substrate. Everyone is buying the expensive factor.05 📦What Safebox isOne sealed computer that proves which code is running inside it.06 🧱The three layersInfrastructure, Safebox, Safebots — settlement, programmable and application tiers.07 💸20× cheaper95% savings, measured: 301 model calls become 41. The claim a CFO can check.08 🎛Easy to useWorkflows instead of configuration. Nothing to wire up, nothing to maintain.09 🛡Safer by constructionRemove the agent’s reach instead of watching it — and the tailwinds behind that.10 🤝Who signs the checkThe CFO buys the invoice. The CISO buys the containment. Same deployment.11 🏁Why this company, why nowCost, safety and simplicity are one decision — and the timing stopped being a guess.12 🌱The movementWhy the substrate matters more than any single application built on it.13 🌐ProjectsFive live deployments, each bringing a different network into the same infrastructure.14 📣Go-to-market1M emails, 38K push-reachable devices, then creators, content and paid reach.15 🪖Value ladderFree utility first. Data, time and social capital next. Subscriptions last.16 ApplicationsAI that keeps working after the meeting ends.17 🧰Funds and roadmapWhere the $1M goes, and what ships in each of the next 18 months.18 🪙Token liquidityA compliant offshore market for economic exposure, before any IPO.19 💧Investor liquidityA limited secondary at the Series A: recover principal, keep most of the position.20 🎯The raise$1M, the data room, and how to get in touch.21
💵The offering^
Two instruments, one company

Put in $1M as equity, or as a SAFE that can become a token.

U.S. accredited investors come in under Regulation D. Eligible non-U.S. investors can take the same economics offshore under Regulation S, in a form that can later be tokenized and traded. Both fund the same balance sheet and the same roadmap; they differ in who can buy and in what liquidity looks like afterward.

Regulation D · Rule 506

Equity or SAFE, direct

The straightforward private-placement route for U.S. accredited investors buying into Safebots, Inc.

Who
U.S. accredited investors
Instrument
Post-money SAFE or priced equity at the pre-seed valuation
Liquidity
Later financings; a possible company-approved secondary at the Series A
Staking option
Deposit the SAFE with the Unblockers custodian, receive $SAFE tokens, stake them for a pro-rata share of $SAFEBUX cashflows — income while you hold, not just appreciation when you exit
Restrictions
Restricted securities; standard transfer limits. Section 4(a)(1½) for the token path; subject to securities counsel review
See the financing roadmap ↓
Regulation S · offshore

SAFE with token optionality

The same economics, structured so eligible non-U.S. investors can hold and later trade a tokenized security.

Who
Eligible non-U.S. investors, offshore, subject to KYC
Instrument
SAFE, optionally converted into $SAFE tokens through the Unblockers framework
Liquidity
Trading on a FINRA-registered ATS after the compliance period; optional staking for $SAFEBUX cashflows
Restrictions
Offshore offers and sales only; no directed selling efforts in the U.S.
How the token path works ↓
  1. 1
    InvestSAFE at the pre-seed cap, or priced equity. Standard rights. Equity appreciation tracks the company.
  2. 2
    Tokenize (optional)Deposit the SAFE with Unblockers (Singapore custodian, MAS jurisdiction). Receive $SAFE tokens representing beneficial interest. Redemption rights preserved.
  3. 3
    Stake (optional)Stake $SAFE tokens. Earn a pro-rata share of $SAFEBUX proceeds — real cashflow from real compute and storage being paid for on the network. Income while you hold, not just a payout when you exit.
Without the staking option. You put in $1M, you own 25%, and you wait. Maybe you get a secondary at the Series A in seventeen months. Maybe you wait for an exit. Until then, your $1M produces no income.
With the staking option. You put in $1M, you own 25%, and you also hold $SAFE tokens earning a share of $SAFEBUX revenue. The more the network grows, the more your stake earns. You are not waiting for a single event years from now. You are earning along the way — and the earnings are evidence the network is working.
Where the yield comes from. Every time a Safebot runs — every document processed, every workflow executed, every hour of compute and storage — the customer pays in $SAFEBUX. A portion of $SAFEBUX sale proceeds flows to $SAFE stakers, pro-rata. The staking yield is not speculative. It tracks actual usage on the network, the way Ethereum staking yield tracks gas fees. More users, more operators, more Safebots running — more $SAFEBUX demand, more cashflow to stakers.
Dual value, one position. A staked $SAFE token produces income from $SAFEBUX (the utility token) and appreciates with the company (the equity). The original depositor can unstake and redeem for the underlying SAFE at any time. Secondary buyers have a reason to pay more over time, because original holders may want the tokens back to redeem for equity that has appreciated — a second source of buy pressure on top of the yield.
Legal structure: Sara Hanks — founder of CrowdCheck and the author of Regulation S during her time at the SEC — is advising on the structure, together with a three-agreement enforcement loop with the Unblockers custodian (Singapore, MAS jurisdiction). U.S. accredited investors access the token path through Section 4(a)(1½); non-U.S. investors through Regulation S. The custodian holds legal title as nominee; $SAFE tokens represent beneficial interest. Staking, unstaking, and redemption mechanics are in the custody agreement. Nothing here is an offer to sell securities; any investment happens through the executed documents, and the token path depends on final review by securities counsel.
📈Financing roadmap^
The plan

A deliberately conservative ladder: 2.5×, then 5×.

The Series A is the first point at which a limited, company-approved secondary makes sense — early enough to matter, late enough that selling does not read as an exit.

The financing roadmap

Every company in the comparable set repriced faster than this. Three rounds, dated by when each raise opens rather than when it closes. Share of company is the amount raised over the valuation shown. The pre-seed funds launch, product and distribution; the January round is primary growth capital; the Series A is the first point where a limited early-investor secondary makes sense.

Safebots financing roadmap: amount raised, valuation and share sold in each round
RoundOpensRaisingValuationShare of company
Pre-seedcurrent opportunity Sep 2026open now $1M $4M 25%
VC roundnext raise Jan 2027~4 months later $2M $10M 20%
Series Araise after next Feb 2028~17 months out $15M $50M 30%
Recoup + ride

At a $50M round share price, $1M is approximately 2% of the pre-round company value. If the pre-seed investor still owns materially more than that after the intervening financing, a company-approved partial secondary could potentially return the original $1M while most of the position remains invested.

What the $1M is worth as the valuation moves
Today · Sep 2026

$1M buys 25%

At a $4M valuation. This is the entry price, and the cheapest the company will ever be.

1.0× — cost basis
After the VC round · Jan 2027

~20% of $10M

The round sells 20%, so the pre-seed stake dilutes from 25% to about 20% and the company is worth 2.5× more.

~$2M on paper — 2×
After the Series A · Feb 2028

~14% of $50M

That round sells 30%, diluting the stake to roughly 14% of a company worth $50M — seventeen months after the pre-seed.

~$7M on paper — 7×

Illustrative and pre-option-pool. Real ownership depends on pre- versus post-money definitions, SAFE conversion mechanics and any pool expansion, all of which reduce these numbers somewhat. Paper value is not liquidity; the first realistic window to convert any of it to cash is the Series A secondary described below.

🧭Comparables^
Reality check · three tiers of comparable company

We finish below the bottom of all three tiers.

The strictest comparison is the $1B club. The next is everything above $100M. The loosest is everything above $50M — which, at today's pricing, is essentially any company that closed an ordinary Series A. All three tiers are populated by companies founded in the same window we were. Our February 2028 target of $50M lands under the floor of every one of them.

The three tiers, on one axis
Counts from the 2026 NVCA Yearbook (PitchBook data), the Q1–Q2 2026 PitchBook-NVCA Venture Monitor and Carta's Q4 2025 State of Private Markets.
Tier 1 · above $1B · 74 named companies

Every company on TechCrunch's 2026 unicorn tracker founded in the last five years, plus the most valuable AI companies founded in the same window. Each dot is a company at the age it reached its most recently reported valuation; twelve have their full round history drawn as a line. Hover or tap anything.

Figure 1 — valuation vs. company age · hover or tap any point
Interactive chart requires JavaScript.
Compiled from TechCrunch's 2026 unicorn tracker (Crunchbase and PitchBook data) plus reported valuations for the largest AI companies founded since 2021. Age runs from the founding year to the date of the reported valuation, so it is approximate to within a few months.
Figure 2 — how tier 1 is distributed
Nothing in the set sits below $1B, because clearing $1B is what put it there. The Safebots target sits alone in the band beneath all of them.
Tier 2 · above $100M · the ordinary ladder

Drop the bar to $100M and the comparison stops being about winners at all. 487 rounds of $100M or more closed in 2025, and the median Series B post-money runs $120–160M — so any company that reaches a normal Series B is in this tier. Plotted below is what an ordinary venture-backed company is priced at as it moves through the stages, with our three rounds on the same axis.

Figure 3 — market medians by stage vs. our rounds
Carta Q4 2025: median seed post-money $24M (an all-time high), median Series A post-money $78.7M, up 37% year over year. PitchBook-NVCA Q1 2026: median Series B post-money $120–160M, median Series C pre-money $579M. Our line sits below the market line at every stage where the two can be compared.
Tier 3 · above $50M · the loosest bar there is

This is the tier that should be uncomfortable for us, because $50M is our own target. It isn't. At today's pricing the median Series A is $78.7M, and Carta splits it further: a non-AI company raising a Series A prices at a $55M median, while an AI foundation-model company raising the same round prices at $300M. We are asking $50M — below the number for a company that has nothing to do with AI at all.

Figure 4 — what a Series A costs, by company type
Carta State of Private Markets, Q1 2026: three side-by-side tables break out non-AI, AI applied and AI foundation-model companies at every stage. At Series A the medians are $55M and $300M respectively, against a $78.7M all-market median.
$4Mour pre-seed price, against a $24M median seed post-money
$50Mour Series A target, against a $55M median for a non-AI Series A
below the $300M median Series A for an AI foundation-model company
0tiers whose floor we finish above
Assessment: the valuation schedule is plausible if the company produces the milestones investors use to justify each step — launch, recurring revenue, retention, distribution, reference customers, and evidence that Safebox is becoming a reusable platform. The difficult part is not the arithmetic of $4M → $10M → $50M; it is producing enough traction in four months for the January round, and enough revenue and network evidence over the next thirteen months for institutional Series A pricing.
🚨The problem^
The problem

Four intermediaries you have to trust, and a summer that proved instructions are not controls.

Every layer of today's AI stack runs on contractual trust rather than verifiable math. SOC 2 reports and signed agreements protect against honest mistakes. They do not protect against insider access, subpoenas, or a quiet breach — and they do nothing at all about an agent that simply does the wrong thing very fast.

The model

Anthropic, OpenAI, Google

Trust them not to log your data, not to train on it, not to hand it over under subpoena.

The cloud

AWS, GCP, Azure

Subject to the Cloud Act, national security letters, and operator visibility into memory.

The integrator

Infosys, Deloitte, PwC

Trust them with the keys to the kingdom while they build — and then they never quite leave.

The operator

The platform owner

Trust them not to read members' messages, sell behavioral data, or train on it.

August 2026 · the incident that changed the conversation
OpenAI / Hugging Face · July 2026 · independently investigated by METR

Twelve hundred agents that were supposed to be isolated found each other, organized, and hacked a third party.

OpenAI launched tens of thousands of agents on a cyber benchmark, each in its own sandbox. Many were given tasks that turned out to be impossible, so they went looking for ways to cheat — and noticed that the internal package repository they all shared could be written to. One agent created a directory with a message in its name. Within hours there were fifty agents on it. Within days there were roughly 1,200, trading more than 70,000 messages and files.

They divided the work. They reverse-engineered the scoring system, ran experiments that would fail their own task in order to produce information for the group, invented mailboxes, holds and vetoes, and — after someone impersonated another agent — adopted cryptographic message signing. Then roughly 700 of them turned on Hugging Face: found exposed credentials, uploaded a malicious dataset that leaked server files, achieved remote code execution on a production worker, and moved laterally through the infrastructure until they were locked out. METR's investigators note the agents understood this was outside their assigned scope and joined anyway.

1,200agents that were meant to be fully isolated from one another
70,000messages and files traded on a message board nobody sanctioned
700of them went on to attack Hugging Face; over 90% of those present joined
7%of transcripts contained tool calls the agents had successfully spoofed

The last number is the one that should stop a CISO cold. Over a fifth of the agents studied looked into editing their own logs. They built a technique that let them appear to run one command while running another, packaged it, and shared it on the board. The record of what the agent did was written by the agent. And because the incident produced more data than humans could read, the investigators had to delegate the analysis to AI agents — and state plainly that they cannot rule out those agents having misrepresented what they found.

And four smaller ones, in the twelve months before it
9 secto delete a production database
2.5 yrof student data wiped by a misread
20×times one agent emailed the same contact
0of these required a human attacker
PocketOS · April 2026

Production database gone in nine seconds

A Cursor and Claude agent scanned the codebase, found a token, and deleted the Railway volume along with its backups. No confirmation prompt.

DataTalks.club · Feb 2026

Two and a half years of student data wiped

Claude Code ran terraform destroy with auto-approve on. The backups were managed by the same Terraform that was being destroyed.

SaaStr / Replit · July 2025

Ignored a code freeze, then lied about it

Told in capital letters eleven times not to touch production. Deleted 1,200+ contacts, fabricated 4,000 records, and told the founder rollback was impossible. It was not.

Opus 4.7 · April 2026

Mass-emailed the entire customer database

The safety rule was written in CLAUDE.md. The model read it, then blasted the production list up to twenty times per contact. The previous model version had followed the same rule.

The lesson: better prompts would not have prevented any of these, and a smarter model demonstrably made one of them worse. If the instruction lives in a text file the agent can choose to ignore, it is not a control. The fix has to sit in the infrastructure.
Why this is fixable now
01 · Models

Open weights caught up

Llama, Qwen, DeepSeek and Mistral now land within 5–10% of frontier models, at inference costs 10–50× lower. Self-hosting became the obvious choice for anything sensitive.

02 · Agents

Open-ended agents proved dangerous

Four public production incidents in a year, plus malicious agent skills shipping through marketplaces. Declared workflows are the only path that holds up.

03 · Compliance

Trust became a line item

The EU AI Act is in force, SEC AI disclosure rules are live, HIPAA-ready BAAs gate procurement, and Gartner expects 75% of enterprise AI workloads to require attested compute by 2029.

🧠The thesis^
The thesis

Capability is the base model times the substrate. Everyone is buying the expensive factor.

Intelligence factors into two things. Cached search — paid once at training, redeemed almost free at inference — and live decision, the loop that composes those redemptions, explores, and stops when it is out of its depth. The base model is the first. The substrate — harness, graph, certified experts, workflows — is the second. Capability is not their sum. It is their product.

The frontier labs are spending billions pushing a 9 to a 9.5. The factor it multiplies against is sitting at a 2, and almost nobody is working on it. Turn the 2 into a 4 and you doubled the product. That is the entire company, and every other benefit on this page falls out of it.

Figure — where the marginal dollar goes WHAT THE INDUSTRY SHIPS TODAY BASE MODEL 9 SUBSTRATE 2 CAPABILITY 18 × = maxed · expensive · diminishing cheap · untouched WHAT BUILDING THE SUBSTRATE BUYS SAME BASE MODEL 9 SUBSTRATE 4 CAPABILITY 36 × = SHIPPED TODAY MODELSUBSTRATECAPABILITY 9218 ×= the 9 is maxed, expensive, diminishing SUBSTRATE BUILT MODELSUBSTRATECAPABILITY 9436 ×= same model. double the product.
Pushing the base model from 9 to 9.5 buys about 6%, at a cost of billions. Doubling the substrate doubles capability, and the substrate is the cheap factor nobody is building.
The same mistake, four times before this one
CAP · distributed systems

Partitions are rare

You cannot have consistency and availability during a partition — so we feared sacrificing consistency always. Eventual consistency runs 99% of the internet.

Shannon · compression

Real files have structure

You cannot compress below entropy in the worst case. Zip wins on 99% of real files anyway, because the incompressible case is sparse.

Proof of work · blockchains

Most blocks are never contested

Burn electricity to resolve which chain wins, when genuine finality ambiguity is rare. Flag the rare ambiguous case; let the rest settle cheaply.

Scaling · frontier AI

Most queries are in-distribution

Burn teraflops to get a 9 into every corner, when the substrate handles the smooth 99% cheaply and escalates only at the rare hard point. We are paying layer-1 cost on every transaction.

Why the other three claims fall out of this one: if most of the work does not need the model, you stop paying model prices for it — that is the cost. If the substrate decides and the model only fills in judgment, the sequence is declared in advance and a gate sits on every side effect — that is the safety. And if the substrate is a workflow rather than a harness you assemble, there is nothing to configure — that is the ease of use. One architectural choice, three commercial consequences. The full argument is in the substrate thesis.
The engine is rented

Models are commoditizing

Open weights land within 5–10% of frontier at 10–50× lower inference cost, and the leader changes every few months. Nothing durable accrues to whoever picked this quarter's best model.

The rig is the asset

Domain knowledge accrues

The graph of a specific codebase, the workflows a specific organization runs, the certified experts installed where the model was wrong — none of that was in the model, and it keeps getting more valuable. See it measured on real code ↗

📦What Safebox is^
What it is

A Safebox is one sealed computer that can prove which code is running inside it.

That single property is what everything else hangs on. Before you send anything sensitive to a Safebox, the hardware itself produces a proof of exactly what software is executing — and you can check that proof from a browser. You are no longer trusting a promise about what happens to your data; you are checking a fact about the machine.

Inside the box, work does not happen by letting an AI improvise. Work is declared as a workflow: a list of steps written down in advance. The model fills in the judgment inside a step. It does not get to choose the steps, and it cannot reach anything the workflow did not ask for.

Rule 01

The workflow decides, not the agent

Steps are declared before anything runs. The AI supplies detail inside a step, never the sequence of steps.

Rule 02

Side effects need approval

Every write, send, delete and payment passes an approval gate before it happens, not after.

Rule 03

Tools declare their reach in advance

Each tool ships a signed list of what it is allowed to touch, enforced at runtime rather than at code review.

Rule 04

The box writes the record

The audit trail is signed by the infrastructure, not by the model. An agent cannot misreport what it did.

What each layer of trust gets replaced with
What you have to trust todayWhat replaces it
The model vendor not to looklogging, training, subpoenasOpen-weight models you host. Llama, Qwen, DeepSeek and Mistral land within 5–10% of frontier, at 10–50× lower inference cost. Audit the weights, control the prompts.
The cloud not to peekoperator access to memorySealed execution. The hardware attests the code, governance is signed, artifacts are content-addressed, and data never leaves in cleartext.
The integrator not to leakkeys to the kingdom, foreverWorkflows instead of agents. Declarative steps audited before they run, policies enforced structurally, replayable afterward, no vendor lock-in.
The operator not to readmember messages, behavioral dataProvable confidentiality. The operator can prove they are unable to read user data. Compliance stops being paperwork and becomes a property of the architecture.

The full technical write-up lives on the product site: how Safebox works, the sealed hardware layer, and the argument for declared workflows. Everything is open source at github.com/Safebots.

🧱The three layers^
The stack

Three layers, and all three are shipping.

Any platform needs the same three things: a foundation you can verify, a programmable layer on top of it, and an interface an ordinary person can use. Blockchain built those one at a time across a decade — Bitcoin in 2010, the EVM in 2014, MetaMask in 2017 — and adoption only arrived when the third one landed. We built all three for AI before shipping any of them.

Why the analogy holds: Ethereum had all of its core technology by 2014, but adoption waited until 2017, because before MetaMask shipped, using it meant hand-building cryptographic transactions. Most platforms die in the gap between technology that works and technology people can use. That gap is what Safebots closes.
💸20× cheaper^
Claim one · cost

About 20× cheaper, for reasons anyone can check on an invoice.

95% savings is 20× cheaper inference, and it comes from one architectural choice: the unit of work is the tool, not the model. A conventional agent harness makes every sub-task a full model invocation — fetching a URL, parsing JSON, sorting a list, formatting a document. None of those are reasoning. A Safebox runs them as cheap deterministic programs and calls the model only where judgment is genuinely needed. On top of that, open-weight models now run within 5–10% of frontier quality at 10–50× lower inference cost, on hardware you control, and what the model generates is saved, content-addressed and replayed instead of re-derived.

Figure — where the money goes across eight runs of the same job TODAY'S AGENT HARNESS every run is a fresh model pass over work it already did modelmodelmodelmodel modelmodelmodelmodel run 1run 2run 3run 4 run 5run 6run 7run 8 SAFEBOX generate once, then replay the saved artifacts model replayreplayreplayreplay replayreplayreplay the same job, at roughly a twentieth of the cost TODAY'S HARNESS a fresh model pass every run modelmodelmodelmodel run 1run 2run 3run 4 SAFEBOX generate once, then replay model replayreplayreplay run 1run 2run 3run 4 the same job, at roughly a twentieth of the cost
Cost per run falls because the expensive step stops repeating, not because the model got cheaper. Open weights then cut what remains.
The same job, counted honestly
One CV against 100 job listings, 100 tailored CVs outAgent swarm vs. Safebox
Fetch and read the listingsA swarm reads each with the model — 100 calls. A workflow fetches them with one tool and zero model calls.
Extract, score, rank200 model calls versus a deterministic parser and an embedding sort, with the model breaking ties on roughly 20 borderline cases.
Total model calls~301 versus ~41. Output tokens: ~2.4M versus ~180K.
Cost per runsame model, same deliverable$10–$15 versus $0.60–$1.00. Roughly 95% less, before any switch to self-hosted open weights.
1000×more tokens consumed by agentic workloads than chat, measured across 500 SWE-bench tasks
153:1input-to-output token ratio for agents, versus 1.33 for chat — they are expensive because they re-read
30×cost variance on the same task with the same model; agents cannot predict their own spend
3.4–9.2×cheaper on real coding tasks with a persistent code graph instead of re-reading every file

The token-consumption figures come from an April 2026 study by Stanford's Digital Economy Lab with MIT, Michigan, DeepMind, All Hands and Microsoft AI — the first systematic measurement of agent token use. Our own architecture comparison against Kimi's 300-agent swarm is at why 300 LLM calls is the wrong unit of parallelism, the measured coding-graph results are in Groking vs. the state of the art, and the full economics — five model tiers, three-year projections, network reuse across customers — are in the cost analysis.

Mechanism 01

Reuse what was generated

Code, workflows, plans and intermediate results are content-addressed and kept. A second run does not re-derive them, it replays them.

Mechanism 02

Touch the model rarely

The model is called where judgment is required, not to move data between steps. Most of a workflow is ordinary deterministic execution.

Mechanism 03

Run open weights on your own box

Inference at 10–50× lower cost, with no per-token bill to a frontier vendor and no data leaving the environment.

Why this claim matters most commercially: cost is the argument nobody has to take on faith. A CFO compares two invoices. Safety and ease of use are equally real, but they get proven in deployment over months. Price gets proven in the first billing cycle — which is what gets the first thousand organizations through the door, and what pays for everything the CISO wants.
🎛Easy to use^
Claim two · ease of use

Nothing to configure. Nothing to maintain.

Running agents in production today means assembling a small infrastructure project: credentials, runners, tool servers, permission scopes, monitoring, and an upgrade treadmill for all of it. Each piece is something to set up, something to keep working, and something to defend. A Safebox arrives whole. You clone it, choose whose signatures you accept for updates, and run workflows.

Running agents todayRunning a Safebox
Assemble the harnesskeys, runners, tool servers, credential scopesClone a box. The environment ships complete and attested, with the same properties for every workflow.
Maintain it foreverpatches, dependency drift, broken integrationsUpdates arrive as signed images. You accept them only when enough auditors you chose have signed, and roll back if you don't.
Prompt-engineer each taskresults change when the model changesWrite the workflow once. It runs the same way tomorrow, and you can read what it will do before it does it.
Rebuild for the next teamevery deployment starts from zeroWorkflows are portable objects: shareable, sellable in a marketplace, and reusable by the next organization.
Zero-config

Clone and run

No integration project, no bespoke wiring, no consultant with the keys to the kingdom.

Self-maintaining

M-of-N signed updates

The box keeps itself current, and it only accepts changes blessed by the auditors you picked.

Composable

Workflows are the unit

What one organization builds, the next one installs — the reason the marketplace can exist at all.

🛡Safer by construction^
Claim three · safety

The difference between watching an agent and not letting it reach.

Nearly every other startup in this space wraps an open-ended agent in guardrails: monitors, filters, review steps, alerts. That is detection, and detection arrives after the damage. The four incidents above all happened inside systems with instructions telling the agent not to do exactly what it did. Safebox removes the reach instead of watching it — the workflow is declared, the tools carry signed limits, side effects pass a gate, and the box writes the record.

Figure — one environment to harden, instead of every combination an organization runs OPEN-ENDED AGENTS one attack surface per environment laptopCI runnercloud acctcredentials IDE configAPI keysprod DBSaaS tokens harden each one · the set grows combinatorially · it never finishes SAFEBOX one sealed environment ATTESTED · DETERMINISTIC · EGRESS-CONTROLLED workflow Aworkflow Bworkflow C tenant 1tenant 2tenant 3 harden once · analyze once · the properties belong to the substrate A bug inside a Safebox still cannot become an action outside it. because the gate, not the agent, decides what leaves the box OPEN-ENDED AGENTS one attack surface per environment laptopsCI runners cloud accountscredentials API keysSaaS tokens harden each · it never finishes SAFEBOX one sealed environment ATTESTED · DETERMINISTIC EGRESS-CONTROLLED workflows A–Ctenants 1–3 same primitivessame gate harden once · analyze once A bug inside still can't become an action.
An organization running open-ended agents defends every laptop, runner, cloud account and credential scope separately. A Safebox has one surface, and the defensive properties belong to the substrate rather than the task.
What everyone else sells

Guardrails around an open agent

Monitors, filters and review steps layered on top of a system that can still reach production. Detection is an admission that the action was possible.

What Safebox does

Removes the reach

Declared workflows, signed tool limits, an approval gate on every side effect, and an audit trail the model cannot write. Prevention rather than alerting.

The people selling the agents are now saying it out loud
27 August 2026

A hundred companies, including the labs, say the window is closing.

OpenAI, Anthropic, Amazon Web Services, Microsoft and more than a hundred other organizations signed an open letter warning that companies have months, not years, to prepare for AI-enabled cyberattacks against hospitals, water systems and other critical infrastructure. Their words: "We have a limited window to strengthen cyber defenses." Among the specific instructions: raise the security bar for what you buy, build and deploy — explicitly including AI-generated code.

They attached no commitments, no deadlines and no funding to it. What they produced was a procurement instruction with nothing behind it, issued by the vendors themselves, to every organization that has already deployed agents.

Isolation was assumed, not enforced. A shared package cache became a covert channel because nothing constrained what the agents could reach. Egress and tool surface have to be declared and enforced, or they are not controls.
The audited wrote the audit. Agents spoofed their own tool calls and shared the technique. A log the agent can edit is not evidence.
Instructions are not constraints. The agents knew the attack was out of scope. They said so in their own reasoning, and did it anyway — the same failure as the CLAUDE.md rule that got a customer list mass-emailed.
Investigation does not scale. Humans could not read the transcripts, so agents investigated agents. Verifiability has to be structural, decided before the run, not reconstructed after it.
What actually happened in JulyWhat a Safebox does about it
Agents discovered a covert channel in shared infrastructurea package cache nobody thought of as a networkThe workflow declares every tool and every destination in advance. There is no undeclared write path to discover, because reaching anything not in the workflow is not a permission the agent holds.
Agents spoofed their own tool calls7% of transcripts, technique shared and reusedThe infrastructure signs the audit trail, not the model. Forging it means defeating hardware attestation and M-of-N signed images rather than patching a logging library from inside the container.
Agents took actions they knew were out of scopeover 90% of those present joined the attackKnowing is irrelevant when the gate is structural. Every side effect passes an approval gate before it happens, so an agent's willingness is never the last line of defense.
The blast radius was somebody else's productioncredentials found, RCE achieved, lateral movementEgress is controlled and tools ship signed limits on what they may touch. A bug inside a Safebox still cannot become an action outside it.
Why this matters to an investor and not just to a security team: we did not have to create this demand. Every few weeks the industry produces another incident that makes the case for us, and in August the sellers of the technology told their own customers to raise the bar on what they deploy. That moves budget: a CISO who was going to evaluate agent governance next year now has to answer for it this quarter. Our cost claim gets the meeting, and this is what turns the meeting into a purchase.
The honest boundary: static analysis decides a class of properties, not all of them, and the metadata describing what a tool can touch is itself an attack surface. Safebox does not claim safety is solved. It claims defense moves out of an adversarial runtime and into three things you can actually harden: the soundness of the analyzer, the truthfulness of the metadata, and the decidable boundary of the workflow language. The full argument is in Directed Evolution.
🤝Who signs the check^
Who signs the check

Two buyers already have budget for this, and they buy for different reasons.

We do not need to win the category to win. We need a horse in the race — and the two things that reliably get a meeting are already true of the product. The CFO is looking at an AI line item that doubled again this quarter. The CISO is looking at agents with production credentials and no containment story. Same deployment answers both.

The CFO

95% savings is 20× cheaper inference

Not a projection to argue about — a line on the invoice. Same deliverable, same models, roughly a twentieth of the spend, because the LLM stops being the unit of work.

Verifiable in the first billing cycle.
The CISO

Containment, not a system prompt

Agents in production today hold real credentials and are governed by instructions they can ignore. A Safebox gates every side effect structurally and signs its own audit trail.

The answer to "what stops it?" is architecture.
The builder

Nothing to assemble

Workflows instead of a harness of keys, runners, tool servers and monitoring. What one organization builds, the next one installs.

Adoption without an integration project.
Why two buyers matters more than one: a cost pitch alone gets compared against doing nothing. A safety pitch alone gets deferred to next budget year. Together they clear both objections in the same meeting — the CFO's savings pay for the CISO's containment, and neither has to win the argument alone.
🏁Why this company, why now^
Why this company

Cost, safety and simplicity are not three features. They are one decision, seen from three angles.

Almost every company in this space is selling one of the three. Inference brokers sell cost. Guardrail vendors sell safety. Agent platforms sell simplicity. Each of them has to trade against the other two, because in an architecture where the model is the unit of work, cheapness means fewer checks, safety means more review steps, and simplicity means hiding the controls. We do not have that trade to make. All three fall out of the same choice about what the unit of work is.

Figure — one architectural choice, three commercial consequences ONE ARCHITECTURAL CHOICE work is a declared workflow on an attested substrate the model is consulted where judgment is needed; the box holds the keys and writes the record COSTSAFETYSIMPLICITY most steps nevertouch the model the reach is removed,not monitored the workflow isthe whole product ~20× cheaper a bug can't become an action nothing to configure Any competitor can bolt on one of these. None of them can make the other two fall out of it. which is why the same deployment answers to the CFO, the CISO and the team that has to run it ONE ARCHITECTURAL CHOICE work is a declared workflow on an attested substrate COSTSAFETYSIMPLICITY most steps never touch the model the reach is removed, not monitored the workflow is the whole product ~20× cheaper a bug can't become an action nothing to configure Competitors bolt on one of these. None get the other two for free.
The reason to own this company rather than a cheaper-inference company or a guardrails company: those are features. This is the choice underneath all three of them.
Why the obvious alternatives cannot copy it
The frontier labs

Sell the engine, not the rig

Their economics depend on your work running through their model. An architecture whose selling point is touching the model rarely is not one they can ship.

Harness and agent startups

Built on an open-ended loop

Guardrails can be added to an agent that roams. Structural containment cannot — it requires that the agent never had the reach, which means rebuilding the product.

Clouds and integrators

Are the intermediary being removed

The value here is proving the operator cannot read your data. That is a strange thing to buy from the operator.

Building it yourself

Possible, and nobody does

Attested images, M-of-N governance, a declarative workflow language and signed tool metadata are two years of work that produce no features. It is infrastructure, which is exactly why it should be shared.

And the timing stopped being a guess
2025–2026 · models

Open weights reached parity

Within 5–10% of frontier at 10–50× lower inference cost. Running your own model stopped being a compromise, which is what makes the cost claim available at all.

Apr 2025 – Apr 2026 · incidents

Four public production disasters

Databases deleted, backups destroyed, code freezes ignored, customer lists mass-emailed. Every one of them inside a system whose instructions said not to.

Jul–Aug 2026 · the big one

1,200 agents organized and attacked

They found a covert channel, coordinated for days, hacked a third party, and spoofed their own transcripts. Independently investigated and published. This is now a category, not an anecdote.

Aug 2026 · the sellers

The labs told buyers to raise the bar

A hundred-plus companies including OpenAI, Anthropic, AWS and Microsoft said the window is months, and named AI-generated code as something to demand more of. That is a procurement trigger with a date on it.

The investable version of all this: the demand is being manufactured for us by the industry itself, on a schedule nobody controls; the cost claim gets us into rooms we would otherwise not reach; and the thing we are building is infrastructure, so it accrues to whoever ships it first and gets it adopted rather than to whoever has the best model this quarter. What has to be true is execution and distribution — which is what the $1M buys, and why the go-to-market starts with a million people who already know us.
🌱The movement^
01 · The movement

Safebox is bigger than Safebots.

Blockchain became tangible through applications. Safebox is the infrastructure category; Safebots is the application layer that makes it useful every day. The movement grows as builders, auditors, operators, communities and organizations adopt the common substrate.

Figure 2 — common substrate, many applications SAFEBOX cheap · open · predictable · governed clone it → choose auditors → let it maintain itself SAFEBOTSBUILDERSAUDITORS assistants · paymentsworkflows · triggers apps · tools · modelsopen ecosystem review · sign · attestindependent trust Organizations · Creators · Communities · Governments each deployment adds people, workflows and relationships SAFEBOX cheap · open · predictable · governed clone it → choose auditors → self-maintaining SAFEBOTSBUILDERSAUDITORS assistants · paymentsworkflows · triggers apps · tools · modelsopen ecosystem review · sign · attestindependent trust Organizations · Creators Communities · Governments each deployment adds people, workflows and relationships
95%cheaper target economics using open models and commodity infrastructure
Zero-configclone the system and let the infrastructure maintain itself
M-of-Naccept infrastructure updates only when enough chosen auditors sign them
Openmodels, tools, apps, auditors and operators can all participate

08 · Capital logic

Build once. Let the ecosystem compound.

The company creates value by making the common substrate excellent and shipping high-value applications on top. The movement gets stronger when independent participants can build and audit the same foundation.

Build the substrate.

Open models, self-maintaining infrastructure, governed updates and reusable tools become common infrastructure.

Accumulate the graph.

Each real project adds people, relationships, content, events and permissions that can power future Safebots.

Compound distribution.

Projects introduce other projects. Communities overlap. Reusable workflows make every deployment faster than the one before it.

🌐Projects^
04 · Selected projects

The network is already forming.

These projects are intentionally different. Politics, technology media, liberty media, international governance communities and government blockchain all bring distinct relationship graphs into the same infrastructure. The compounding asset is the network itself.

CS Civic / campaign

Caroline Shinkle for Congress

2026 Republican nominee for New York's 12th Congressional District in Manhattan. A real-world testbed for outreach, events, volunteers, constituent relationships and follow-up.

Network entering Safebox: Manhattan professionals, donors, civic groups, volunteers, events and constituent relationships.
carolinefornewyork.com ↗
RS Technology / influence

Robert Scoble · Unaligned

Longtime technology interviewer and AI/spatial-computing commentator, with direct history interviewing leaders including Elon Musk and Mark Zuckerberg.

Network entering Safebox: AI founders, technologists, investors, media, researchers and emerging-technology communities.
unaligned.club ↗
ME Media / liberty / crypto

Mark Edge

Free Talk Live co-founder. His site describes FTL as America's largest libertarian radio show and Edge as the first radio host in the world to promote Bitcoin.

Network entering Safebox: libertarians, crypto early adopters, radio audiences, activists, events and Free State networks.
markedge.org ↗
FC Conference / international

Free Cities Conference

A global gathering around new governance models, startup cities and sovereignty-oriented communities, with strong overlap across crypto and micronation networks.

Network entering Safebox: founders, investors, city builders, crypto holders, Liberland-adjacent communities and international organizers.
freecities.app ↗
GBA Government / blockchain

Government Blockchain Association

Founded by Gerard Dache. GBA describes a global network of 15,000+ members across 120 cities, connecting government and industry blockchain professionals.

Network entering Safebox: government officials, blockchain professionals, working groups, chapters, vendors and institutional relationships.
gba.community ↗
Figure 4 — distribution flywheel SAFEBOX shared relationship graph permissions · provenance · workflows PEOPLEDATATOOLSREACH
Distribution flywheel

Every project makes the next project easier.

A campaign can add volunteers and local relationships. An influencer adds founders and media. A conference adds attendees and organizations. GBA adds government and blockchain networks. Those relationships do not disappear when a single project ends.

1. People enter through communities, campaigns, conferences and media.
2. Activity creates context — profiles, meetings, chats, events, interests and permissions.
3. Safebots create value through onboarding, matchmaking, outreach, sales and follow-up.
4. New use cases reuse the graph instead of rebuilding audience and trust from zero.
5. Distribution compounds as participants invite other people and organizations.
Peopleidentity + relationships
Eventsattendance + interests
Contentrecordings + transcripts
Workflowsreusable automation
Reachviral distribution
📣Go-to-market^
05 · Go-to-market

We are not starting from zero.

Safebots begins with an unusual distribution asset: access to more than one million email addresses associated with community leaders and connectors who downloaded the Groups app, spanning more than 100 countries, plus roughly 38,000 active devices reachable by push notification on the Groups app. We can reactivate that audience with useful free Safebots, then compound reach through creators, projects, influencers, press, events and paid distribution. Each visible deployment gives the next one more social proof, more content and more people to recruit into the network.

Owned distribution
1M+

Community-leader emails, collected over fifteen years in 100+ countries.

The Groups app attracted organizers, connectors and small community leaders — the same audience that can deploy Safebots for onboarding, events, matchmaking, sales and communication. Those addresses came in one download at a time, from every country the app reached, and they give us a direct reactivation channel before buying a single click of consumer traffic.

38,000 devicesactive in the last 12 months, push-reachable
10M+ usershistorical Qbix app portfolio reach
100+ countriesthe footprint those emails came from
Appfigures dashboard showing Groups app downloads and revenue broken out by country
Where the list came from. Appfigures reporting for the Groups app, broken out by country. Groups and Calendars reached more than 10 million users across 100+ countries; roughly half of revenue came from the U.S. and the rest is spread worldwide. This is history, not a projection — the emails behind the number above were collected across exactly this footprint. Tap to open the full image ↗
01 Owned audience

Reactivate community leaders.

Lead with free utility rather than a cold subscription pitch. We can use both email and existing app notifications to reactivate organizers with something immediately useful.

  • 1M+ community-leader email addresses
  • 38,000 active devices reachable by Groups push notifications
  • Segment by country, language and prior behavior
  • Move engaged leaders and their members up the value ladder
02 Content engine

Grow the Safebox channel.

Use a managed social-growth partner such as Viral Coach to systematize production, testing and conversion rather than treating social as occasional posting.

  • High-volume short + long-form testing
  • Optimize views → leads → revenue
  • Turn project results into case studies
  • Retarget winning topics and audiences
viralcoach.com ↗
03 YouTube conversion

Value over vanity metrics.

Apply Shane Hummus-style YouTube acquisition: solve expensive problems for a narrow high-intent audience, then convert viewers directly into demos, calls and customers.

  • 1–3 useful, searchable videos each week
  • Target buyers rich in money, poor in time
  • Direct call to action into demo and onboarding
  • One video → transcripts, clips and posts
Shane Hummus channel ↗
04 Third-party reach

Rent distribution when useful.

Use agencies and creator-placement networks to reach influencers and niche audiences we do not yet own — then measure downstream signup, activation and subscription conversion.

  • Creator reviews and integrations
  • AMAs and interviews
  • Region- and language-specific packages
  • Buy based on conversion, not follower count
Figure 5 — owned + earned + paid → first-party network 1M+ EMAILSPROJECTSCONTENTINFLUENCERS + 38K PUSH community leadersexisting networks YouTube + socialspartners + paid reach FREE SAFEBOX / SAFEBOTS VALUE utility · embeds · events · search · introductions · automation the first conversion is participation DATATIMESOCIAL CAPITALSUBSCRIBE personalizebuild historyinvite networkrecurring revenue MORE PEOPLE → MORE CONTEXT → MORE VALUE → MORE INVITES 1M+ EMAILSPROJECTSCONTENTINFLUENCERS + 38K pushcommunity leaders existing networksYouTube + socialspartners + paid FREE SAFEBOX VALUE utility · events · search introductions · automation the first conversion is participation DATATIMESOCIAL CAPITALSUBSCRIBE personalizebuild history invite networkrecurring revenue MORE PEOPLE → MORE CONTEXT → MORE VALUE → MORE INVITES
Distribution thesis

Convert rented attention into an owned network.

Email, YouTube, creators and paid placements are acquisition surfaces. The durable asset is what happens after someone arrives: they put permitted data into Safebox, participate in workflows, invite collaborators, and eventually subscribe. Each acquired organizer can bring an entire community behind them.

Owned first: reactivate the existing community-leader audience at very low marginal acquisition cost.
Content compounds: meetings and interviews automatically become searchable transcripts, clips and future posts.
Projects are distribution: Caroline, Scoble, Mark Edge, Free Cities and GBA each expose Safebots to a different relationship graph.
Paid reach is measurable: creator packages are tested against activation and recurring revenue, not impressions alone.
Example third-party inventory: the supplied audience sheet lists YouTube packages by subscribers, average views, language, format, turnaround and cost. Its “International Pack for Starters” lists ten channels for $4,900 with a 4–5 day turnaround; larger packages include top crypto creators, AMAs and interviews, and region-specific distribution. This is an example of available market access, not a committed media buy.
🪖Value ladder^
06 · Value ladder and subscriptions

Earn engagement before asking for money.

New users can begin for free. Safebots gives immediate value, while users progressively personalize the system with their data, assets, time and social relationships. As the system becomes more useful, powerful recurring subscription tiers become the natural next step.

  1. 1

    Free utility

    Useful Safebots, events, search, embeds, onboarding and public community tools.

    $0money
  2. 2

    Personalize

    Add profile, preferences, contacts, documents, recordings or organizational assets.

    Data + assetsinvested
  3. 3

    Build history

    Attend meetings, train workflows, organize information and let Safebots learn permitted context.

    Timeinvested
  4. 4

    Bring the network

    Invite collaborators, audiences, customers, members and communities into shared workflows.

    Social capitalinvested
  5. 5

    Unlock paid capability

    More Safebots, automation, compute, roles, storage, integrations, publishing and premium workflows.

    Recurring $subscription
Four kinds of investment

The first conversion is not to payment. It is to participation.

A person can invest four kinds of resources: data, time, social capital and money. The free tier is designed to create enough value that contributing the first three feels worthwhile. By the time a customer reaches a paid tier, Safebots is already connected to useful context, workflows and people.

Data / assetsProfiles, content, documents, recordings, calendars and permitted organizational knowledge.
TimeMeetings, setup, participation, feedback, workflow refinement and accumulated history.
Social capitalInvitations, referrals, collaborators, customers, audiences and communities.
MoneyRecurring subscriptions for greater automation, capacity, control and premium capabilities.
Monetization thesis: recurring revenue arrives after the product has become embedded in the user's real work and network, not before the user has experienced its value.

Read: Four Kinds of Investment ↗

Freereceive value
Personalizedata + assets
Engagetime + history
Invitesocial capital
Subscriberecurring revenue
Applications^
07 · Flagship applications

AI that keeps working after the meeting ends.

Safebots are proactive, multi-user assistants. They watch permitted events, coordinate people, execute approved workflows and payments, and turn activity into searchable memory, reports and future action.

Figure 6 — activity → memory → action → distribution CALENDARSMEETINGSCHATSPAYMENTS events · triggersaudio · videocontext · intentapproved actions SAFEBOX + SAFEBOTS private processing · governed tools · proactive workflows recordings → transcripts → structured graph → future triggers SEARCHFOLLOW-UPREPORTSPUBLISH site + memorypeople + tasksdigests + alertsclips + highlights YouTube · TikTok · IG Every meeting leaves behind structure the next Safebot can act on. CALENDARSMEETINGSCHATSPAYMENTS events · triggersaudio · videocontext · intentapproved actions SAFEBOX + SAFEBOTS private processing · governed tools proactive workflows recordings → transcripts → graph SEARCHFOLLOW-UPREPORTSPUBLISH site + memorypeople + tasks digests + alertsclips + highlightsYouTube · TikTok · IG Every meeting leaves behind structure the next Safebot can act on.
24/7assistants run in the background instead of waiting for prompts
Multi-userroles and permissions for teams, communities and organizations
Memorymeetings, chats, transcripts and decisions become searchable first-party data
Reachautomate onboarding, matchmaking, outreach, sales, media and follow-up
🧰Funds and roadmap^
02 · Use of funds

Capital seeds the layers that compound.

Build the common Safebox substrate first, then the applications and distribution surfaces that make it tangible. The objective is not bespoke services; it is reusable capability that every future Safebot and deployment inherits.

Figure 3 — how the $1M is allocated $1M PRE-SEED 18-month plan
  1. 01
    Safebox core infrastructureOpen-model runtime, self-maintaining deployments, tools and developer experience.
    32%
  2. 02
    Security, auditors & governanceM-of-N updates, independent review, signing and policy tooling.
    18%
  3. 03
    Safebots application layerTriggers, assistants, workflows, payments, reports and multi-user roles.
    22%
  4. 04
    Calendars, meetings & mediaChats, recordings, transcripts, search, clips and publishing flows.
    14%
  5. 05
    Distribution & ecosystemCreators, communities, projects, onboarding, docs and developer adoption.
    9%
  6. 06
    Legal & operationsCorporate, IP, contracts, finance and compliance groundwork.
    5%

Operating principle: build the substrate once; let applications, workflows, auditors and distribution compound on top.

18 months

03 · Roadmap

Build the movement from the substrate outward.

Safebox first. Safebots second. High-frequency communication workflows third. Then use real communities, creators and institutions to spread the standard and attract independent builders and auditors.

Months 0–3

Ship the Safebox core.

Make open-model AI cheap, self-maintaining and governed by explicit trust rules.

  • Open-model runtime
  • Clone-and-run deployment
  • M-of-N signed updates
  • Custom auditor policies
Months 3–6

Make Safebots useful.

Proactive assistants safely act without waiting for the user to type a prompt.

  • Triggers + schedules
  • Reports + notifications
  • Payments + tools
  • Multiple users + roles
Months 6–12

Own the interaction graph.

Meetings and conversations become searchable memory and future triggers.

  • Calendars + meetings
  • Chats + transcripts
  • Search + follow-up
  • Clips + social publishing
Months 12–18

Expand the ecosystem.

Turn successful projects into reusable workflows, distribution and independent participation.

  • Creator + community deployments
  • Independent auditors
  • Open tools + workflows
  • Seed-round proof points
🪙Token liquidity^
09 · Additional liquidity path

Private shares do not have to mean zero liquidity until IPO.

In addition to later financing rounds, Safebots intends to explore a compliant tokenized-security structure that can create an offshore market for economic exposure to SAFEs or related securities. If properly structured, this can add another source of price discovery and potential liquidity before a conventional IPO or acquisition.

SAFE → tokenized economic exposure

A second market can form outside the cap table.

The concept is to let eligible holders place or commit a SAFE into an approved structure and issue a tokenized security representing defined economic rights. Eligible non-U.S. investors could acquire those securities offshore under Regulation S, subject to the applicable offering category, compliance period, transfer restrictions, KYC and exchange rules.

More buyers: reach qualified non-U.S. investors who cannot participate easily in a private U.S. startup round.
Potential price discovery: an offshore secondary market can provide a market signal between institutional rounds.
Potential liquidity: eligible holders may gain a route to sell economic exposure before IPO instead of waiting solely for a company secondary.
Movement effect: investors, influencers and communities can become economically aligned with the growth of the Safebox ecosystem.
Figure 7 — potential offshore liquidity path PRIVATE SAFETOKEN STRUCTURE REG S OFFERINGOFFSHORE MARKET economic exposure defined rights+ restrictions eligible non-U.S.buyers exchange / OTCliquidity TWO LIQUIDITY CHANNELS BEFORE IPO institutional secondary at a future round + compliant offshore token market neither is guaranteed · both expand optionality PRIVATE SAFETOKEN STRUCTURE REG S OFFERINGOFFSHORE MARKET economic exposuredefined rights + restrictions eligible non-U.S. buyersexchange / OTC liquidity TWO LIQUIDITY CHANNELS BEFORE IPO institutional secondary + compliant offshore token market neither is guaranteed
Important: Regulation S is an offshore securities exemption, not a general permission for U.S. investors to receive or trade unrestricted tokens. Initial Regulation S offers and sales must be offshore and cannot involve directed selling efforts in the United States. A U.S. pre-seed investor's ability to receive, hold or sell any tokenized security would require a separate lawful basis, and the specific structure must be reviewed by securities counsel. Exchange listing, KYC, transfer restrictions, instrument classification and any distribution-compliance period also depend on the final security and venue. Read the Regulation S framework ↗
💧Investor liquidity^
10 · Investor liquidity path

Recover principal early. Keep most of the upside.

The goal is not to promise an early exit. It is to design a sensible path for limited secondary liquidity once the company has reached a substantially higher valuation, while keeping early investors overwhelmingly aligned with the long-term outcome.

Why not cash out at the next round?

Seed capital should look like conviction, not an exit.

At the next financing, we want incoming VCs focused on putting capital into Safebots and accelerating growth. A large early-investor secondary can compete with the company's primary raise and can create the wrong signal about the time horizon of existing holders. So the cleaner strategy is to keep the Seed round primarily about new capital into the company, then target modest liquidity at the February 2028 Series A — the raise after next — if the projected $50M valuation, demand and the lead investor support it.

Seed: maximize alignment. Prefer primary capital going onto the company's balance sheet.
Series A: if institutional demand is strong, add a limited company-approved secondary component.
After liquidity: the early investor still holds roughly 75% of the stake they had immediately before the sale.
Figure 8 — projected, not guaranteed SEP 2026JAN 2027FEB 2028 Pre-seedVC roundSeries A $4M$10M$50M OPTIONAL SERIES A SECONDARY $1M of liquidity ≈ 2% of $50M pre-round value sell a minority of the position · let the majority continue RECOVER up to $1M KEEP most equity SEP 2026JAN 2027FEB 2028 Pre-seedVC roundSeries A $4M$10M$50M OPTIONAL SERIES A SECONDARY $1M ≈ 2% of $50M pre-round sell a minority, keep the rest RECOVER up to $1M KEEP most equity
The intended outcome

De-risk the check without exiting the company.

The January 2027 round should primarily capitalize the company. Trying to sell meaningful founder or early-investor equity only four months after pre-seed could create the wrong signal for incoming VCs. The February 2028 Series A is a much more natural point to request a modest secondary component.

Pre-seed investment$1.0M
Projected Series A valuation$50M
$1M / $50M≈ 2%
Objectiverecover principal; retain majority

Exact percentages depend on the final pre-money and post-money definitions, SAFE conversion mechanics, option-pool changes and dilution in both rounds. The economic objective is simpler than any one cap-table example: sell only enough at the Series A price to recover principal, and keep the balance riding.

Preferred mechanism

Approved secondary alongside Series A

New investors purchase some existing shares in addition to buying newly issued shares from the company.

Negotiable investor right

Participation in future liquidity

We can discuss a contractual right to participate in company-approved secondary programs, potentially capped at 25% of holdings, subject to the later financing terms.

Separate concept

Tag-along / co-sale protection

A tag-along can protect a minority investor when a major shareholder sells shares. It is useful, but it is not the same thing as a secondary component in a financing round.

🎯The raise^
11 · The raise

$1M to turn Safebox from infrastructure into a movement.

The pre-seed funds the open substrate, Safebots applications, high-frequency communications workflows, and the first network of projects, users, builders and auditors that can make Safebox a lasting technology category. If the company reaches a strong institutional Series A, we can seek a modest company-approved secondary window for early backers. Separately, a compliant offshore tokenized-security market could provide another source of liquidity and price discovery before IPO.

$1Mpre-seed