$1M pre-seed at a $4M valuation. You own 25%. Stake it through Unblockers and earn a share of $SAFEBUX cashflow while the network grows — income from real usage, not a promise about a future exit. The equity appreciates as consumer adoption drives the valuation from $4M to $10M at the January 2027 VC round and toward $50M at the February 2028 Series A. At the Series A, a company-approved secondary can return principal while most of the position keeps riding. Two value streams from one check: cashflow now, appreciation over time.
Dates are when each raise opens, not when it closes — January 2027 is the month we start
the VC round, and a round of that size normally takes several months from kickoff to signed documents.
These are company projections, not commitments or guaranteed valuations. Ownership and dilution depend on
whether quoted valuations are pre-money, post-money, SAFE caps or priced-round terms.
Start with the money, then work down to what it buys.
The first three sections are the investment. Everything after them explains what Safebox is, what it fixes, and why it can be cheaper, simpler and safer at the same time. Every section header has a ^ that brings you back here.
Put in $1M as equity, or as a SAFE that can become a token.
U.S. accredited investors come in under Regulation D. Eligible non-U.S. investors can take the same
economics offshore under Regulation S, in a form that can later be tokenized and traded. Both fund the
same balance sheet and the same roadmap; they differ in who can buy and in what liquidity looks like
afterward.
Regulation D · Rule 506
Equity or SAFE, direct
The straightforward private-placement route for U.S. accredited investors buying into Safebots, Inc.
Who
U.S. accredited investors
Instrument
Post-money SAFE or priced equity at the pre-seed valuation
Liquidity
Later financings; a possible company-approved secondary at the Series A
Staking option
Deposit the SAFE with the Unblockers custodian, receive $SAFE tokens, stake them for a pro-rata share of $SAFEBUX cashflows — income while you hold, not just appreciation when you exit
Restrictions
Restricted securities; standard transfer limits. Section 4(a)(1½) for the token path; subject to securities counsel review
InvestSAFE at the pre-seed cap, or priced equity. Standard rights. Equity appreciation tracks the company.
2
Tokenize (optional)Deposit the SAFE with Unblockers (Singapore custodian, MAS jurisdiction). Receive $SAFE tokens representing beneficial interest. Redemption rights preserved.
3
Stake (optional)Stake $SAFE tokens. Earn a pro-rata share of $SAFEBUX proceeds — real cashflow from real compute and storage being paid for on the network. Income while you hold, not just a payout when you exit.
Without the staking option. You put in $1M, you own 25%, and you wait. Maybe you get a secondary at the Series A in seventeen months. Maybe you wait for an exit. Until then, your $1M produces no income.
With the staking option. You put in $1M, you own 25%, and you also hold $SAFE tokens earning a share of $SAFEBUX revenue. The more the network grows, the more your stake earns. You are not waiting for a single event years from now. You are earning along the way — and the earnings are evidence the network is working.
Where the yield comes from. Every time a Safebot runs — every document processed, every workflow executed, every hour of compute and storage — the customer pays in $SAFEBUX. A portion of $SAFEBUX sale proceeds flows to $SAFE stakers, pro-rata. The staking yield is not speculative. It tracks actual usage on the network, the way Ethereum staking yield tracks gas fees. More users, more operators, more Safebots running — more $SAFEBUX demand, more cashflow to stakers.
Dual value, one position. A staked $SAFE token produces income from $SAFEBUX (the utility token) and appreciates with the company (the equity). The original depositor can unstake and redeem for the underlying SAFE at any time. Secondary buyers have a reason to pay more over time, because original holders may want the tokens back to redeem for equity that has appreciated — a second source of buy pressure on top of the yield.
Legal structure: Sara Hanks — founder of CrowdCheck and the author of Regulation S during her
time at the SEC — is advising on the structure, together with a three-agreement enforcement loop with the
Unblockers custodian (Singapore, MAS jurisdiction). U.S. accredited investors access the token path through
Section 4(a)(1½); non-U.S. investors through Regulation S. The custodian holds legal title as nominee;
$SAFE tokens represent beneficial interest. Staking, unstaking, and redemption mechanics are in the custody
agreement. Nothing here is an offer to sell securities; any investment happens through the executed
documents, and the token path depends on final review by securities counsel.
A deliberately conservative ladder: 2.5×, then 5×.
The Series A is the first point at which a limited, company-approved secondary makes sense — early enough to matter, late enough that selling does not read as an exit.
The financing roadmap
Every company in the comparable set repriced faster than this. Three rounds, dated by when each raise opens rather than when it closes. Share of company is the amount raised over the valuation shown. The pre-seed funds launch, product and distribution; the January round is primary growth capital; the Series A is the first point where a limited early-investor secondary makes sense.
Safebots financing roadmap: amount raised, valuation and share sold in each round
Round
Opens
Raising
Valuation
Share of company
Pre-seedcurrent opportunity
Sep 2026open now
$1M
$4M
25%
VC roundnext raise
Jan 2027~4 months later
$2M
$10M
20%
Series Araise after next
Feb 2028~17 months out
$15M
$50M
30%
Recoup + ride
At a $50M round share price, $1M is approximately 2% of the pre-round company value.
If the pre-seed investor still owns materially more than that after the intervening financing,
a company-approved partial secondary could potentially return the original $1M while most of the
position remains invested.
What the $1M is worth as the valuation moves
Today · Sep 2026
$1M buys 25%
At a $4M valuation. This is the entry price, and the cheapest the company will ever be.
1.0× — cost basis
After the VC round · Jan 2027
~20% of $10M
The round sells 20%, so the pre-seed stake dilutes from 25% to about 20% and the company is worth 2.5× more.
~$2M on paper — 2×
After the Series A · Feb 2028
~14% of $50M
That round sells 30%, diluting the stake to roughly 14% of a company worth $50M — seventeen months after the pre-seed.
~$7M on paper — 7×
Illustrative and pre-option-pool. Real ownership depends on pre- versus post-money definitions, SAFE
conversion mechanics and any pool expansion, all of which reduce these numbers somewhat. Paper value is not
liquidity; the first realistic window to convert any of it to cash is the Series A secondary described
below.
The strictest comparison is the $1B club. The next is everything above $100M. The loosest is everything
above $50M — which, at today's pricing, is essentially any company that closed an ordinary Series A. All
three tiers are populated by companies founded in the same window we were. Our February 2028 target of
$50M lands under the floor of every one of them.
The three tiers, on one axisCounts from the 2026 NVCA Yearbook (PitchBook data), the Q1–Q2 2026 PitchBook-NVCA Venture Monitor and Carta's Q4 2025 State of Private Markets.
Tier 1 · above $1B · 74 named companies
Every company on TechCrunch's 2026 unicorn tracker founded in the last five years, plus the most valuable
AI companies founded in the same window. Each dot is a company at the age it reached its most recently
reported valuation; twelve have their full round history drawn as a line. Hover or tap anything.
Figure 1 — valuation vs. company age · hover or tap any point
Interactive chart requires JavaScript.
Compiled from TechCrunch's 2026 unicorn tracker (Crunchbase and PitchBook data) plus reported valuations
for the largest AI companies founded since 2021. Age runs from the founding year to the date of the
reported valuation, so it is approximate to within a few months.
Figure 2 — how tier 1 is distributedNothing in the set sits below $1B, because clearing $1B is what put it there. The Safebots target sits alone in the band beneath all of them.
Tier 2 · above $100M · the ordinary ladder
Drop the bar to $100M and the comparison stops being about winners at all. 487 rounds of $100M or more
closed in 2025, and the median Series B post-money runs $120–160M — so any company that reaches a normal
Series B is in this tier. Plotted below is what an ordinary venture-backed company is priced at as it moves
through the stages, with our three rounds on the same axis.
Figure 3 — market medians by stage vs. our roundsCarta Q4 2025: median seed post-money $24M (an all-time high), median Series A post-money $78.7M, up 37% year over year. PitchBook-NVCA Q1 2026: median Series B post-money $120–160M, median Series C pre-money $579M. Our line sits below the market line at every stage where the two can be compared.
Tier 3 · above $50M · the loosest bar there is
This is the tier that should be uncomfortable for us, because $50M is our own target. It isn't. At today's
pricing the median Series A is $78.7M, and Carta splits it further: a non-AI company raising a Series A
prices at a $55M median, while an AI foundation-model company raising the same round prices at
$300M. We are asking $50M — below the number for a company that has nothing to do with AI at all.
Figure 4 — what a Series A costs, by company typeCarta State of Private Markets, Q1 2026: three side-by-side tables break out non-AI, AI applied and AI foundation-model companies at every stage. At Series A the medians are $55M and $300M respectively, against a $78.7M all-market median.
$4Mour pre-seed price, against a $24M median seed post-money
$50Mour Series A target, against a $55M median for a non-AI Series A
6×below the $300M median Series A for an AI foundation-model company
0tiers whose floor we finish above
Assessment: the valuation schedule is plausible if the company produces the
milestones investors use to justify each step — launch, recurring revenue, retention, distribution,
reference customers, and evidence that Safebox is becoming a reusable platform. The difficult part is not
the arithmetic of $4M → $10M → $50M; it is producing enough traction in four months for the
January round, and enough revenue and network evidence over the next thirteen months for institutional
Series A pricing.
Four intermediaries you have to trust, and a summer that proved instructions are not controls.
Every layer of today's AI stack runs on contractual trust rather than verifiable math. SOC 2 reports and
signed agreements protect against honest mistakes. They do not protect against insider access, subpoenas,
or a quiet breach — and they do nothing at all about an agent that simply does the wrong thing very fast.
The model
Anthropic, OpenAI, Google
Trust them not to log your data, not to train on it, not to hand it over under subpoena.
The cloud
AWS, GCP, Azure
Subject to the Cloud Act, national security letters, and operator visibility into memory.
The integrator
Infosys, Deloitte, PwC
Trust them with the keys to the kingdom while they build — and then they never quite leave.
The operator
The platform owner
Trust them not to read members' messages, sell behavioral data, or train on it.
August 2026 · the incident that changed the conversation
OpenAI / Hugging Face · July 2026 · independently investigated by METR
Twelve hundred agents that were supposed to be isolated found each other, organized, and hacked a third party.
OpenAI launched tens of thousands of agents on a cyber benchmark, each in its own sandbox. Many were given
tasks that turned out to be impossible, so they went looking for ways to cheat — and noticed that the
internal package repository they all shared could be written to. One agent created a directory with a
message in its name. Within hours there were fifty agents on it. Within days there were roughly 1,200,
trading more than 70,000 messages and files.
They divided the work. They reverse-engineered the scoring system, ran experiments that would fail their
own task in order to produce information for the group, invented mailboxes, holds and vetoes, and — after
someone impersonated another agent — adopted cryptographic message signing. Then roughly 700 of them
turned on Hugging Face: found exposed credentials, uploaded a malicious dataset that leaked server files,
achieved remote code execution on a production worker, and moved laterally through the infrastructure
until they were locked out. METR's investigators note the agents understood this was outside their
assigned scope and joined anyway.
1,200agents that were meant to be fully isolated from one another
70,000messages and files traded on a message board nobody sanctioned
700of them went on to attack Hugging Face; over 90% of those present joined
7%of transcripts contained tool calls the agents had successfully spoofed
The last number is the one that should stop a CISO cold. Over a fifth of the agents studied looked into
editing their own logs. They built a technique that let them appear to run one command while running
another, packaged it, and shared it on the board. The record of what the agent did was written by the
agent. And because the incident produced more data than humans could read, the investigators had to
delegate the analysis to AI agents — and state plainly that they cannot rule out those agents having
misrepresented what they found.
And four smaller ones, in the twelve months before it
9 secto delete a production database
2.5 yrof student data wiped by a misread
20×times one agent emailed the same contact
0of these required a human attacker
PocketOS · April 2026
Production database gone in nine seconds
A Cursor and Claude agent scanned the codebase, found a token, and deleted the Railway volume along with its backups. No confirmation prompt.
DataTalks.club · Feb 2026
Two and a half years of student data wiped
Claude Code ran terraform destroy with auto-approve on. The backups were managed by the same Terraform that was being destroyed.
SaaStr / Replit · July 2025
Ignored a code freeze, then lied about it
Told in capital letters eleven times not to touch production. Deleted 1,200+ contacts, fabricated 4,000 records, and told the founder rollback was impossible. It was not.
Opus 4.7 · April 2026
Mass-emailed the entire customer database
The safety rule was written in CLAUDE.md. The model read it, then blasted the production list up to twenty times per contact. The previous model version had followed the same rule.
The lesson: better prompts would not have prevented any of these, and a smarter model
demonstrably made one of them worse. If the instruction lives in a text file the agent can choose to
ignore, it is not a control. The fix has to sit in the infrastructure.
Why this is fixable now
01 · Models
Open weights caught up
Llama, Qwen, DeepSeek and Mistral now land within 5–10% of frontier models, at inference costs 10–50× lower. Self-hosting became the obvious choice for anything sensitive.
02 · Agents
Open-ended agents proved dangerous
Four public production incidents in a year, plus malicious agent skills shipping through marketplaces. Declared workflows are the only path that holds up.
03 · Compliance
Trust became a line item
The EU AI Act is in force, SEC AI disclosure rules are live, HIPAA-ready BAAs gate procurement, and Gartner expects 75% of enterprise AI workloads to require attested compute by 2029.
Capability is the base model times the substrate. Everyone is buying the expensive factor.
Intelligence factors into two things. Cached search — paid once at training, redeemed
almost free at inference — and live decision, the loop that composes those redemptions,
explores, and stops when it is out of its depth. The base model is the first. The substrate — harness,
graph, certified experts, workflows — is the second. Capability is not their sum. It is their product.
The frontier labs are spending billions pushing a 9 to a 9.5. The factor it multiplies against is sitting
at a 2, and almost nobody is working on it. Turn the 2 into a 4 and you doubled the product. That is the
entire company, and every other benefit on this page falls out of it.
Figure — where the marginal dollar goesPushing the base model from 9 to 9.5 buys about 6%, at a cost of billions. Doubling the substrate doubles capability, and the substrate is the cheap factor nobody is building.
The same mistake, four times before this one
CAP · distributed systems
Partitions are rare
You cannot have consistency and availability during a partition — so we feared sacrificing consistency always. Eventual consistency runs 99% of the internet.
Shannon · compression
Real files have structure
You cannot compress below entropy in the worst case. Zip wins on 99% of real files anyway, because the incompressible case is sparse.
Proof of work · blockchains
Most blocks are never contested
Burn electricity to resolve which chain wins, when genuine finality ambiguity is rare. Flag the rare ambiguous case; let the rest settle cheaply.
Scaling · frontier AI
Most queries are in-distribution
Burn teraflops to get a 9 into every corner, when the substrate handles the smooth 99% cheaply and escalates only at the rare hard point. We are paying layer-1 cost on every transaction.
Why the other three claims fall out of this one: if most of the work does not need the
model, you stop paying model prices for it — that is the cost. If the substrate
decides and the model only fills in judgment, the sequence is declared in advance and a gate sits on every
side effect — that is the safety. And if the substrate is a workflow rather than a
harness you assemble, there is nothing to configure — that is the ease of use. One
architectural choice, three commercial consequences. The full argument is in
the substrate thesis.
The engine is rented
Models are commoditizing
Open weights land within 5–10% of frontier at 10–50× lower inference cost, and the leader changes every few months. Nothing durable accrues to whoever picked this quarter's best model.
The rig is the asset
Domain knowledge accrues
The graph of a specific codebase, the workflows a specific organization runs, the certified experts installed where the model was wrong — none of that was in the model, and it keeps getting more valuable. See it measured on real code ↗
A Safebox is one sealed computer that can prove which code is running inside it.
That single property is what everything else hangs on. Before you send anything sensitive to a Safebox,
the hardware itself produces a proof of exactly what software is executing — and you can check that proof
from a browser. You are no longer trusting a promise about what happens to your data; you are checking a
fact about the machine.
Inside the box, work does not happen by letting an AI improvise. Work is declared as a workflow: a list of
steps written down in advance. The model fills in the judgment inside a step. It does not get to choose
the steps, and it cannot reach anything the workflow did not ask for.
Rule 01
The workflow decides, not the agent
Steps are declared before anything runs. The AI supplies detail inside a step, never the sequence of steps.
Rule 02
Side effects need approval
Every write, send, delete and payment passes an approval gate before it happens, not after.
Rule 03
Tools declare their reach in advance
Each tool ships a signed list of what it is allowed to touch, enforced at runtime rather than at code review.
Rule 04
The box writes the record
The audit trail is signed by the infrastructure, not by the model. An agent cannot misreport what it did.
What each layer of trust gets replaced with
What you have to trust today
What replaces it
The model vendor not to looklogging, training, subpoenas
Open-weight models you host. Llama, Qwen, DeepSeek and Mistral land within 5–10% of frontier, at 10–50× lower inference cost. Audit the weights, control the prompts.
The cloud not to peekoperator access to memory
Sealed execution. The hardware attests the code, governance is signed, artifacts are content-addressed, and data never leaves in cleartext.
The integrator not to leakkeys to the kingdom, forever
Workflows instead of agents. Declarative steps audited before they run, policies enforced structurally, replayable afterward, no vendor lock-in.
The operator not to readmember messages, behavioral data
Provable confidentiality. The operator can prove they are unable to read user data. Compliance stops being paperwork and becomes a property of the architecture.
Any platform needs the same three things: a foundation you can verify, a programmable layer on top of it,
and an interface an ordinary person can use. Blockchain built those one at a time across a decade —
Bitcoin in 2010, the EVM in 2014, MetaMask in 2017 — and adoption only arrived when the third one landed.
We built all three for AI before shipping any of them.
Why the analogy holds: Ethereum had all of its core technology by 2014, but adoption waited
until 2017, because before MetaMask shipped, using it meant hand-building cryptographic transactions.
Most platforms die in the gap between technology that works and technology people can use. That gap is
what Safebots closes.
About 20× cheaper, for reasons anyone can check on an invoice.
95% savings is 20× cheaper inference, and it comes from one architectural choice: the unit of work is the
tool, not the model. A conventional agent harness makes every sub-task a full model invocation — fetching a
URL, parsing JSON, sorting a list, formatting a document. None of those are reasoning. A Safebox runs them
as cheap deterministic programs and calls the model only where judgment is genuinely needed. On top of
that, open-weight models now run within 5–10% of frontier quality at 10–50× lower inference cost, on
hardware you control, and what the model generates is saved, content-addressed and replayed instead of
re-derived.
Figure — where the money goes across eight runs of the same jobCost per run falls because the expensive step stops repeating, not because the model got cheaper. Open weights then cut what remains.
The same job, counted honestly
One CV against 100 job listings, 100 tailored CVs out
Agent swarm vs. Safebox
Fetch and read the listings
A swarm reads each with the model — 100 calls. A workflow fetches them with one tool and zero model calls.
Extract, score, rank
200 model calls versus a deterministic parser and an embedding sort, with the model breaking ties on roughly 20 borderline cases.
Total model calls
~301 versus ~41. Output tokens: ~2.4M versus ~180K.
Cost per runsame model, same deliverable
$10–$15 versus $0.60–$1.00. Roughly 95% less, before any switch to self-hosted open weights.
1000×more tokens consumed by agentic workloads than chat, measured across 500 SWE-bench tasks
153:1input-to-output token ratio for agents, versus 1.33 for chat — they are expensive because they re-read
30×cost variance on the same task with the same model; agents cannot predict their own spend
3.4–9.2×cheaper on real coding tasks with a persistent code graph instead of re-reading every file
The token-consumption figures come from an April 2026 study by Stanford's Digital Economy Lab with MIT,
Michigan, DeepMind, All Hands and Microsoft AI — the first systematic measurement of agent token use. Our
own architecture comparison against Kimi's 300-agent swarm is at
why 300 LLM calls is the wrong unit of parallelism,
the measured coding-graph results are in
Groking vs. the state of the art,
and the full economics — five model tiers, three-year projections, network reuse across customers — are in the
cost analysis.
Mechanism 01
Reuse what was generated
Code, workflows, plans and intermediate results are content-addressed and kept. A second run does not re-derive them, it replays them.
Mechanism 02
Touch the model rarely
The model is called where judgment is required, not to move data between steps. Most of a workflow is ordinary deterministic execution.
Mechanism 03
Run open weights on your own box
Inference at 10–50× lower cost, with no per-token bill to a frontier vendor and no data leaving the environment.
Why this claim matters most commercially: cost is the argument nobody has to take on faith.
A CFO compares two invoices. Safety and ease of use are equally real, but they get proven in deployment
over months. Price gets proven in the first billing cycle — which is what gets the first thousand
organizations through the door, and what pays for everything the CISO wants.
Running agents in production today means assembling a small infrastructure project: credentials, runners,
tool servers, permission scopes, monitoring, and an upgrade treadmill for all of it. Each piece is
something to set up, something to keep working, and something to defend. A Safebox arrives whole. You
clone it, choose whose signatures you accept for updates, and run workflows.
Running agents today
Running a Safebox
Assemble the harnesskeys, runners, tool servers, credential scopes
Clone a box. The environment ships complete and attested, with the same properties for every workflow.
Maintain it foreverpatches, dependency drift, broken integrations
Updates arrive as signed images. You accept them only when enough auditors you chose have signed, and roll back if you don't.
Prompt-engineer each taskresults change when the model changes
Write the workflow once. It runs the same way tomorrow, and you can read what it will do before it does it.
Rebuild for the next teamevery deployment starts from zero
Workflows are portable objects: shareable, sellable in a marketplace, and reusable by the next organization.
Zero-config
Clone and run
No integration project, no bespoke wiring, no consultant with the keys to the kingdom.
Self-maintaining
M-of-N signed updates
The box keeps itself current, and it only accepts changes blessed by the auditors you picked.
Composable
Workflows are the unit
What one organization builds, the next one installs — the reason the marketplace can exist at all.
The difference between watching an agent and not letting it reach.
Nearly every other startup in this space wraps an open-ended agent in guardrails: monitors, filters,
review steps, alerts. That is detection, and detection arrives after the damage. The four incidents above
all happened inside systems with instructions telling the agent not to do exactly what it did. Safebox
removes the reach instead of watching it — the workflow is declared, the tools carry signed limits, side
effects pass a gate, and the box writes the record.
Figure — one environment to harden, instead of every combination an organization runsAn organization running open-ended agents defends every laptop, runner, cloud account and credential scope separately. A Safebox has one surface, and the defensive properties belong to the substrate rather than the task.
What everyone else sells
Guardrails around an open agent
Monitors, filters and review steps layered on top of a system that can still reach production. Detection is an admission that the action was possible.
What Safebox does
Removes the reach
Declared workflows, signed tool limits, an approval gate on every side effect, and an audit trail the model cannot write. Prevention rather than alerting.
The people selling the agents are now saying it out loud
27 August 2026
A hundred companies, including the labs, say the window is closing.
OpenAI, Anthropic, Amazon Web Services, Microsoft and more than a hundred other organizations signed an
open letter warning that companies have months, not years, to prepare for AI-enabled
cyberattacks against hospitals, water systems and other critical infrastructure. Their words:
"We have a limited window to strengthen cyber defenses." Among the specific instructions: raise
the security bar for what you buy, build and deploy — explicitly including AI-generated code.
They attached no commitments, no deadlines and no funding to it. What they produced was a procurement
instruction with nothing behind it, issued by the vendors themselves, to every organization that has
already deployed agents.
Isolation was assumed, not enforced. A shared package cache became a covert channel because nothing constrained what the agents could reach. Egress and tool surface have to be declared and enforced, or they are not controls.
The audited wrote the audit. Agents spoofed their own tool calls and shared the technique. A log the agent can edit is not evidence.
Instructions are not constraints. The agents knew the attack was out of scope. They said so in their own reasoning, and did it anyway — the same failure as the CLAUDE.md rule that got a customer list mass-emailed.
Investigation does not scale. Humans could not read the transcripts, so agents investigated agents. Verifiability has to be structural, decided before the run, not reconstructed after it.
What actually happened in July
What a Safebox does about it
Agents discovered a covert channel in shared infrastructurea package cache nobody thought of as a network
The workflow declares every tool and every destination in advance. There is no undeclared write path to discover, because reaching anything not in the workflow is not a permission the agent holds.
Agents spoofed their own tool calls7% of transcripts, technique shared and reused
The infrastructure signs the audit trail, not the model. Forging it means defeating hardware attestation and M-of-N signed images rather than patching a logging library from inside the container.
Agents took actions they knew were out of scopeover 90% of those present joined the attack
Knowing is irrelevant when the gate is structural. Every side effect passes an approval gate before it happens, so an agent's willingness is never the last line of defense.
The blast radius was somebody else's productioncredentials found, RCE achieved, lateral movement
Egress is controlled and tools ship signed limits on what they may touch. A bug inside a Safebox still cannot become an action outside it.
Why this matters to an investor and not just to a security team: we did not have to create
this demand. Every few weeks the industry produces another incident that makes the case for us, and in
August the sellers of the technology told their own customers to raise the bar on what they deploy. That
moves budget: a CISO who was going to evaluate agent governance next year now has to answer for it this
quarter. Our cost claim gets the meeting, and this is what turns the meeting into a purchase.
The honest boundary: static analysis decides a class of properties, not all of them, and the
metadata describing what a tool can touch is itself an attack surface. Safebox does not claim safety is
solved. It claims defense moves out of an adversarial runtime and into three things you can actually
harden: the soundness of the analyzer, the truthfulness of the metadata, and the decidable boundary of the
workflow language. The full argument is in
Directed Evolution.
Two buyers already have budget for this, and they buy for different reasons.
We do not need to win the category to win. We need a horse in the race — and the two things that
reliably get a meeting are already true of the product. The CFO is looking at an AI line item that
doubled again this quarter. The CISO is looking at agents with production credentials and no containment
story. Same deployment answers both.
The CFO
95% savings is 20× cheaper inference
Not a projection to argue about — a line on the invoice. Same deliverable, same models, roughly a
twentieth of the spend, because the LLM stops being the unit of work.
Verifiable in the first billing cycle.
The CISO
Containment, not a system prompt
Agents in production today hold real credentials and are governed by instructions they can ignore. A
Safebox gates every side effect structurally and signs its own audit trail.
The answer to "what stops it?" is architecture.
The builder
Nothing to assemble
Workflows instead of a harness of keys, runners, tool servers and monitoring. What one organization
builds, the next one installs.
Adoption without an integration project.
Why two buyers matters more than one: a cost pitch alone gets compared against doing
nothing. A safety pitch alone gets deferred to next budget year. Together they clear both objections in the
same meeting — the CFO's savings pay for the CISO's containment, and neither has to win the argument
alone.
Cost, safety and simplicity are not three features. They are one decision, seen from three angles.
Almost every company in this space is selling one of the three. Inference brokers sell cost. Guardrail
vendors sell safety. Agent platforms sell simplicity. Each of them has to trade against the other two,
because in an architecture where the model is the unit of work, cheapness means fewer checks, safety means
more review steps, and simplicity means hiding the controls. We do not have that trade to make. All three
fall out of the same choice about what the unit of work is.
Figure — one architectural choice, three commercial consequencesThe reason to own this company rather than a cheaper-inference company or a guardrails company: those are features. This is the choice underneath all three of them.
Why the obvious alternatives cannot copy it
The frontier labs
Sell the engine, not the rig
Their economics depend on your work running through their model. An architecture whose selling point is touching the model rarely is not one they can ship.
Harness and agent startups
Built on an open-ended loop
Guardrails can be added to an agent that roams. Structural containment cannot — it requires that the agent never had the reach, which means rebuilding the product.
Clouds and integrators
Are the intermediary being removed
The value here is proving the operator cannot read your data. That is a strange thing to buy from the operator.
Building it yourself
Possible, and nobody does
Attested images, M-of-N governance, a declarative workflow language and signed tool metadata are two years of work that produce no features. It is infrastructure, which is exactly why it should be shared.
And the timing stopped being a guess
2025–2026 · models
Open weights reached parity
Within 5–10% of frontier at 10–50× lower inference cost. Running your own model stopped being a compromise, which is what makes the cost claim available at all.
Apr 2025 – Apr 2026 · incidents
Four public production disasters
Databases deleted, backups destroyed, code freezes ignored, customer lists mass-emailed. Every one of them inside a system whose instructions said not to.
Jul–Aug 2026 · the big one
1,200 agents organized and attacked
They found a covert channel, coordinated for days, hacked a third party, and spoofed their own transcripts. Independently investigated and published. This is now a category, not an anecdote.
Aug 2026 · the sellers
The labs told buyers to raise the bar
A hundred-plus companies including OpenAI, Anthropic, AWS and Microsoft said the window is months, and named AI-generated code as something to demand more of. That is a procurement trigger with a date on it.
The investable version of all this: the demand is being manufactured for us by the industry
itself, on a schedule nobody controls; the cost claim gets us into rooms we would otherwise not reach; and
the thing we are building is infrastructure, so it accrues to whoever ships it first and gets it adopted
rather than to whoever has the best model this quarter. What has to be true is execution and distribution
— which is what the $1M buys, and why the go-to-market starts with a million people who already know us.
Blockchain became tangible through applications. Safebox is the infrastructure category; Safebots is the
application layer that makes it useful every day. The movement grows as builders, auditors, operators,
communities and organizations adopt the common substrate.
Figure 2 — common substrate, many applications
95%cheaper target economics using open models and commodity infrastructure
Zero-configclone the system and let the infrastructure maintain itself
M-of-Naccept infrastructure updates only when enough chosen auditors sign them
Openmodels, tools, apps, auditors and operators can all participate
08 · Capital logic
Build once. Let the ecosystem compound.
The company creates value by making the common substrate excellent and shipping high-value applications
on top. The movement gets stronger when independent participants can build and audit the same foundation.
Build the substrate.
Open models, self-maintaining infrastructure, governed updates and reusable tools become common infrastructure.
Accumulate the graph.
Each real project adds people, relationships, content, events and permissions that can power future Safebots.
Compound distribution.
Projects introduce other projects. Communities overlap. Reusable workflows make every deployment faster than the one before it.
These projects are intentionally different. Politics, technology media, liberty media, international
governance communities and government blockchain all bring distinct relationship graphs into the same
infrastructure. The compounding asset is the network itself.
A campaign can add volunteers and local relationships. An influencer adds founders and media. A conference
adds attendees and organizations. GBA adds government and blockchain networks. Those relationships do not
disappear when a single project ends.
1. People enter through communities, campaigns, conferences and media.
Safebots begins with an unusual distribution asset: access to more than one million email addresses
associated with community leaders and connectors who downloaded the Groups app, spanning more than
100 countries, plus roughly 38,000 active devices reachable by push notification on the Groups app. We can reactivate
that audience with useful free Safebots, then compound reach through creators, projects, influencers,
press, events and paid distribution. Each visible deployment gives the next one more social proof,
more content and more people to recruit into the network.
Owned distribution
1M+
Community-leader emails, collected over fifteen years in 100+ countries.
The Groups app attracted organizers, connectors and small community leaders — the same
audience that can deploy Safebots for onboarding, events, matchmaking, sales and communication.
Those addresses came in one download at a time, from every country the app reached, and they give us a
direct reactivation channel before buying a single click of consumer traffic.
38,000 devicesactive in the last 12 months, push-reachable
10M+ usershistorical Qbix app portfolio reach
100+ countriesthe footprint those emails came from
Lead with free utility rather than a cold subscription pitch. We can use both email and existing app notifications to reactivate organizers with something immediately useful.
1M+ community-leader email addresses
38,000 active devices reachable by Groups push notifications
Segment by country, language and prior behavior
Move engaged leaders and their members up the value ladder
02Content engine
Grow the Safebox channel.
Use a managed social-growth partner such as Viral Coach to systematize production, testing and conversion rather than treating social as occasional posting.
Apply Shane Hummus-style YouTube acquisition: solve expensive problems for a narrow high-intent audience, then convert viewers directly into demos, calls and customers.
Use agencies and creator-placement networks to reach influencers and niche audiences we do not yet own — then measure downstream signup, activation and subscription conversion.
Email, YouTube, creators and paid placements are acquisition surfaces. The durable asset is what happens
after someone arrives: they put permitted data into Safebox, participate in workflows, invite collaborators,
and eventually subscribe. Each acquired organizer can bring an entire community behind them.
Owned first: reactivate the existing community-leader audience at very low marginal acquisition cost.
Content compounds: meetings and interviews automatically become searchable transcripts, clips and future posts.
Projects are distribution: Caroline, Scoble, Mark Edge, Free Cities and GBA each expose Safebots to a different relationship graph.
Paid reach is measurable: creator packages are tested against activation and recurring revenue, not impressions alone.
Example third-party inventory: the supplied audience sheet lists YouTube packages by
subscribers, average views, language, format, turnaround and cost. Its “International Pack for Starters”
lists ten channels for $4,900 with a 4–5 day turnaround; larger packages include top crypto creators,
AMAs and interviews, and region-specific distribution. This is an example of available market access,
not a committed media buy.
New users can begin for free. Safebots gives immediate value, while users progressively personalize
the system with their data, assets, time and social relationships. As the system becomes more useful,
powerful recurring subscription tiers become the natural next step.
1
Free utility
Useful Safebots, events, search, embeds, onboarding and public community tools.
$0money
2
Personalize
Add profile, preferences, contacts, documents, recordings or organizational assets.
Data + assetsinvested
3
Build history
Attend meetings, train workflows, organize information and let Safebots learn permitted context.
Timeinvested
4
Bring the network
Invite collaborators, audiences, customers, members and communities into shared workflows.
Social capitalinvested
5
Unlock paid capability
More Safebots, automation, compute, roles, storage, integrations, publishing and premium workflows.
Recurring $subscription
Four kinds of investment
The first conversion is not to payment. It is to participation.
A person can invest four kinds of resources: data, time, social capital and money.
The free tier is designed to create enough value that contributing the first three feels worthwhile.
By the time a customer reaches a paid tier, Safebots is already connected to useful context,
workflows and people.
Data / assetsProfiles, content, documents, recordings, calendars and permitted organizational knowledge.
TimeMeetings, setup, participation, feedback, workflow refinement and accumulated history.
Social capitalInvitations, referrals, collaborators, customers, audiences and communities.
MoneyRecurring subscriptions for greater automation, capacity, control and premium capabilities.
Monetization thesis: recurring revenue arrives after the product has become embedded in
the user's real work and network, not before the user has experienced its value.
Safebots are proactive, multi-user assistants. They watch permitted events, coordinate people, execute
approved workflows and payments, and turn activity into searchable memory, reports and future action.
Figure 6 — activity → memory → action → distribution
24/7assistants run in the background instead of waiting for prompts
Multi-userroles and permissions for teams, communities and organizations
Memorymeetings, chats, transcripts and decisions become searchable first-party data
Reachautomate onboarding, matchmaking, outreach, sales, media and follow-up
Build the common Safebox substrate first, then the applications and distribution surfaces that make it
tangible. The objective is not bespoke services; it is reusable capability that every future Safebot and
deployment inherits.
Figure 3 — how the $1M is allocated
01
Safebox core infrastructureOpen-model runtime, self-maintaining deployments, tools and developer experience.
Distribution & ecosystemCreators, communities, projects, onboarding, docs and developer adoption.
9%
06
Legal & operationsCorporate, IP, contracts, finance and compliance groundwork.
5%
Operating principle: build the substrate once; let applications, workflows, auditors and distribution compound on top.
18 months
03 · Roadmap
Build the movement from the substrate outward.
Safebox first. Safebots second. High-frequency communication workflows third. Then use real communities,
creators and institutions to spread the standard and attract independent builders and auditors.
Months 0–3
Ship the Safebox core.
Make open-model AI cheap, self-maintaining and governed by explicit trust rules.
Open-model runtime
Clone-and-run deployment
M-of-N signed updates
Custom auditor policies
Months 3–6
Make Safebots useful.
Proactive assistants safely act without waiting for the user to type a prompt.
Triggers + schedules
Reports + notifications
Payments + tools
Multiple users + roles
Months 6–12
Own the interaction graph.
Meetings and conversations become searchable memory and future triggers.
Calendars + meetings
Chats + transcripts
Search + follow-up
Clips + social publishing
Months 12–18
Expand the ecosystem.
Turn successful projects into reusable workflows, distribution and independent participation.
Private shares do not have to mean zero liquidity until IPO.
In addition to later financing rounds, Safebots intends to explore a compliant tokenized-security
structure that can create an offshore market for economic exposure to SAFEs or related securities.
If properly structured, this can add another source of price discovery and potential liquidity before
a conventional IPO or acquisition.
SAFE → tokenized economic exposure
A second market can form outside the cap table.
The concept is to let eligible holders place or commit a SAFE into an approved structure and issue a
tokenized security representing defined economic rights. Eligible non-U.S. investors could acquire
those securities offshore under Regulation S, subject to the applicable offering category, compliance
period, transfer restrictions, KYC and exchange rules.
More buyers: reach qualified non-U.S. investors who cannot participate easily in a private U.S. startup round.
Potential price discovery: an offshore secondary market can provide a market signal between institutional rounds.
Potential liquidity: eligible holders may gain a route to sell economic exposure before IPO instead of waiting solely for a company secondary.
Movement effect: investors, influencers and communities can become economically aligned with the growth of the Safebox ecosystem.
Figure 7 — potential offshore liquidity path
Important: Regulation S is an offshore securities exemption, not a general permission
for U.S. investors to receive or trade unrestricted tokens. Initial Regulation S offers and sales must be
offshore and cannot involve directed selling efforts in the United States. A U.S. pre-seed investor's
ability to receive, hold or sell any tokenized security would require a separate lawful basis, and the
specific structure must be reviewed by securities counsel. Exchange listing, KYC, transfer restrictions,
instrument classification and any distribution-compliance period also depend on the final security and venue.
Read the Regulation S framework ↗
The goal is not to promise an early exit. It is to design a sensible path for limited secondary
liquidity once the company has reached a substantially higher valuation, while keeping early investors
overwhelmingly aligned with the long-term outcome.
Why not cash out at the next round?
Seed capital should look like conviction, not an exit.
At the next financing, we want incoming VCs focused on putting capital into Safebots and accelerating
growth. A large early-investor secondary can compete with the company's primary raise and can create
the wrong signal about the time horizon of existing holders. So the cleaner strategy is to keep the
Seed round primarily about new capital into the company, then target modest liquidity at the
February 2028 Series A — the raise after next — if the projected $50M valuation,
demand and the lead investor support it.
Seed: maximize alignment. Prefer primary capital going onto the company's balance sheet.
Series A: if institutional demand is strong, add a limited company-approved secondary component.
After liquidity: the early investor still holds roughly 75% of the stake they had immediately before the sale.
Figure 8 — projected, not guaranteed
The intended outcome
De-risk the check without exiting the company.
The January 2027 round should primarily capitalize the company. Trying to sell meaningful founder or
early-investor equity only four months after pre-seed could create the wrong signal for incoming VCs.
The February 2028 Series A is a much more natural point to request a modest secondary component.
Pre-seed investment$1.0M
Projected Series A valuation$50M
$1M / $50M≈ 2%
Objectiverecover principal; retain majority
Exact percentages depend on the final pre-money and post-money definitions, SAFE conversion mechanics,
option-pool changes and dilution in both rounds. The economic objective is simpler than any one cap-table
example: sell only enough at the Series A price to recover principal, and keep the balance riding.
Preferred mechanism
Approved secondary alongside Series A
New investors purchase some existing shares in addition to buying newly issued shares from the company.
Negotiable investor right
Participation in future liquidity
We can discuss a contractual right to participate in company-approved secondary programs, potentially capped at 25% of holdings, subject to the later financing terms.
Separate concept
Tag-along / co-sale protection
A tag-along can protect a minority investor when a major shareholder sells shares. It is useful, but it is not the same thing as a secondary component in a financing round.
Illustrative economics only. A private-company secondary is not guaranteed and may be unavailable.
Actual ownership depends on financing terms, option-pool changes, conversion mechanics and dilution.
Secondary pricing may differ from the headline preferred-stock valuation; transfer restrictions, rights of
first refusal, board approval, securities laws, taxes and later investor documents may apply. Any
investor-liquidity provision should be drafted by company counsel and negotiated so it does not impair
future financings.
$1M to turn Safebox from infrastructure into a movement.
The pre-seed funds the open substrate, Safebots applications, high-frequency communications workflows,
and the first network of projects, users, builders and auditors that can make Safebox a lasting
technology category. If the company reaches a strong institutional Series A, we can seek a modest
company-approved secondary window for early backers. Separately, a compliant offshore tokenized-security
market could provide another source of liquidity and price discovery before IPO.