ApexClaw
Home › About
About

ApexClaw is an evidence-grade agent trust layer, built by the person who found the governance gap by operating agents himself.

Governance, receipts, approvals, revocation and replay for autonomous AI agents — so an action can be authorized before it happens and proven after it does.

Published

Get an Agent Trust Gap Brief

What ApexClaw is

ApexClaw is an evidence-grade agent trust layer: governance, receipts, approvals, revocation and replay for autonomous AI agents. It decides whether an autonomous agent is allowed to act, and emits a signed, tamper-evident receipt proving exactly what happened. See the platform overview for the five surfaces that make that work.

Who built it

Julian Joseph, founder. Twenty-plus years in adtech and martech. ApexClaw is personally funded and personally owned, and its evidence comes from a system he built and runs himself. Full background on the founder page.

How we handle claims

  • No fabricated numbers. Sourced, first-party with methodology, or labelled TARGET / SYNTHETIC / COLLECTING / INTERPRETATION.
  • No certifications we do not hold. SOC 2 and ISO 27001 are roadmap items, never claimed as achieved.
  • No internal metric passed off as market proof. Our own system's numbers are labelled as our own system's numbers.
  • A past receipt is not proof of present health. Live claims carry an expiry and are re-verified on cadence.

Ledger of material product and evidence claims, each with its basis and expiry: the trust center.

Contact

Email: julian [at] thruliquid [dot] com. Security reports: see security.txt (RFC 9116). For anything else, use the contact page.

What ApexClaw is, and is not

IsIs not
A control plane that authorizes an action before it executesA filter that only inspects prompt text going in and out
A signed, tamper-evident record of what an agent didAn audit log that can be edited and rarely records refusals
An assessment of your agent estate's controls and evidenceA certification, attestation, or compliance determination
A system that governs itself and publishes the receiptsA vendor asking you to trust a claim it does not evidence

Common questions

Why is ApexClaw personally funded rather than venture-backed?

Personal funding keeps the incentive aligned with proof rather than growth-at-all-costs. The tradeoff is stated plainly rather than hidden: slower scaling, no investor pressure to overclaim readiness.

What makes this an evidence-grade trust layer rather than a filter?

A filter inspects text going in and out. This layer decides whether an action executes, before it does, and produces a signed receipt proving what was authorized and what happened.

Does ApexClaw hold SOC 2 or ISO 27001?

No. Both are roadmap items and are never claimed as achieved. The trust center lists exactly what is and is not held, with dates.

Why does the founder operate his own agents?

Because the gap between what a vendor claims and what actually holds under real agent traffic is only visible from inside a running system, not from a deck.

Sources

The gap this exists to close is not abstract: machine identities already outnumber human ones by more than 80x in most enterprises, and Gartner projects more than 40% of agentic AI projects will be cancelled by the end of 2027, driven by escalating cost, unclear value, and inadequate risk controls. Enforcement exposure is real too: the EU AI Act's three penalty tiers run up to 7%, 3% and 1% of global turnover depending on the obligation breached. The system ApexClaw governs itself with has produced 0% real external sends across its history, verified at the network layer on the governed-run record. Standards referenced: OWASP Top 10 for Agentic Applications, NIST AI RMF, and ISO/IEC 42001 for the management-system reference point neither SOC 2 nor ISO 27001 is claimed against here.

How this page fits with the rest of the site

This page states what ApexClaw is and who built it; it deliberately does not restate the platform's five surfaces, the pricing model, or the standards crosswalk in full, because each of those already has its own page built to answer that specific question in depth rather than compressed into a paragraph here. The platform overview covers the control surfaces, pricing covers how engagements are scoped, and the trust center covers every material claim with its basis and expiry.

That separation is itself a claims-law choice, not an accident of site structure. A summary page that tries to also be the definitive source on pricing, methodology and standards mapping ends up drifting out of sync with the pages that are actually maintained on a cadence, which is exactly the kind of contradiction a careful reader — or an answer engine checking one page against another — is positioned to catch. Keeping one fact in one place, linked rather than duplicated, is slower to write and easier to keep honest.