Four Criticals and three CVEs. Closed before the agent ever touched production.
Hermes Sovereign Runtime is an AI agent runtime built to operate under real governance. Before it ran anything that mattered, we put it through the security process most agents skip — and the findings are on the public record.
Most AI agents reach production on a demo and a deadline.
The pressure to ship agentic systems is enormous, and the security bar is whatever the team had time for. "It works" becomes "it's live." We built Hermes Sovereign Runtime to prove the opposite path: an agent runtime that earns production access by passing the process, in public.
The findings were Critical. That is exactly the point.
Four Critical findings in a runtime headed for production.
Critical means exploitable with real impact. These are the findings that, missed, become the incident report six months later.
Caught before deployment, not after an incident.
The same findings discovered post-launch are a breach, a disclosure, and a remediation scramble. Discovered first, they're just engineering.
Three of them became CVEs.
Filing a CVE puts the finding on a public, permanent register. It is the difference between "we found some issues" and a claim anyone can check.
Find. File. Fix. Verify. Then — and only then — ship.
Adversarial review
Static analysis, dependency and supply-chain review, and hands-on runtime testing against the agent's real capabilities.
Disclose to the record
Where findings warranted it, we filed CVEs — accepting public accountability for the claim.
Remediate at the root
Each Critical was closed in the runtime's design, not muted with a config flag or an exception.
Re-test cold
Confirm each fix independently before production access is granted. Zero Criticals carried forward.
A runtime that reached production with its findings already closed — and on the record.
Ask any agent vendor for the CVEs they filed against their own runtime before launch. The answer — or the silence — tells you everything.
Put your agent through the same process.
Three ways in, matched to how close you are to shipping.
Agent readiness brief
The pre-production checklist we ran against Hermes. Download and self-assess.
Get the brief →Threat-model workshop
We threat-model your agent runtime with your engineers in a working session.
Book the workshop →Pre-production assessment
The full find-file-fix-verify process run against your runtime before it ships.
Scope the assessment →