VEMSEC

Machine speed.
Human command.

VEMSEC builds AI agents and AI cyber capabilities for U.S. defense that stay inside the authorities you set and answer to the people in command.

Founder-led and now inviting pilot partners.

Illustrative simulation

The fight runs on software.


Adversaries are automating their planning and their attacks. Too much of our defense still moves at the speed of email. VEMSEC exists to close that gap with autonomous software that answers to human command and is designed to run where the mission runs, including networks that never touch the internet.

We are starting small on purpose: we are looking for a few real workflows and a few pilot partners, and we intend to earn trust one approved action at a time.

Capabilities


AI Agents

Agents designed to take on the planning, analysis and workflow burden that slows missions down, and to hand every consequential decision to a person.

Illustrative simulation

  • Planning support Draft courses of action, timelines and staff products against the constraints the commander sets, for a human to approve.

  • Intelligence triage Sort collection across sources, correlate entities, and cite the source behind every claim.

  • Workflow automation Move reports, requests, tasking and shift handoffs between the systems a unit already runs.

  • Disconnected operation Run on local compute and local models when the link is denied or degraded, or was never there.

Talk about AI agents

AI Cyber

Defensive agents designed to hunt and contain inside pre-approved authorities, plus security for the AI systems the mission now depends on.

Illustrative simulation

  • Threat hunting Hypothesis-driven hunts structured around MITRE ATT&CK®, with the evidence packaged for the analyst.

  • Bounded response Containment playbooks designed to run inside pre-approved authorities. Anything beyond them stops and waits for a human.

  • AI system security Red-team and harden models and agents against prompt injection, data poisoning and model theft, using MITRE ATLAS™ and OWASP guidance for LLM and agentic applications.

  • Secure AI delivery Hardened, signed container images with a software bill of materials, packaged for GitOps delivery to your program’s Kubernetes platform, whether connected or air-gapped.

Talk about AI cyber

Humans in command.


The first question about agentic AI in defense is who is in control. We answer it in the design, before we write the feature. These commitments apply to everything we build.

  1. Human approval gates

    You set the authorities. Anything outside them stops and asks a person, and consequential actions never run on an agent’s judgment alone.

  2. A complete audit trail

    We design every system so each prompt, tool call, model version and approval is recorded and attributable, and any action traces back to the person who authorized it.

  3. Models of known origin

    We build on models and weights whose origin we can document. We do not use models from adversary nations.

  4. Deployable to disconnected networks

    Every component is designed to install and run with no internet connection: containerized, shipped with its dependencies, signed, and documented with a software bill of materials.

These are design commitments, not certifications. Accreditation is earned system by system, with your authorizing official.

Audit log (illustrative, not operational data)

Illustrative audit log: an agent proposes isolating a host, the action waits at an approval gate, a watch officer approves it, and the action is logged.


Founder-led

VEMSEC is founder-led. When you talk to us, you talk to the person designing the software, building it, and accountable for it.

We use AI agents in our own engineering under the same rules we build into our software: gated, logged, and reviewed by a person before anything ships.

Founder

Matt Vasquez

Founder & CEO

  • More than 20 years on the technical side of U.S. government technology programs.
  • Work spanning network security, DevSecOps and Kubernetes platforms, and cloud.
  • AI security, including published work on red teaming local, open-source LLMs.

“I started VEMSEC to give the people who defend the mission AI they can trust and command, on their networks and under their authority.”


Pilot with us

VEMSEC is looking for a small number of pilot partners: mission teams with a workflow that should move faster, and primes and integrators who need agentic AI or AI-security depth on a program.

  1. One workflow

    We pick one real, bounded problem together, with a clear definition of done.

  2. Your environment

    We start in a representative environment, connected or disconnected, and work in yours only under the agreement and access rules your program requires.

  3. Your operators decide

    The people who would use it evaluate it, with the approval gates, the audit trail and the models open to them from day one. If it doesn’t earn its place, we stop.

What we ask

A real problem, an operator willing to use what we build, and a sponsor who can tell us yes or no.

For primes and integrators

We’re open to teaming conversations on current and upcoming pursuits.

Propose a pilot

Talk to the founder

Tell us about the mission, the workflow or the pursuit. You’ll get a reply from a vemsec.com address.

Enter your name.
Enter your organization.
Enter a full email address, like name@agency.mil.
Choose a topic.
A few sentences is plenty.

NoticeDo not submit classified information or CUI through this form.

Your message goes straight to the founder.

Message sent

Received. You’ll hear back from a vemsec.com address.

We use what you send only to reply and to keep a record of the conversation. Privacy

Privacy

VEMSEC collects only what you choose to send us: the details in the contact form or in an email. We use them to reply to you and to keep a record of the conversation. We don’t sell them, and we share them only with the services that run this site and our email.

This site is hosted by Netlify, which processes your IP address and standard request logs (time, page requested, browser) to serve the site and keep it secure. Messages sent through the contact form are stored by Netlify Forms and emailed to contact@vemsec.com (our email runs on Google Workspace).

There are no analytics, no cookies and no third-party trackers on this site, and the fonts are served from this site, not a third party. Your Animation preference is saved in your browser only (local storage) and is never sent to us.

To see or delete what we hold about you, email contact@vemsec.com.

Last updated September 28, 2026

Accessibility

We want this site to work for everyone, and we design it to meet WCAG 2.2 Level AA. Motion follows your system’s reduced-motion setting, and you can turn animation off at any time with the Animation control. If something doesn’t work for you, email contact@vemsec.com and we’ll fix it.

Last updated September 28, 2026