Training infrastructure · Build 0427

Ship autonomous agents that hold up in production.

Substrate is a training and runtime platform for teams building long-horizon AI agents. Compose tools, supervise traces, run evals against adversarial suites, and deploy sandboxed workers in fourteen regions — all from a single control plane.

47.2M
Agent runs / week
312ms
p95 tool latency
99.982%
Runtime SLA
02 / Capabilities

A full training surface for agents that act, not chat.

Substrate separates the four things agent teams keep wiring themselves: supervised orchestration, continuous evaluation, sandboxed tool execution, and policy-gated deployment. Each surface is inspectable at the token level.

01 / ORCHESTRATE
Deterministic orchestration for long-horizon plans
Hierarchical planner with replay, branching, and hard step budgets. Every decision is reproducible from trace ID.
planneractive
retrieve12ms
tool.shellok
criticscore .94
02 / EVALUATE
Adversarial evals with regression tracking
Ship a change, see pass-rate deltas on 240+ curated suites. Flag drift before it hits prod.
487/512
Pass rate
+2.8%
WoW
0.003
Drift σ
03 / TOOLS
240+ first-class tools
Browser, shell, SQL, retrieval, code-exec — with typed schemas.
82%
Typed
04 / REASONING
Inspect the reasoning, not just the output
Every agent keeps a replayable plan tree. Jump to the step, fork, and re-run.
plan.step[7]: fetch ledger → reconcile variance > 2.4%
14.2k
Tokens
23
Steps
ok
Critic
05 / RUNTIME
Sandboxed workers in 14 regions
Hardware-isolated runners, deterministic replays, and per-tool network egress policy.
14:22:07.184 worker/a7f-eu spawn ok image=agent:0.4.2
14:22:07.511 tool.browser.goto 200 rtt=211ms
14:22:08.044 tool.retrieval.k=8 ok mrr=0.82
14:22:08.712 policy.egress deny host=api.unknown.io
14:22:09.198 planner branch fork reason=deny
14:22:10.062 tool.shell.run exit 0 dur=864ms
14:22:10.881 trace.commit 247 spans · 14.2k tok
06 / LATENCY
Edge-scheduled, p95 under 312ms
Regional caches and warm pools.
03 / Builder

Compose agents the way engineers wire systems.

A typed, version-controlled canvas. Drag tools onto the graph, wire in critics and retrievers, and export the entire pipeline as reproducible config. No hidden state, no invisible prompts.

pipeline · ledger-reconciler Running
Input · Webhook IN
schemaLedgerEvent
rate42/s
Planner · Meridian-3.1 LLM
horizon2048
temp0.31
traceon
Retrieval TOOL
indexledgers-2026
top-k8
Critic · strict-v4 EVAL
threshold.88
on-failfork
Output · Kafka OUT
topicrecon.out
ackall
5 nodes · 4 edges · strict/enterprise-v4 saved · commit 7a3f9c1
04 / Security

Every agent action is gated, logged, and revocable.

Agents are a new class of principal. We treat them that way — scoped credentials, egress policy, tamper-evident traces, and a revocation surface your security team can actually use at 3am.

Scoped agent identities

Short-lived credentials, per-tool scopes, automatic rotation. Agents can't borrow human creds.

SPIFFE · SVIDENFORCED

Sandboxed execution

Hardware-isolated workers, deterministic replay, syscall allowlist per tool. No shared filesystem.

gVisor · KVMACTIVE

Tamper-evident traces

Every span is signed and merkle-chained. Auditors verify against public anchors, not your word.

SLSA · L3PASSED

Kill-switch at the edge

Revoke an agent, a tool, or an entire region in under 400ms. Runtime acknowledges before returning.

MTTR · 320msOK

Egress policy engine

Declarative allow-lists per agent, per environment. OPA-compatible. Denials branch the plan, not crash it.

OPA · REGO 3LIVE

Private data boundaries

Per-tenant KMS, BYOK, row-level policy inherited into retrieval. Nothing leaks into evals.

HSM · FIPS 140-3CERT

Adversarial red-teaming

Continuous jailbreak, prompt-injection, and tool-misuse suites run nightly against every pipeline.

MITRE · ATLASMAPPED

Compliance, built-in

SOC 2 II, ISO 27001, HIPAA, GDPR, EU AI Act Annex III. Evidence packaged on export.

8 standardsREADY
Live audit streamus-east · eu-north · apac-3
last 60s · 3,142 events
14:22:10.881 agent.ledger-reconciler committed trace 7a3f9c1 principal: svid://eu/a7f TRACE ✓ ok
14:22:09.412 policy.egress blocked request to api.unknown.io rule: enterprise/default EGRESS ⚠ deny
14:22:08.027 agent.support-tier2 escalated to Amara Okonkwo threshold: critic < .82 HANDOFF ✓ ok
14:22:06.714 runtime.worker-c1e sandbox violation · syscall ptrace region: apac-3 SANDBOX ✗ kill
14:22:04.188 eval.adversarial nightly suite · 487/512 pass suite: tool-misuse-v7 EVAL ✓ ok
05 / Get access

Move your agents off duct tape.

Substrate ships with a 30-day evaluation tier: 2M agent steps, every region, every eval suite. White-glove onboarding from a solutions engineer on day one.

SSO · SCIM · VPC peering · BYOK from day 1
2M
Free steps
14
Regions
30d
Evaluation