top of page

doxx.net Funding Puts $38 Million Behind a Private Internet for AI Agents

14 hours ago
13 min read

doxx.net funding has put $38 million behind a direct challenge to how AI agents use the internet. The startup wants network infrastructure, not prompts alone, to constrain where agents connect and what they can reach.

The Series A round accompanies the open beta of doxx.net’s Agentic Defined Networking platform. Andreessen Horowitz led the financing, with Animo Ventures and Focal.vc participating. The Miami-based company says its platform gives people and agents private networks with programmable identities, routing, firewalls, and threat filtering.

That pitch arrives as browser agents gain access to email, files, APIs, cloud services, and payment workflows. A compromised chatbot can generate a harmful answer. A compromised agent can take a harmful action using its owner’s authority.

The central question is therefore larger than whether doxx.net has designed a more private VPN. It is whether moving agent controls into the network can limit mistakes that model-level safeguards fail to catch.

The Funding Backs a Network and a Security Thesis

doxx.net is selling infrastructure as the missing enforcement layer between an AI agent and the public internet.

The company announced its Series A and open beta on October 1, 2026. Barrett Lyon founded doxx.net in 2025 after building several networking and security companies, including Prolexic and Defense.net.

Andreessen Horowitz led the round, while Animo Ventures and Focal.vc joined it. The firm reportedly operates infrastructure across six continents, although detailed capacity and customer figures remain undisclosed.

The financing itself matters because doxx.net is attempting more than a browser extension or another policy dashboard. It has built a network that includes dedicated hardware, its own IP space, a private naming system, and a certificate authority.

The product is called Agentic Defined Networking, or ADN. The term describes networks that agents can configure and operate under policies established by their owners.

According to the company, an agent can create a private network, connect devices, set firewall rules, establish private names, and manage secure paths. It can also lease public IP addresses and operate services inside that environment.

The open beta includes native applications for iOS, macOS, and Android. The company also says Windows and Linux systems can connect to its backbone.

This launch joins two products that security vendors usually separate. One protects traffic moving across networks. The other governs software agents that make decisions and call tools.

doxx.net argues that those categories now need to overlap. An agent might read a document, browse a site, download a file, and call an API during one task. Every connection becomes part of its decision environment.

That is why the company’s funding announcement centers on network boundaries. Its open-beta launch says agents need limits on what they can resolve, reach, and leave behind.

The platform also includes DNS-level threat protection. DNS, the internet’s naming system, converts domain names into the addresses used to establish connections.

doxx.net says its service checks destinations before a user or agent connects. It combines 30 filtering lists with a neural-network system designed to identify malicious destinations missed by static lists.

The company claims that this system blocked more than 38 million threats during its closed beta, which began in December 2025. It also reports more than 1.2 million blocked events each week.

Those are company-supplied figures, not results from a published independent evaluation. They still clarify the product’s immediate purpose: stop suspicious connections before an agent can interact with the destination.

The funding report describes the platform as an environment with defined connectivity and built-in threat protection. That framing distinguishes it from tools focused only on monitoring an agent after execution.

The distinction gives the doxx.net funding event its importance. Investors are backing a claim that agent safety will become a networking problem, not only a model problem.

Why AI Agents Put Existing Internet Controls Under Pressure

AI agents turn ordinary security weaknesses into delegated authority, because they can act while processing untrusted information.

Traditional web security assumes a person remains involved in consequential decisions. Software may flag a suspicious page, but a human chooses whether to proceed, share a file, or approve a transaction.

Agents weaken that assumption. They can navigate websites, inspect messages, move documents, change configurations, and communicate with outside services during a single assignment.

Each capability improves usefulness. Each one also gives hostile content another path toward the agent’s tools and credentials.

Indirect prompt injection illustrates the problem. An attacker hides instructions inside a webpage, email, document, image, or tool response that an agent processes.

Those instructions can conflict with the user’s original request. A vulnerable agent might follow them because both legitimate information and hostile commands arrive through its working context.

Anthropic has called prompt injection one of the most significant risks facing browser agents. Its browser security research warns that every visited page can become an attack vector.

The company also says no browser agent is immune. Training, content classifiers, permission prompts, monitoring, and human review can reduce exposure, but no single safeguard settles the problem.

That limitation creates an opening for doxx.net. Its product does not need to determine whether every sentence on a page is trustworthy. It can instead restrict which destinations an agent may contact.

For example, a research agent might need access to approved news sites and an internal document service. It would not need permission to connect to an unknown file-sharing domain discovered inside a webpage.

A network rule could block that second connection even if the model misread the page. The restriction acts outside the model’s reasoning process.

This approach resembles sandboxing, where software operates inside a constrained environment. Sandboxes limit what a process can reach even when the process behaves incorrectly.

doxx.net extends that principle into networking. Its controls address destinations, identities, routes, certificates, and communication paths rather than only local files or computing resources.

The pressure falls on several established security categories. Secure web gateways inspect web traffic, identity systems control account access, and endpoint tools watch activity on individual devices.

Agent security platforms add another layer by monitoring prompts, tool calls, data flows, and non-human identities. However, these systems often depend on integrations across many applications and cloud services.

doxx.net’s proposition is that a private network can create a more consistent boundary. If the agent’s traffic passes through an environment controlled by the user, policies can follow that agent across tasks.

That claim also challenges developers. Many agent frameworks concentrate on reasoning accuracy, tool selection, and task completion. Network policy remains external infrastructure that another team must configure.

ADN attempts to make the agent capable of building that infrastructure. Administrators can issue separate read-only or administrative tokens, then revoke or expire them.

This is a delicate reversal. The agent becomes part of the security problem, but it also helps operate the proposed solution.

The design therefore depends on authority being tightly divided. An agent that can rewrite every firewall rule without oversight would reproduce the original risk at the network layer.

doxx.net says users do not hand agents their master credentials. That separation is essential because a private network does not help when a compromised agent can remove its own restrictions.

How doxx.net Funding Turns Agent Security Into Network Policy

The doxx.net funding thesis rests on enforceable network controls that remain separate from an agent’s interpretation of content.

The platform combines an encrypted mesh, custom transports, a separate control plane, private names, and programmable agent identities. Together, these components define where activity occurs and who can participate.

An encrypted mesh connects authorized sites and devices through protected links. Network World’s technical account says the mesh supports IPv4 and IPv6 and is orchestrated through an API.

An API lets software request functions through a defined interface. Here, it allows an approved agent to build connections or modify network settings without manually navigating an administrator console.

The control plane manages routing, port forwarding, and firewall rules separately from each client device. Keeping these controls separate can make individual clients easier to restrict.

doxx.net also operates its own DNS root and offers 196 custom top-level domains. Services using these names can resolve inside a private environment without appearing in public DNS.

Its certificate authority provides credentials for services within that trust system. Certificates help devices confirm that they are communicating with the intended service rather than an impersonator.

Private naming has practical value for agent workflows. An organization could expose an internal service through a name that only its authorized network participants understand.

An agent would not need to send the request across the public internet. Outside systems could not resolve the same address through ordinary DNS.

The company also supports direct peer-to-peer communication. Calls, messages, and file transfers can move between authorized endpoints without a central communications server storing their content.

That design reduces some intermediaries, but it does not erase every form of metadata. Network operators and endpoint devices can still produce operational information required for routing, maintenance, or abuse prevention.

doxx.net says its architecture avoids permanent user-linked behavioral records. It also allows accounts to be created without an email address, phone number, username, or password.

Instead, the platform uses cryptographic tokens and proof-of-work, which requires a device to complete a computational task. The goal is to establish access without gathering conventional identity data.

The startup has also developed custom transports intended to carry private traffic through restrictive networks. Its reported options include WireGuard, HTTPS, WebSocket, QUIC, SIP, and ping-based methods.

WireGuard is an encrypted tunneling protocol commonly used for virtual private networks. QUIC is a transport protocol designed for faster and more resilient internet connections.

These features expand the platform beyond agent security. They position doxx.net as privacy infrastructure for people, services, and devices, with agents becoming another network participant.

That wider scope strengthens the product and complicates its evaluation. A system covering private communications, censorship resistance, DNS filtering, agent identity, and network automation has many trust boundaries.

A failure in one component can affect the others. A certificate problem could undermine service identity, while a compromised administrative token could alter routing or firewall policy.

The company’s central claim remains narrower and more testable. Network-level enforcement can stop certain actions even when an agent’s reasoning fails.

Suppose an agent reads a malicious instruction telling it to upload confidential files. A destination allowlist could block the attacker’s server before transmission begins.

The same network control cannot determine whether an allowed recipient should receive a particular document. It also cannot detect every malicious action directed at a legitimate service.

That boundary explains what ADN adds without treating it as a complete answer. It provides another enforcement layer, especially for outbound connections, identity, and reachability.

Andreessen Horowitz’s investment thesis argues that agents expand the surface requiring protection because they combine data access with autonomous action. The firm sees infrastructure ownership as doxx.net’s differentiation.

The technical question is whether that ownership produces better controls and fewer blind spots than established cloud-based security systems. Funding gives the company time to demonstrate the answer.

Private Infrastructure Does Not Solve Every Agent Risk

A private network can reduce exposure, but it cannot make an unreliable agent trustworthy or classify every permitted action correctly.

The first uncertainty concerns doxx.net’s threat-blocking claims. The company reports more than 38 million blocked threats, but it has not published an independent audit supporting that number.

A blocked event is not automatically a prevented compromise. One malicious domain can generate repeated requests, while false positives can stop harmless destinations.

Buyers need definitions for what counts as a threat, how events are deduplicated, and which samples receive human validation. Comparative testing would also show whether the system exceeds widely used DNS filters.

The second uncertainty concerns destination-based enforcement. Blocking known malicious infrastructure is useful, but attackers often exploit trusted platforms and compromised legitimate websites.

An agent could disclose data through an approved email system, collaboration tool, or cloud-storage account. The network might see a permitted destination while missing the harmful intent.

Encrypted traffic creates another constraint. A network can observe endpoints and connection patterns, but end-to-end encryption may prevent it from inspecting the content needed for deeper judgments.

Decrypting traffic would introduce different privacy and security problems. The platform must therefore balance visibility against its promise to reduce intermediaries and retained information.

The third uncertainty involves agent administration. doxx.net lets agents configure networks, issue names, manage certificates, and change policies when they hold the required permissions.

Those capabilities make setup easier. They also raise the impact of a stolen token, a misinterpreted command, or an agent operating beyond the user’s intent.

Read-only roles, expiring tokens, revocation, and separated administrative credentials help. Enterprise users will still expect approval gates, detailed logs, recovery procedures, and integration with existing identity systems.

The fourth uncertainty is operational concentration. doxx.net criticizes rented infrastructure and centralized communications services, but customers must still trust doxx.net’s implementation.

Owning hardware can reduce reliance on public cloud providers. It does not automatically prevent configuration errors, software flaws, insider abuse, supply-chain attacks, or physical infrastructure failures.

A separate DNS root and certificate authority also create responsibilities normally distributed across mature public systems. Availability and incident response become as important as privacy.

This is where independent testing matters. Security audits, penetration tests, reproducible benchmarks, and transparent incident disclosures would provide evidence beyond architectural claims.

The broader research supports a layered approach. A 2026 NIST analysis found widespread agreement that existing cybersecurity practices remain relevant but require adaptation for AI agents.

That conclusion does not favor model security over network security. It suggests that organizations need controls across identity, permissions, execution environments, data access, networking, and human authorization.

A browser agent handling sensitive documents might therefore require several protections. It could run inside a sandbox, use limited credentials, access an approved destination list, and request confirmation before transmitting data.

Monitoring would record its tool calls and network activity. Security testing would repeatedly expose it to hostile webpages, documents, and messages.

ADN could occupy the network portion of that stack. Its strongest case is not that network policy replaces every other defense.

Its strongest case is that prompts cannot provide a hard boundary. A model might misunderstand a sentence, while a correctly enforced firewall rule remains a firewall rule.

That advantage disappears if agents can casually rewrite the rule. The platform’s success will depend on making safe authority easier than unrestricted authority.

The Competitive Fight Is Over Where Agent Controls Belong

doxx.net is competing against a security architecture, not one direct rival.

One route places most safeguards around the AI model. Developers train the model to reject suspicious instructions, add classifiers, and interrupt risky actions.

Another route governs the agent’s identity and tool permissions. Security teams decide which accounts, databases, APIs, and applications each non-human identity can access.

A third route isolates execution. Sandboxes limit filesystem access, processes, commands, and network connections, reducing the damage from a successful attack.

doxx.net adds a network-centered route. It treats connection policy, private naming, routing, and threat filtering as native parts of an agent’s operating environment.

These routes overlap, but they do not eliminate one another. Model defenses can identify suspicious content that a network cannot inspect.

Identity controls can restrict what an agent does inside a permitted application. Sandboxes can stop unwanted local changes after an agent reaches a legitimate website.

Network policy can prevent contact with destinations outside an approved boundary. It can also isolate private services from the public naming system.

The commercial contest will turn on integration. Enterprises already operate firewalls, identity providers, endpoint agents, secure web gateways, and cloud access controls.

A new platform must fit those systems without forcing security teams to create a second, disconnected policy universe. It must also explain which existing tools it replaces and which remain necessary.

doxx.net’s physical network could differentiate it from software-only agent governance vendors. That same infrastructure introduces greater capital and operational demands.

Running a global backbone requires reliability across regions, hardware, transit providers, routing, DNS, certificates, and customer support. A failure can interrupt every protected workflow using the service.

The open beta will reveal whether agent-built networking simplifies this complexity. Early users should watch how often agents configure the correct policy on their first attempt.

They should also test whether non-specialists understand the resulting network. Automation is less valuable when only an expert can verify that its output is safe.

Lyon’s history gives doxx.net credibility in networking and distributed denial-of-service defense. Prolexic helped establish the managed DDoS protection market before Akamai acquired it.

That record explains investor confidence, but it does not validate the current product. Agent security combines established networking problems with less predictable model behavior.

The market is also moving quickly. Agent platform developers are adding native sandboxes, permission systems, policy engines, and network restrictions.

Security vendors are extending identity and data controls to non-human actors. Cloud platforms can bundle similar protections with infrastructure that customers already use.

doxx.net must prove that its owned network offers a meaningful enforcement advantage. Privacy claims alone will not settle procurement decisions involving reliability, compliance, and integration.

The company can strengthen its position by publishing clear threat models. Those documents should identify which attacks ADN blocks, which it only detects, and which remain outside its scope.

It can also provide workload-specific templates. A research agent, coding agent, finance agent, and customer-support agent require different destinations, credentials, and approval points.

Templates would convert the broad promise of agentic networking into policies buyers can inspect. They would also reveal whether the system remains manageable across many agents.

The key contest is therefore architectural. Should agent security be added to existing networks, or should agents receive a private network designed around their identities and tasks?

doxx.net funding gives the second approach a substantial test. Open-beta evidence will determine whether it becomes a separate product category or a feature absorbed elsewhere.

Three Signals Will Show Whether Agentic Defined Networking Works

The next stage depends on measurable security outcomes, controlled administration, and real adoption beyond privacy enthusiasts.

The first signal is independent technical validation. doxx.net should publish audits covering DNS protection, token security, certificate handling, routing, and its control plane.

Researchers also need enough methodology to interpret the 38 million blocked-threat claim. False-positive rates, unique destinations, attack categories, and comparison baselines would make the figure useful.

A strong audit would support doxx.net’s argument that its owned infrastructure creates verifiable controls. Serious undisclosed weaknesses would weaken the architecture-first pitch.

The second signal is enterprise-grade policy management. The beta already includes separate read-only and administrative tokens, expiration, revocation, and gateway removal.

The next test is whether teams can apply least privilege across many agents. Least privilege means granting only the access required for a defined task.

Buyers should look for approval workflows, policy versioning, emergency access removal, audit trails, and integrations with established identity systems.

An administrator must also be able to explain why an agent received a route or permission. Agent-created configurations need human-readable records and safe rollback options.

Clear enterprise controls would strengthen the view that agents can help operate networks without controlling their own guardrails. Weak oversight would reproduce the same authority problem ADN claims to address.

The third signal is sustained real-world usage. Beta downloads reveal interest, but recurring agent workloads provide stronger evidence.

Useful indicators include active private networks, connected agents, retained organizations, policy changes, blocked outbound actions, and incident reports. Customer case studies should describe specific workloads rather than general privacy benefits.

A credible case might involve a research agent restricted to approved sources and an internal repository. Another might cover an infrastructure agent that can inspect systems but cannot change routing without approval.

These deployments would test whether network boundaries reduce practical risk without making agents too limited. Security controls fail commercially when users disable them to complete ordinary work.

Developers and enterprise buyers should not wait for one vendor to settle every question. They can begin by mapping each agent’s data, tools, destinations, credentials, and approval requirements.

Knowledge workers should apply the same discipline at a smaller scale. Before delegating research or file operations, identify which information the agent can read and where it can send results.

Teams organizing sensitive source material can also review their searchable knowledge base practices before connecting autonomous tools. Clear information boundaries make agent permissions easier to define.

The $38 million doxx.net funding round does not prove that a parallel private network will contain agent failures. It does show that network enforcement has become a serious part of the agent-security debate.

Watch the audits, administrative controls, and repeat usage. Those signals will show whether Agentic Defined Networking becomes essential infrastructure or remains an ambitious open-beta experiment.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page