- doxx.net raised $38 million in a Series A led by Andreessen Horowitz and launched an open-beta network built to filter where AI agents can connect.
- The company says agents cannot reliably tell safe actions from unsafe ones while using a person's accounts. Its answer is to control the network around the agent.
- The results so far are the company's own claims. Ask how blocking works, who holds the trust anchors, and whether blocking reaches beyond known and emerging malicious destinations.
An AI agent that books travel or reads your inbox carries your login. It does not carry your judgment. That gap is the problem a new funding round is aimed at, and it shifts the question for security teams. The old question was whether the user would click a bad link. The new one is where the agent is allowed to go at all.
What was announced
SecurityWeek reported that Miami-based doxx.net raised $38 million in a Series A round led by Andreessen Horowitz. Animo Ventures and Focal.vc also took part. Barrett Lyon founded the company in 2025.
The funding came with the open-beta launch of a product called Agentic Defined Networking, or ADN. In SecurityWeek's account, ADN puts an agent on a controlled network with set connections and protection already built in. The goal is to stop agents reaching destinations already known to be malicious as they work for a person online.
The problem it names
SecurityWeek's account of the pitch is blunt. Agents browse, communicate and use services on a person's behalf. They cannot necessarily tell safe information and actions from unsafe ones, yet they work with the user's accounts and authority.
This is the lesson in the announcement. An agent is a new kind of user. It is fast and tireless, and it has no instinct for suspicion. A person might pause at an odd page. An agent that inherits the person's permissions may simply proceed.
How the design works
ADN is described as a parallel, private network for both people and agents. It aims to work without central intermediary servers. The company argues such servers create a single point for interception, can be blocked or censored, and raise the chance an agent lands somewhere malicious.
SecurityWeek lists the main pieces. Devices talk peer to peer, with end-to-end encrypted messages and file transfers. DNS, the system that turns names into addresses, filters out known and emerging malicious destinations before a connection is made. Agents are managed through an API. Native apps cover iOS, macOS and Android, with Windows and Linux support.
The unusual part is how much the company controls. SecurityWeek says customers can run entirely on infrastructure doxx.net owns. That covers its address block and its ASN, the identity that announces those addresses to the internet's routing system. It also covers the root of its naming system, its certificate authority and its physical servers.
Inside a customer's network, some names point to sites the public internet cannot look up. The company says it offers 196 custom top-level domains, the endings that follow the last dot in a web address. Accounts need no username, password or personal data. They are created by proof-of-work, a small computing task.
What the design asks you to trust
Lyon says privacy should come from architecture, not a policy document. He also says the company built the network so it can never see what users search or where they go. These are company statements. SecurityWeek did not report an independent test of them.
There is a tension worth noting. The pitch removes third parties, but customers run on infrastructure doxx.net owns end to end. That includes the certificate authority, which vouches for the identity of the sites a network resolves. Trust does not vanish in this design. It moves to one vendor's root of trust.
The threat figure also needs context. By the company's own count, its closed beta has turned away more than 38 million threats since December 2025. SecurityWeek gives no method, no definition of a threat and no false-positive rate. The figure is a claim, not a measured result.
Questions for your team
This is one vendor's launch. It is not evidence that agent networks are a settled category. It is still a useful prompt for planning.
First, list every agent in your organisation and the accounts each one can use. Treat that list as an access review. Second, ask what limits where those agents can connect today. Check whether the honest answer is nothing beyond the user's own network.
Third, if you evaluate ADN or a rival, ask four things. What counts as a blocked threat? Does blocking reach beyond known and emerging malicious destinations, and what covers a harmless-looking page the agent should not trust? Who operates the certificate authority and the DNS root? Can an outside party test the privacy claims?
An agent with a person's authority needs rules about where it may go, set by the organisation and not left to the agent. The product is new. The need for those rules does not depend on it.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: doxx.net.





