Security that starts from runtime
To protect something well, you have to know how it behaves. So bifrost starts from runtime and works up: it learns what each workload really does, gives every CVE a verdict against that knowledge, and allows only the behaviour it learned.
Our mission
bifrost prevents breaches of the software companies build and run, from runtime up. It learns what each workload really does, triages every CVE to what actually matters instead of adding to-dos, and allows only the behaviour it learned.
The enemy is the noise machine. Scanners flood teams with findings that carry no runtime context: thousands of CVEs, and no way to tell which ones are dangerous here. Engineers burn weeks triaging vulnerabilities that are never loaded, never reachable, never exploitable, while the few that are sit buried in the same pile.
Runtime is the ground truth that defeats the noise. What a workload actually does when it runs, the syscalls it makes, the files it touches, the connections it opens, is knowable. bifrost observes every workload continuously and turns that observation into two things, in this order. First, verdicts: every CVE is reachable, mitigated by the profile, or never loaded, and what reaches the developer is a short list with the evidence attached. Then hardening: a kernel security profile tailored to each workload, allowing the behaviour it observed and nothing else.
The goal is prevent. Not detect faster, not contain better: keep the breach from happening.
The bifrost difference
Scanners start from the image
They never reach runtime, so every finding arrives without the context that would verdict it.
Detect-and-respond starts at runtime, but only watches
It reports what happened and leaves the acting to you, after the fact.
Manual policy engines start from a rulebook
Someone has to write it, and the rules rot the moment the software changes.
bifrost starts at runtime and builds up: knowledge, verdicts, protection, answers
Verdicts, not findings
What we build by
How we behave while we build bifrost, with each other, with customers and with the public. A value only counts if it costs something.
Behaviour is truth
Trust what runs, not what's promised.
What a system does matters more than what it was designed to do: that is the product's core bet, and it is how we work, settling disagreements with evidence rather than effort or intent.
Strength is subtraction
Build like climbing gear: every part holds weight.
Strength comes from each piece doing its job, in code, documentation, design and email alike, with nothing decorative, nothing bloated and nothing kept just in case.
No single points of failure
Layers, not walls, in systems and in teams.
Security works when several checks overlap at different boundaries, and so do we: share context across roles, review each other's work, keep work visible.
Precision is a kindness
Spend your time to save the reader's.
Vague tickets, sloppy specs and ambiguous emails outsource the thinking to whoever reads them, so clarity is the writer's job, even when it slows the writer down.
Noise is debt
Remove work, don't add it.
bifrost exists because security tools bury people in to-dos that don't matter, so findings ship with a verdict, meetings end with a decision, and alerts come with an action.
Our journey
bifrost has its roots in a joint EU research project bringing together leading European universities and major industry partners. Research into runtime security produced the findings that laid the groundwork for bifrost.
2022
Spun out of Lund University into a standalone company. First patents granted for runtime behavioural profiling methodology.
2023
First prototype deployed in a real environment
2024
Beta release and first customers onboarded
2025
First commercial release. Additional patents granted, bringing total to three granted patents protecting bifrost's core technology.
2026
Expansion across the Nordic region
Our team
The people building bifrost.

Hannes Ullman
Co-Founder & CEO
Serial entrepreneur with 15 years in technology and management consulting.

Konrad Eriksson
Co-Founder & CTO
Entrepreneur and security researcher with deep expertise in runtime protection and cloud-native security.

Christian Gehrmann
Co-founder & Head of Research
Professor of Computer Security at Lund University. Pioneering research in runtime behavioural profiling.

Johannes Olsson
Software Engineer
Former consultant with long experience of building scalable software solutions for enterprise customers.

Alexander Bokelund Singh
Software Engineer
Talented engineer with a knack for building elegant, high-performance software with AI and machine learning components.
Board of directors
Guided by leaders with deep experience in security, technology, and scaling Nordic companies.

Anders Malmström
Chairman of the Board
Previously CEO of Foreseeti, AI solution for Cybersecurity (exit to Google 2022).

Stina Slottsjö
Board Member
Chief Commercial Officer at Telavox, with a long history of B2B sales and marketing.

Kristian Hansson
Board Member
Investor and former Chief Commercial Officer at Foreseeti, with deep experience in scaling Nordic B2B software companies.
Backed by
bifrost is backed by Sweden's innovation agency and Nordic investors who share our vision: a world where breaches of custom software are abnormal.




Patented technology
bifrost's behavioural profiling methodology is protected by three granted patents (2022, 2025). Our approach to automated runtime profile generation is built on years of academic research at Lund University.
Built in Sweden
bifrost is a Swedish-developed, Swedish-owned company with offices in Stockholm at Norrsken House and Malmö at MINC. We're proud to be building patented runtime security technology from Sweden, working with Nordic customers in regulated industries.
Our ambition extends beyond the Nordics: prevention, not faster detection, for the software organisations everywhere build and run.
Built for harsh climates.
Join our teamStockholm
Norrsken House
Birger Jarlsgatan 57C
Malmö
MINC
Anckargripsgatan 3
Meet the team behind bifrost
A 30-minute call with a founder, on your stack and your questions.