Skip to main content

Security that starts from runtime

To protect something well, you have to know how it behaves. So bifrost starts from runtime and works up: it learns what each workload really does, gives every CVE a verdict against that knowledge, and allows only the behaviour it learned.

Our mission

bifrost prevents breaches of the software companies build and run, from runtime up. It learns what each workload really does, triages every CVE to what actually matters instead of adding to-dos, and allows only the behaviour it learned.

The enemy is the noise machine. Scanners flood teams with findings that carry no runtime context: thousands of CVEs, and no way to tell which ones are dangerous here. Engineers burn weeks triaging vulnerabilities that are never loaded, never reachable, never exploitable, while the few that are sit buried in the same pile.

Runtime is the ground truth that defeats the noise. What a workload actually does when it runs, the syscalls it makes, the files it touches, the connections it opens, is knowable. bifrost observes every workload continuously and turns that observation into two things, in this order. First, verdicts: every CVE is reachable, mitigated by the profile, or never loaded, and what reaches the developer is a short list with the evidence attached. Then hardening: a kernel security profile tailored to each workload, allowing the behaviour it observed and nothing else.

The goal is prevent. Not detect faster, not contain better: keep the breach from happening.

The bifrost difference

Scanners start from the image

They never reach runtime, so every finding arrives without the context that would verdict it.

Detect-and-respond starts at runtime, but only watches

It reports what happened and leaves the acting to you, after the fact.

Manual policy engines start from a rulebook

Someone has to write it, and the rules rot the moment the software changes.

bifrost starts at runtime and builds up: knowledge, verdicts, protection, answers

Verdicts, not findings

What we build by

How we behave while we build bifrost, with each other, with customers and with the public. A value only counts if it costs something.

Behaviour is truth

Trust what runs, not what's promised.

What a system does matters more than what it was designed to do: that is the product's core bet, and it is how we work, settling disagreements with evidence rather than effort or intent.

Strength is subtraction

Build like climbing gear: every part holds weight.

Strength comes from each piece doing its job, in code, documentation, design and email alike, with nothing decorative, nothing bloated and nothing kept just in case.

No single points of failure

Layers, not walls, in systems and in teams.

Security works when several checks overlap at different boundaries, and so do we: share context across roles, review each other's work, keep work visible.

Precision is a kindness

Spend your time to save the reader's.

Vague tickets, sloppy specs and ambiguous emails outsource the thinking to whoever reads them, so clarity is the writer's job, even when it slows the writer down.

Noise is debt

Remove work, don't add it.

bifrost exists because security tools bury people in to-dos that don't matter, so findings ship with a verdict, meetings end with a decision, and alerts come with an action.

Our journey

bifrost has its roots in a joint EU research project bringing together leading European universities and major industry partners. Research into runtime security produced the findings that laid the groundwork for bifrost.

2022

Spun out of Lund University into a standalone company. First patents granted for runtime behavioural profiling methodology.

2023

First prototype deployed in a real environment

2024

Beta release and first customers onboarded

2025

First commercial release. Additional patents granted, bringing total to three granted patents protecting bifrost's core technology.

2026

Expansion across the Nordic region

Our team

The people building bifrost.

Hannes Ullman

Hannes Ullman

Co-Founder & CEO

Serial entrepreneur with 15 years in technology and management consulting.

Konrad Eriksson

Konrad Eriksson

Co-Founder & CTO

Entrepreneur and security researcher with deep expertise in runtime protection and cloud-native security.

Christian Gehrmann

Christian Gehrmann

Co-founder & Head of Research

Professor of Computer Security at Lund University. Pioneering research in runtime behavioural profiling.

Johannes Olsson

Johannes Olsson

Software Engineer

Former consultant with long experience of building scalable software solutions for enterprise customers.

Alexander Bokelund Singh

Alexander Bokelund Singh

Software Engineer

Talented engineer with a knack for building elegant, high-performance software with AI and machine learning components.

Board of directors

Guided by leaders with deep experience in security, technology, and scaling Nordic companies.

Anders Malmström

Anders Malmström

Chairman of the Board

Previously CEO of Foreseeti, AI solution for Cybersecurity (exit to Google 2022).

Stina Slottsjö

Stina Slottsjö

Board Member

Chief Commercial Officer at Telavox, with a long history of B2B sales and marketing.

Kristian Hansson

Kristian Hansson

Board Member

Investor and former Chief Commercial Officer at Foreseeti, with deep experience in scaling Nordic B2B software companies.

Backed by

bifrost is backed by Sweden's innovation agency and Nordic investors who share our vision: a world where breaches of custom software are abnormal.

Vinnova
Sweden's Innovation Agency
LU Ventures
Lund University Investments
Quinary Investment
Nordic Venture Capital
Almi Invest
Sweden's most active early-stage investor

Patented technology

bifrost's behavioural profiling methodology is protected by three granted patents (2022, 2025). Our approach to automated runtime profile generation is built on years of academic research at Lund University.

Built in Sweden

bifrost is a Swedish-developed, Swedish-owned company with offices in Stockholm at Norrsken House and Malmö at MINC. We're proud to be building patented runtime security technology from Sweden, working with Nordic customers in regulated industries.

Our ambition extends beyond the Nordics: prevention, not faster detection, for the software organisations everywhere build and run.

Built for harsh climates.

Join our team

Stockholm

Norrsken House

Birger Jarlsgatan 57C

Malmö

MINC

Anckargripsgatan 3

Meet the team behind bifrost

A 30-minute call with a founder, on your stack and your questions.