A tribe of builders, hackers, and OSS maintainers united by a single question: What if we could know what code actually does when it runs?
Our DNA comes from developer experience, low-level systems, and observability infrastructure—the kind of work where you're accountable for what ships in other people's production paths. We've built, maintained, and contributed to much of what the industry runs on today: Tracee, Tetragon, Fluent Bit, systemd, and nmap. That's the through-line we bring to Garnet.
Garnet was born from hard lessons. At their previous AI infrastructure startup, Umar and Farrukh faced every founder's nightmare: a cryptominer infiltrated production through a compromised Python dependency—running undetected for weeks in a customer's environment.
While we had static and vulnerability scanners, we were running blind to what was actually running. With an early glimpse of what the future of supply chain attacks would look like, one thing became clear: you can't trust code if you can't see it at runtime. This became the spark for Garnet.
We're building the trust layer for modern software —with a vision to combine best-in-class infrastructure, intelligence, and a lovable developer experience—so teams at the frontier have the visibility and control to ship with confidence.


































One edit to your existing workflow file. Get your first run profile on the next push.