Marshall Kiely and Alex Graveley aren't waiting for the cloud wars to settle. The duo—Graveley a self-described co-creator of GitHub Copilot, both with experience at Perplexity—released an open-source runtime last September that lets companies run AI agents on their own servers rather than through third-party platforms.
Their startup, UFO.ai, joined Y Combinator's most recent cohort with a pitch that resonates in an era of mounting enterprise anxiety over data sovereignty: give businesses the tooling to deploy autonomous agents without piping sensitive information through someone else's infrastructure. The runtime, called ufo-core and distributed under an Apache 2.0 license, handles the unglamorous but essential plumbing of agent systems—turn queues, sandboxing, job execution, and crash recovery.
It's a technical play in a market that has grown crowded quickly. OpenAI launched Operator in January 2025, integrating it into ChatGPT's evolving agent capabilities by July. Academic researchers published a handful of arXiv papers sketching out reference architectures for what some call "agent operating systems." Other commercial frameworks emerged around the same time, though exact launch dates and feature sets vary enough to make direct comparisons difficult.
UFO's founders are betting that enterprises will choose control over convenience, at least for certain workloads. Kiely previously handled finance at Perplexity and worked as a founding AI engineer at Notable Health, with an earlier stop in machine learning at Mixpanel, according to the Y Combinator directory. Graveley, who describes himself on his personal site as a co-creator of GitHub Copilot, brings engineering credentials from that project and later contributions to Perplexity's infrastructure.
The software itself operates in two modes. By default, the client runs actions directly on a user's machine in whatever directory the terminal happens to be open. A single flag switches execution to a remote sandbox, with options for Docker or E2B containers when the input can't be trusted. That flexibility comes with trade-offs that the team doesn't try to hide.
A security review published by GreenlitBooks in late September identified execution risks in the default setup. The analysis, which examined a specific commit from that period, found that agents gain read access to the entire host machine and noted the absence of kernel-enforced egress controls. Security researcher Ravi Vale's assessment was blunt: "Only on a throwaway machine, with your own keys and input you trust."

UFO's own documentation acknowledges the tension. The default local sandbox "confines writes with Seatbelt or Landlock, but can read the whole host," the README states plainly. For anything involving untrusted input, the team recommends the more isolated Docker or E2B sandboxes. A separate production-readiness benchmark scored UFO at 85 out of 100 overall, though the security component lagged at 25, citing missing Content-Security-Policy headers and the absence of HTTP Strict Transport Security at the time of measurement.
Under the hood, UFO leans on DBOS-backed workflows to make agent interactions durable across crashes. It supports SQLite for single-server deployments or scales to Postgres, S3, and Redis when needed. An extension system allows teams to plug in custom tools, connectors, model providers, and what the documentation calls "sandbox carriers."
Developers can self-host by running a straightforward setup command to start a local server. Alternatively, a hosted option connects via a terminal client to a UFO-managed workspace. The company's infrastructure relies on AWS and Cloudflare, with AI inference farmed out to OpenRouter, Fireworks AI, and Anthropic. Connectors from Composio and Pipedream round out the stack, while references to Slack integrations and Stripe billing hint at commercial hosted plans in the works.

The company operates under the legal name Metalcraft Inc, with incorporation documents and public code commits appearing in late September. UFO is based in San Francisco, with Garry Tan listed as the primary Y Combinator partner on the accelerator's directory. The founders declined to disclose funding specifics beyond their participation in the program.
What UFO calls an "operating platform for your business" lets teams deploy AI agents that execute commands, read files, and edit documents on member machines or within server-side sandboxes. It positions itself somewhere between the ease of fully managed services and the overhead of building agent infrastructure from scratch.
Whether that middle ground proves durable remains an open question. The agent runtime market is still young enough that competitive dynamics haven't fully crystallized. Microsoft operates an unrelated research project also called UFO, focused on Windows desktop agents, which surfaced in early 2024 and adds a layer of naming confusion to an already noisy space.
For now, UFO.ai is making a calculated wager: that some slice of the enterprise market will value the ability to keep their agent workloads in-house enough to accept the added complexity. The ufo-core repository includes detailed specifications for extensions and sandbox configurations, signaling an intent to build a developer ecosystem rather than just ship a product.
How large that slice turns out to be may determine whether UFO's approach becomes a footnote or a template.
