Company
Our mission
We build the control plane that lets agents run infrastructure safely — and forward-deploy it with the startups and institutions that cannot afford to fail.
The challenge
Critical public infrastructure is under real, active threat. The hard part was never building it, it is keeping it resilient when it is being tested by adversaries, scale, and time.
Bugz builds products that combine security architecture, AI-driven operations, and continuous compliance into a single discipline. We design systems that defend themselves, respond at machine speed, and stay audit-ready, so the institutions people depend on do not fail.





Meet the team
The builders
Shekhar Gowda
Founder & Product Engineer
Divakar Prayaga
Mentor & Strategic Advisor
Ankush Ranka
Technical Lead
Sashank Narain, Ph.D.
Product R&D
Mintoy Joy
Brand & Identity
By the numbers
Two years, measured honestly.
2
Years building
50+
Pitches given
8
Industry stages
2
Cohorts completed
2
POCs sunset
Programs & recognition
Guided by Karnataka’s cybersecurity ecosystem
CySecK H.A.C.K
Selected and completed. Karnataka’s flagship cybersecurity acceleration programme, run by the state Centre of Excellence.
T-Hub Rubrix
Selected and completed. A deep-tech programme at India’s leading innovation ecosystem, sharpening go-to-market and product.
CySecK
Karnataka’s K-Tech Centre of Excellence for Cyber Security, hosted at IISc. CySecK guides our research and connects us to the people defending India’s public infrastructure.
IISc
The Indian Institute of Science, India’s premier research institution and host of CySecK. IISc anchors the deep security research that informs how Bugz builds.
T-Hub
India’s pioneering innovation ecosystem and business incubator. T-Hub incubates Bugz, giving us mentorship, resources, and a community of builders.
Where we showed up
In the room, on the stages that matter.
- VulnCon
- BSides Bangalore
- CSA CyBe
- DSCI AISS
- BFI
- Bengaluru Tech Summit
- Nullcon ’25
- CySecK Annual Conference
FAQ
Your questions answered.
What does Bugz actually do?
Bugz sits between AI agents and your cloud. Agents propose changes; every change runs a standard operating procedure, passes compliance checks, and waits for a human approval before it applies. When teams need it shipped fast, we forward-deploy — building, securing and running it with them — most recently a cyber-resilience platform for Karnataka’s government.
Who do you work with?
Platform and security teams putting AI agents into production use the platform. We run cyber resilience for a state government and its digital public infrastructure, guided by CySecK and IISc, and are building our European base in Helsinki.
Are you a services agency or a product company?
A product company. The Bugz platform governs what agents may execute; Bugz Services is our forward-deployed wing — the team builds and ships it with you, which is how we delivered the Karnataka cyber-resilience platform. Engagements harden the product, and the product makes engagements repeatable.
How does an engagement start?
Usually with a scoped agent-readiness assessment for DORA and NIS2 — a fixed-duration diagnostic of which changes your agents can make today with no procedure, no independent approver and no log. From there, a governed-operations engagement puts your agents behind the control plane, under your approvers. We aim to deliver tangible value in weeks, not quarters.
Is our data safe with you?
Yes. We support on-prem and in-VPC deployment, follow zero-trust by default, and never train models on customer data. The security of your environment is the product, not a side effect — nothing leaves your estate without your governance.
Can you deploy sovereignly for government?
Yes. Our Public Sector / Managed engagements are built for sovereign deployment — on-prem or in your VPC — and aligned to CERT-In, RBI, NIST and CIS. The approach is research-led, developed alongside CySecK and IISc.
Build resilient infrastructure with us.
We’re a product company in Bengaluru and Helsinki building the governance layer for agent-run infrastructure — and deploying it forward with the teams who need it.