DevCurationThe Premier Voice of the Entire Tech Ecosystem
Home
Where the Money Moved
News
Events
Investor Spotlight
Company Spotlight
Frameworks
DevCuration
Home
Where the Money Moved
News
Events
Investor Spotlight
Company Spotlight
Frameworks
DevCuration
Latest
POLITICO New York Outlook Puts Affordability on the Agenda|ELC Annual 2026: AI Speed Meets Engineering Accountability|Secure Software Factory Show and Tell: NYC Agent Security|Snowflake x Google Cloud AI Agent Lab Comes to New York|Tech x Market Decoders: Personal AI Agents and Trust|Pitch and Run Monday: NYC Founder Networking, October 12|Connect Ventures Reaches $55M First Close for Fund V|Universal Quantum Raises Over $100M for Modular Computing|Elliott and Siris Explore Potential $2B-Plus Gigamon Sale|Kore.ai Autoloop Targets Verified AI Agent RepairKore.ai Autoloop Targets Verified AI Agent Repair|POLITICO New York Outlook Puts Affordability on the Agenda|ELC Annual 2026: AI Speed Meets Engineering Accountability|Secure Software Factory Show and Tell: NYC Agent Security|Snowflake x Google Cloud AI Agent Lab Comes to New York|Tech x Market Decoders: Personal AI Agents and Trust|Pitch and Run Monday: NYC Founder Networking, October 12|Connect Ventures Reaches $55M First Close for Fund V|Universal Quantum Raises Over $100M for Modular Computing|Elliott and Siris Explore Potential $2B-Plus Gigamon Sale|Kore.ai Autoloop Targets Verified AI Agent RepairKore.ai Autoloop Targets Verified AI Agent Repair
DevCuration

The premier voice of the tech ecosystem, from ideation to enterprise.

Explore

  • Where the Money Moved
  • Events
  • Articles & Analysis

Spotlights

  • Investor Spotlight
  • Company Spotlight
  • Frameworks

Company

  • About Us
  • Privacy Policy
  • Terms of Service
© 2026 DevCuration. All rights reserved.
TwitterLinkedIn
Logos provided by Logo.dev
Back to Events
Panel

Secure Software Factory Show and Tell: NYC Agent Security

Keycard, Braintrust, Socket and Docker DevRel will host Secure Software Factory Show and Tell on October 13, 2026, from 5:30–8:30 PM EDT at Elsie Rooftop in New York. The panel and planned live demonstrations focus on securing software workflows operated by AI agents. Registration is free and requires host approval, with doors opening at 5:30 PM at 1412 Broadway, New York, NY 10018.

The gathering puts an operational question in front of the people building those workflows: how does responsibility travel with an agent as it moves between tools? Runtime authorization, isolated execution, behavioral evidence and component checks each carry part of the answer. For engineering and security owners, the interesting territory is where one control hands the job to another, especially when a system needs to be stopped.

What the software factory program puts on display

The advertised demonstrations divide the work into recognizable responsibilities. Keycard plans to cover discovery, runtime authorization scoped to a task, and response to a rogue agent; Docker will address execution constraints, Braintrust will examine behavior and drift, and Socket will address component validation. The program gives attendees a way to inspect how those responsibilities fit around an agent that produces software.

Consider an engineering team deciding which tools a coding agent may use. Someone has to define the task, someone has to grant access, and someone has to explain the resulting activity. An environment boundary and an authorization decision serve different purposes. A trace adds another perspective, but the team still needs to understand which action the evidence describes and who was allowed to initiate it.

That is the conversation to take into a demonstration. Ask where the boundary is enforced, what information travels through it, and what remains visible after the agent finishes. A convincing answer should make the ownership of the next step easier to understand. These are editorial questions for attendees, rather than promises that every demonstration will resolve them.

The panel-to-demo format is useful because an implementation can expose assumptions that a broad discussion leaves floating. A security owner and a platform engineer may agree on the word “authorized” while expecting different evidence behind it. Watching the same operation gives them something concrete to discuss, including the parts of a workflow that their respective teams need to review together.

Agent Baseline gives the room a shared starting point

The event draws on Agent Baseline, an open-source reference framework currently labeled v1.0-draft. Its six outcomes cover discovering agents, constraining their reach, authorizing actions, observing activity, validating systems and responding to incidents. Published July 30, 2026, the framework remains a working draft; its presence in the program should be understood as an organizing approach rather than a certification.

The framework's value for this discussion is the breadth of the responsibility it names. An agent inventory helps an organization understand what is operating, while limits and authorization define what an agent can do. Observation, validation and response ask how teams will evaluate behavior and act when it crosses a boundary. Those responsibilities can sit with different owners even inside the same company.

For an operator, the practical exercise is to follow a task through those owners. Which team can explain the permitted access? Which team can connect an action to its result? Which team can remove authority and preserve the evidence? A draft framework provides a common set of questions, while each organization still has to establish the answers in its own environment.

The demonstrations also sit beside the vendors' stated product areas. Docker offers secure agent sandboxes, Braintrust focuses on agent observability and evaluations, and Socket addresses malicious software dependencies. Keycard describes runtime authorization for agents. Taken together, those perspectives make the boundaries between product responsibilities worth examining; the event has yet to demonstrate how any particular deployment will perform.

The listed panel spans identity and operational controls

The current organizer program lists Dick Hardt, founder of AAuth; Ian Livingstone, Keycard co-founder and CEO; Ahmad Nassri, Socket CTO; Zachary Hamilton, Braintrust solutions engineer; and Eli Aleyner, Docker VP Product Strategy. Allie Howe, host of the Insecure Agents podcast, is scheduled to moderate. These are forthcoming program participants, with the organizer's listing controlling any subsequent changes.

Dick Hardt's standards background gives the identity discussion a useful anchor: RFC 6749 identifies Dick Hardt as editor of the OAuth 2.0 authorization framework. The connection matters because delegated access has a long technical history. An agent-operated workflow gives the audience a concrete setting in which to ask how identity and permitted action relate across a sequence of tools.

The other listed roles bring the product and implementation responsibilities into the same conversation. Executives can explain intended boundaries and product choices; an implementation practitioner can help surface the questions a team encounters while trying to make behavior visible. The role descriptions support that range of perspectives without establishing what any individual will say on the night.

Attendees can make the exchange more useful by bringing a specific operating question. A platform owner might ask about runtime isolation, while a security lead might ask about access revocation or an investigation record. A technical founder might ask which responsibility stays with the buyer. Those are different entry points into the same workflow, and the panel gives them a place to meet before the demos begin.

Why the New York timing sharpens the discussion

The gathering appears on the official side-event schedule for AI Engineer New York 2026, which runs October 12–14 and focuses on production AI across financial services. Readers following DevCuration's Events coverage can place this gathering beside the wider conference program. It brings the discussion of agent-operated development close to an audience already considering how AI systems behave inside working institutions.

For that audience, an agent's useful output is one piece of the operating decision. A team also needs a clear account of the access involved, the actions taken and the recovery path available. The show-and-tell format invites a more tangible conversation about those responsibilities than an abstract promise of autonomy. Its usefulness will depend on the questions participants can connect to their own systems.

Elsie Rooftop offers a setting for continuing those questions after the formal program. The approval-required registration gives organizers control over admission, but the public listing establishes no guaranteed introductions, investor access or business return. Engineers, security leaders and technical operators can evaluate the program on its verified subject matter and follow the organizer's registration instructions for attendance.

The work waiting back at the office will still involve several people: the owner of the runtime, the person granting credentials, and the colleague who needs an intelligible record when something goes wrong. October 13 gives those responsibilities a shared demonstration to examine. The useful conversation can continue around the exact point where an agent's authority ends and a human team has to decide what evidence is enough for the next task.

Frequently Asked Questions

Why do controls around a coding agent need to work together?

An agent-operated software task can involve credentials, an execution environment, tool calls and dependencies. The event brings runtime authorization, execution constraints, observation and component validation into one program, giving operators a setting to examine the handoffs between those responsibilities.

Which operators would find the program relevant?

Platform engineers, security leaders, AI engineers and technical founders responsible for agent workflows can connect the panel and demonstrations to their own access and recovery questions. No particular attendee roster, introduction or business outcome is guaranteed.

Is Agent Baseline a completed security standard?

Agent Baseline is an open-source reference framework currently labeled v1.0-draft. Its six outcomes cover discovery, constraints, authorization, observation, validation and response; it is not presented here as a certification or regulation.

What should attendees know about registration and arrival?

The current official listing gives October 13, 2026, 5:30–8:30 PM EDT, at Elsie Rooftop, 1412 Broadway, New York, NY 10018. Doors open at 5:30 PM. Registration through the official Luma page is free and requires host approval; consult the organizer for program updates.

What questions should a team take into the planned demos?

Ask where authority is enforced, which identity follows an action, what evidence connects a request to its result, and how execution can be stopped. These are editorial suggestions for examining the control handoffs, rather than promises of specific answers from the speakers.

Event Details

  • Date
    Tuesday, October 13, 2026
  • Time
    5:30–8:30 PM EDT; doors open 5:30 PM
  • Location
    Elsie Rooftop, New York, NY
    1412 Broadway, New York, NY, 10018
  • Hosted by
    • Keycard · Keycard
    • Braintrust · Braintrust
    • Socket · Socket
    • Docker DevRel · Docker DevRel
    • Allie Howe · Moderator; Host at Insecure Agents
Register

Speakers (5)

Dick Hardt

Founder, AAuth

Ian Livingstone

Co-Founder and CEO, Keycard

Ahmad Nassri

CTO, Socket

Zachary Hamilton

Solutions Engineer, Braintrust

Eli Aleyner

VP Product Strategy, Docker

Upcoming Events

May 14
PMAI AI Demo: Founders Ask Turns AI Week New York Into a Live Strategy Room
New York, NY
May 14
Metronome and Stripe Put the Future of AI Monetization on the Table in May 14 Webinar
May 15
Pulse NYC and Abhijit Patharkar Position Claude Deployment as the Next Enterprise Infrastructure Shift
May 15
AI Week New York: Peter Corbett and Pulse NYC Bring Founder Performance Into the AI Conversation
New York, NY
View all events
Back to all events