AI can already suggest security patches, but nobody proves they work before they ship. The Frontier AI cybersecurity survey (arXiv:2504.05408) found zero systems for remediation deployment. CloseLoop fills that gap: Find → Fix → Prove → Ship.
How it works: a scanner or red-team agent posts a finding to CloseLoop's handoff API. OpenAI generates a least-privilege patch, which runs through an offline check (up to 3 retries). A Guild AI reviewer agent approves or rejects it. Approved patches are applied to a live lab on Akash, and CloseLoop replays the real exploit: it must succeed before the fix and be blocked after, while canary and app health checks stay green. If anything breaks, it rolls back automatically. Verified fixes ship as a GitHub PR that changes only the affected policy line, with the before/after evidence attached.
Tech: OpenAI for patch generation; Guild AI as the independent reviewer agent; Akash to host the live target environment and apply changes via its Console API; ClickHouse to record every pipeline event and evidence trail; GitHub for automated PR shipping. Built with Next.js and TypeScript, 56 tests passing.
Results: 4 verified end-to-end runs, each opening a real infra PR, plus a passing rollback test. The recorded run went from finding to verified fix in 1 minute 38 seconds.