While most teenagers were worried about prom and college applications, Devin and Gavin Capriola were worried about something far bigger: stopping the next global AI catastrophe. What started as a side project on how AI agents make decisions, they discovered a flaw that’s been significantly overlooked. They found out that these AI systems would execute nearly anything they were instructed to do, without verifying if the command was legitimate or even safe.
Instead of waiting for someone else to fix it, the brothers created A2SPA (Agent-to-Secure Payload Authorization), a protocol that has already been dubbed the “SSL of AI.” Their solution has gained interest from investors, tech leaders, and defense agencies, with tech enthusiasts viewing it as a cornerstone of a safer AI future.
Devin and Gavin’s journey is even more striking given their background. At just 17, they graduated high school a year early with a 4.7 GPA, logged over 10,000 hours of coding, and earned more than 90 certifications — a rare blend of youth and deep technical fluency that stands out in a space usually dominated by industry veterans.
Business Now caught up with the Capriola brothers to discuss how they turned a late-night discovery into a mission to make AI trustworthy.
BN: Let’s go back to the beginning — was there a specific moment when you both realized this wasn’t just a hobby or interest…but something that could actually shape the future of tech?
Devin & Gavin: At first, we were just building cool stuff because we liked it. But when we saw how AI agents were just blindly running whatever you gave them, no checks, no questions — it felt insane. It was like watching a self-driving car taking directions from anyone shouting at it, without ever checking who’s behind the voice. We knew this was bigger than just building cool stuff. That’s not a side project — that’s a security hole that could mess up everything. We didn’t wait around. We started fixing it.

People are calling A2SPA the “SSL for AI” — that’s a big comparison. In your own words, what does it actually do, and why is this kind of security so critical right now?
A2SPA wraps every AI agent command in cryptographic verification. Just like SSL verifies websites before you trust them with your data, A2SPA verifies who sent the command, what they’re allowed to do, and if it’s been tampered with. Without that layer, agents will run anything — fake commands, jailbroken payloads, malicious prompts. It’s like leaving a loaded weapon on the table with no safety on. We built a secure gate to ensure only trusted commands pass through, and it’s the protection AI needs right now.
You guys were earning certifications, competing globally, and getting noticed by defense agencies — all before most teens get their driver’s license. How did you stay grounded through all that, and what kept you going?
We just liked building. And once we saw how broken AI security was, it became about fixing it. The moment we realized this could be bigger than us was when we realized that AI could soon influence things like finances, healthcare, and even our children’s education. Without proper verification, a single spoofed command could lead to chaos. That’s when we knew we were doing something that mattered.
That Salesforce and HackerOne breach in 2025 was a wake-up call for a lot of people. If A2SPA had been in place, how would things have played out differently? And do you think companies are finally taking AI security seriously?
If A2SPA was in place, those attacks wouldn’t have worked. The spoofed commands wouldn’t pass the check. Companies are waking up now, but most still don’t have real protection — they’re patching stuff after the fact. We built the layer that should’ve been there from the start. This isn’t just about stopping breaches; it’s about stopping catastrophic failures before they happen.
Your dad, Jonathan, clearly played a big role in shaping your entrepreneurial mindset. What’s it like working with him now — and how has his experience helped guide your vision for AI Blockchain Ventures?
He’s been through the startup grind before, so he gets it. He’s always throwing ideas at us and keeping things moving. He taught us the value of thinking long-term and focusing on making an impact, not just making profits.
It’s not just a protocol you’re building — you’re creating a whole ecosystem around secure AI. What’s the bigger picture here? Where do you see AI Blockchain Ventures heading in the next few years?
Yeah, A2SPA is just the start. We’re building wallets, agent marketplaces, finance bots, and more. All powered by secure AI. The big picture? Every person should have their own AI that works like a second brain — and it should be locked down so no one can mess with it. We’re not just securing the future of tech, we’re securing the future of how we live our lives with AI.
You’re up against some of the biggest names in tech — OpenAI, Google, AWS. What gives two brothers from Florida the belief that you can stand toe-to-toe with companies like that?
Because they missed this. They all skipped security. Their agents still run unauthenticated by default. We’re not trying to be them — we’re building what they forgot. Our mission isn’t just about competing; it’s about leading with a security-first mentality.
Watch the video below to see A2SPA in action and how it’s reshaping AI security.
If you could say one thing to every developer or founder building AI tools right now — something they really need to hear — what would that message be?
Never automate without authentication. The risks are too high. The world’s not ready for an AI that doesn’t verify itself.
As the AI industry races ahead, Devin and Gavin Capriola are reminding the world that advancement without protection is a risky gamble. Their goal with A2SPA is simple: to establish confidence in every AI interaction, ensuring that these systems are safe, verified, and trustworthy.

Business Now believes this protocol will not only stop billion-dollar breaches but will also become as essential and ubiquitous as seatbelts in cars or locks on doors. What began as ‘building cool stuff’ has now expanded into a mission to make AI a reliable and secure technology for everyone.
A2SPA offers solutions tailored to different audiences — from everyday users and developers who want their AI agents protected (aimodularity.com/A2SPA) to enterprise companies that need advanced security and compliance (aimodularity.com/A2SPA/enterprise).
For more information, visit: www.aiblockchainventures.com
Follow on LinkedIn: AI Blockchain Ventures