Governance and trust
Twenty-three policy modules, written as code, switched as an operating control
A financial-institution ruleset, a Turkish personal-data ruleset, and twenty European governance instruments — data protection, the AI Act, network and information security, operational resilience for finance, information-security and AI management standards, digital identity, payments and card data, and more.
Thirteen enforce by default. Seven that carry a real false-positive risk ship switched off, so turning the pack on cannot break production traffic on the day you enable it. That split is the point: a vendor who ships everything default-on has not tested any of it.
Every module ships with its own test module, and the whole suite runs before any rule change is released.
Shadow mode
Run a new rule so its hits are recorded and nothing is blocked. Measure its real false-positive rate on your own traffic, then enforce.
It is also the humane answer to a bad denial: unblock the user in seconds while keeping the evidence.
And if the policy configuration is ever lost, every module enforces. A governance control that fails silently open is worse than none.
What we will not claim
We hold no certifications, and this page will never tell you the product makes you compliant with anything. What it does is map rules to named legal instruments and return the citation inside the denial, so your own reviewer can check the rule against the law without talking to us.
Output scanning flags; it does not block. The bytes have already reached the client by the time a response is scanned, and we would rather say so than sell you a guarantee the architecture cannot make.
The availability posture when the policy engine is unreachable is your choice, set deliberately at install: fail open and record it, or fail closed and refuse. There is no default we would defend for every customer.
Your network stays closed
Inference nodes dial out to the control plane. The platform never needs a route into your network, and adding a node is installing an agent that enrols itself in seconds. Your network engineer can verify this by reading their own firewall rules rather than taking our word for it.
Your documents stay in it
Retrieved document passages are stamped, and a dedicated rule blocks any request carrying that stamp from reaching an external provider. Document context is confined to the capacity you own — enforced, not promised.
Credentials nobody handles
Personal provider keys are validated without spending a token and stored encrypted. Tool-server credentials are injected on the server side, so a client never sees an internal address or a secret. An agent reaching an internal system goes through one credentialed, metered, auditable chokepoint instead of a sprawl of per-desktop configurations with pasted secrets.