AI governance

Anyone can add AI.
The hard part is proving you can take it away.

Within a year every function in your business will be running agents that read, decide and act. The question stops being whether you have AI and becomes whether you can govern it: stop it on demand, show what it touched, and keep operating once it is off. This page is the whole argument, and the demo is live. Pull the switch yourself.

Propose
The agent never writes. It proposes, and the engine performs the write through the same rules a person faces. There is no path where a model touches your data directly.
Approve
A human owns anything irreversible. Proposals sit in a review surface with their reasoning and their confidence. Approving is a recorded act with a name on it.
Or kill
One action stops every agent. Platform, module or feature. It fails closed, and the blocked calls leave no trace because they never reached the gateway.
The second demo · pull it yourself

Stop every agent. Then check what it left behind.

This is the question a model-risk examiner actually asks, and most platforms answer it with a policy document. Pull the switch below. The AI rail goes dark, the deterministic floor keeps working, and the AI's trace goes to zero, because the calls never reached the gateway. Shown here as an illustration of the behaviour.

AI rail · live
The AI railkillable
The floorno switch
Deterministic checks. No model, no prompt, no inference.

In the product the switch has three levels, covering the whole platform, one module, or a single feature, and it fails closed: if the switch cannot be read, the answer is no. See how the kill-switch works →

The deterministic floor

The AI was off all night. It still caught everything.

The floor checks coverage, orphaned citations, broken lineage and stale evidence with no model, no prompt and no inference. The same inputs give the same findings every run. There is nothing to hallucinate and nothing to explain to a regulator.

It runs on its own schedule with the AI switched off, and it has no off switch. That is the sentence most platforms cannot say.

See what the floor checks
Runs nightly · AI off
Checksdeterministic, no model
Coveragecontrols with nothing behind them
Lineageregulation to evidence, severed
Stalenessthe day a source stops proving it
Sealedevery finding, into the chain
A floor that can be switched off
is not a floor.
Why this cannot be added later

A model-first platform cannot remove the model and keep working.

The floor never used a model
Switching the AI off does not degrade it, because it never depended on inference in the first place. A platform built model-first has nothing left underneath.
The gateway is the only door
Every model call goes through one chokepoint, which is what makes a switch meaningful. A platform with calls scattered through its codebase can only ask them nicely to stop.
Zero trace is structural
A blocked call never reaches the gateway, so it writes nothing anywhere. That is a property of where the check sits, not a cleanup job that runs afterwards.
It was built before it was required
Provisional patent applications covering the kill-switch cluster were filed before the RBI published its 2026 draft model-risk framework. Filed, not granted. We will not call them more than they are.
The three pieces, in detail

Each of these is a page of its own, because each is a question you will be asked separately.

Design partner programme

Bring us the question your regulator is going to ask.

A small cohort of regulated banks, NBFCs and the firms that own them. Early access, real influence, pricing that holds.

We are pre-launch and we will not dress it up. There are no logos on this page because there are none to show. Come and try to break the chain.