Most AI tools watch what already happened.
We decide what is allowed to happen — then keep the proof.
Not a breach. A correct-looking system doing a permitted thing, thousands of times, with nothing in the execution path to stop it.
The agent wasn't attacked. The control was missing.
Once before the code ships. Once while the agent runs. Both ends know the same defect by the same name, and write to the same record.
Static analysis that reasons about what agent code actually does — loops without bounds, calls without limits, secrets on the wrong path.
Apache-2.0 · SARIF 2.1.0 · offline by default
Policy in the request path. Every call is checked against what that agent may do — before it executes, not after.
Same defect. Same identity. Same evidence.
You cannot govern AI you cannot inventory. Before anyone says what an agent may not do, someone has to say what agents exist, who owns them, and what they reach.
The system of record for the AI you already have. It sits underneath the two products above.
Not a filter on the output. A permission model on the action — declared per agent, enforced in the request path, before the tool runs.
Approval required is human-in-the-loop as a guardrail — the reviewer sees the action, the arguments, and the policy that stopped it.
One record per decision — what the agent tried, which policy applied, what it cost, and whether the answer held up.
Not a dashboard average. Gated on the weakest dimension — and when the evidence isn't there, it says so instead of producing a number.
Ninety days of production evidence behind every number.
We will not manufacture a number because a dashboard has space for one.
Four questions, in the order a regulated enterprise has to answer them.
Turn production behaviour into governance evidence.
Most enterprises running agents in production are at L0 or L1, and have not been told which.
Nobody has to approve the first one.
Scan your own repository and see what a gate would have stopped. No telemetry, no account.
Bring one live agent. We instrument it, put policy in its request path, and show you the record.
A few design partners are running the Registry against their own repositories. Selective and unpriced.
Going into production, already live, or heading into an audit — start with a conversation. No slideware.