Compliance as a byproduct of running the work.
The platform leaves its evidence behind as it runs; there is no separate evidence-assembly step.
Private data never reaches the model. Watch it happen.
One request, end to end: the name is tokenized on your soil, only tokens cross the trust boundary, and what comes back is made whole again on your servers.
Every lane is masked
Connector reads, retrieval, tool inputs and tool outputs all pass the same masking gate as chat before any model sees them. An unknown category fails closed, to masked.
Schema masking, per connector and document
For structured data you can go further: a deterministic masking schema per connector or document type says exactly which fields tokenize. Every declared field tokenizes the same way every time; anything undeclared is masked.
Every job ends in a verified receipt.
A receipt you can check, item by item: the masking count, the human approval, rehydration on-soil, the sealed ledger event, the metered cost.
Masked before any model
The count of items protected, and the plain fact that raw personal data never reached the provider.
Approved, then rehydrated
A person said yes where it mattered; real names were restored only after, only on your servers.
Sealed and metered
A signed event in the append-only ledger, and the per-job cost as metered.
Rehydrated at the gate; the mail left with real names.
A rejected hold NEVER rehydrates.
budget checked before it ran
From the clause to the module that enforces it.
Every governed turn, tool call and decision lands on the append-only ledger; click any row to open the signed receipt it left behind.
sample events, illustrative · your console reports its own live, hash-chained ledger
Events
| Verdict | Time | Agent | Kind | Source | Categories | Masked | Policy |
|---|---|---|---|---|---|---|---|
| 14 masked | 2026-07-16 09:02 | Sales Agent | Governed turn | Teams | PERSONORGFIN-AMOUNT+1 | 14/14 | v7 |
| clean | 2026-07-16 08:57 | Compliance Agent | Policy change | Console | - | - | v7 |
| held | 2026-07-16 08:41 | Finance Agent | Approvals | Console | FIN-AMOUNT | 3/3 | v7 |
| 22 masked | 2026-07-16 07:31 | Chief of Staff | Governed turn | Web chat | PERSONEMAILPHONE | 22/22 | v7 |
| clean | 2026-07-16 06:14 | Marketing Agent | Governed turn | SharePoint | - | - | v7 |
| clean | 2026-07-15 18:22 | Ask Ali | Governed turn | Web chat | - | - | v7 |
| 31 masked | 2026-07-15 16:44 | HR Agent | Governed turn | Word | PERSONEMAILPHONE+1 | 31/31 | v7 |
| 6 masked | 2026-07-15 15:10 | Operations Agent | Tool call | CRM | PERSONEMAIL | 6/6 | v7 |
| clean | 2026-07-15 14:03 | Compliance Agent | Governed turn | Console | - | - | v7 |
| 7 masked | 2026-07-15 11:30 | Project Manager | Governed turn | Teams | PERSON | 7/7 | v7 |
| clean | 2026-07-15 09:05 | Help Desk | Governed turn | Teams | - | - | v7 |
| 18 masked | 2026-07-14 17:20 | Finance Agent | Governed turn | Word | IBANFIN-AMOUNTORG | 18/18 | v7 |
| held | 2026-07-14 12:02 | Sales Agent | Tool call | Outlook | EMAILPERSON | 4/4 | v7 |
| refused | 2026-07-14 10:41 | Compliance Agent | Tool call | Console | - | - | v7 |
| 7 masked | 2026-07-14 09:12 | Operations Agent | Governed turn | Teams | PERSON | 7/7 | v6 |
| clean | 2026-07-13 16:40 | Compliance Agent | Policy change | Console | - | - | v6 |
| clean | 2026-07-13 10:15 | HR Agent | Approvals | Console | EMAILPHONE | 2/2 | v6 |
| 5 masked | 2026-07-12 08:30 | Marketing Agent | Governed turn | SharePoint | PERSONORG | 5/5 | v6 |
Mapped to the frameworks your auditor already knows.
Trace it yourself: pick a law set, then click any law, control, module or proof to light its whole chain across all four columns, both ways.
Trace the framework
Click any node: its whole chain lights across all four columns, both ways.
A focused pack, shaped to the framework that asked.
A regulator does not want a data dump. Pick an agent and a framework and assemble the pack a supervisor actually reads: the system card, the controls trace, the signed event extract, the masking summary. Every claim in it cites a signed event.
Pick a scope and a framework, then assemble the pack. The preview is illustrative; a live console builds it from the signed ledger.
We work the way regulators read.
A supervisor should not wade through raw logs. They get the registry, the risks, and the packs, each row backed by the ledger. Here are the systems we run and the risks we carry, stated plainly.
AI System Registry
The ten agents as registered AI systems: purpose, model routing, data classes, and the human gate.
| System | Purpose | Model routing | Data classes | Human gate | Status |
|---|---|---|---|---|---|
Marketing Agent sys-mkt-01 | Drafts campaigns and posts from approved brand and field sources. | policy-routed: claude-sonnet-5 for long-form, claude-haiku-4.5 default | Public / brand · occasional PERSON, ORG | Outbound publishing held for approval | active |
Sales Agent sys-sales-01 | Researches accounts and drafts outreach before first touch. | policy-routed: claude-sonnet-5 for research, zeroh-ft-3 for alerts | PERSON, ORG, EMAIL, FIN-AMOUNT | Outbound mail held for approval | active |
Finance Agent sys-fin-01 | Reads spend, flags anomalies, drafts variance notes. | policy-routed: claude-haiku-4.5 default, claude-sonnet-5 for narrative | FIN-AMOUNT, IBAN, ORG | Session unmask + posting held for DPO | active |
HR Agent sys-hr-01 | Screens candidates blind and drafts people documents. | policy-routed: claude-sonnet-5 for scoring, claude-haiku-4.5 default | PERSON, EMAIL, PHONE, LOCATION | Unmask + decisions held for People Partner | active |
Operations Agent sys-ops-01 | Keeps CRM clean, captures decisions, preps reviews. | policy-routed: claude-haiku-4.5 default | PERSON, EMAIL, ORG | CRM writes card-approved | active |
Compliance Agent sys-cmp-01 | Assembles proof packs, watches policy, answers the GRC desk. | policy-routed: zeroh-ft-3 for packs, claude-sonnet-5 for consult | Governance metadata · no raw PII | Policy writes versioned, DPO-approved | active |
Help Desk sys-help-01 | Answers handbook and IT questions, grounded on approved corpora. | policy-routed: zeroh-ft-3 default | Handbook / policy · minimal PERSON | Escalations handed to a human | active |
Project Manager sys-pm-01 | Tracks programs, drafts status, surfaces blockers and owners. | policy-routed: claude-haiku-4.5 default | PERSON, ORG · project metadata | Status posts reviewed before send | active |
Chief of Staff sys-cos-01 | Runs morning digests and cross-team synthesis for the executive. | policy-routed: zeroh-ft-3 for digests, claude-sonnet-5 for synthesis | PERSON, EMAIL, PHONE · cross-team | Sensitive summaries held for the sponsor | active |
Ask Ali sys-ali-01 | Grounds Shariah and compliance answers on the governed corpus. | policy-routed: zeroh-ft-3 default, claude-sonnet-5 for long-form | Doctrine / citations · no personal data | Rulings cite sources; disputes escalate | onboarding |
Risk Registry
An honest AI risk register: the two that matter most first, each mitigation backed by a signed event.
| Risk | Likelihood | Impact | Mitigation | Evidence |
|---|---|---|---|---|
AI concentration | High | High | Over-relying on one model or provider is itself a risk. Policy routing spreads jobs across models and providers (claude-haiku-4.5, claude-sonnet-5, gpt-5.4-mini and the tuned zeroh-ft-3), with per-job model economics and no single-model dependency. | Model routing summary · the leaderboard models line · per-turn model on every receipt |
PII shared with AI | High | High | Masking runs on-soil before any model call, so raw personal data never reaches a provider. PII reaches a model only with your explicit approval: session-unmask grants and human gates. | Masking summary · the per-turn masked-before-model receipt · session-unmask approvals record |
Hallucination / ungrounded output | Medium | Medium | Retrieval grounding, refuse-over-guess, and a quality bar the turn must clear before it lands. | Grounded turns cite sources · refusals are their own sealed events |
Prompt injection | Medium | High | Governed tools only, tool allowlists, and an SSRF guard on any web fetch. | Blocked tool calls on the ledger · the gate-refusal control on the receipt |
Data residency | Low | High | On-soil masking and rehydration, per-tenant deployment; rehydration maps live in memory only. | On-soil deployment attestation · the rehydration proofline on every turn |
Runaway cost | Medium | Medium | Soft budgets, per-job metering, and day pools that cap public-desk spend. | Per-job actual cost on every receipt · the spend KPI on the board |
Model drift | Medium | Medium | Eval gates and ratified improvements: a change ships only past the gate. | Eval-loop runs · the skill-promotion events on the ledger |
Vendor lock-in | Low | Medium | Multi-provider routing keeps the work portable across models and providers. | Model routing summary · the multi-provider spread on the board |
Built for the regulator that will ask.
The QCB AI guideline mapped clause-by-clause, with proof packs generated from the live ledger, the kind a regulated bank can file.
Mapped clause-by-clause
The Qatar Central Bank AI guideline traced to controls and the modules that enforce them.
Quarterly proof pack, filed
Regulator-grade, generated from the live ledger, in ISO 42001 / QCB pack formats.
The rulebook tiles
The specific clauses the platform answers to, each backed by a receipt.
Every AI output traceable to a signed record
Human approval before external effect
Model inputs stripped of personal identifiers
Asked before every pilot.
Does the AI provider ever see our personal data?
No. Personal data is masked on your own infrastructure before any model is called: names become reversible placeholders, only the placeholders cross the trust boundary, and the restoration happens back on your servers. An unknown category fails closed, to masked.
What evidence do we get that a job ran the way you claim?
Every turn lands on an append-only, hash-chained audit ledger, and every job ends in a receipt you can check: the masking count, the human approval, rehydration on your soil, the sealed ledger event and the metered cost. An action that cannot be recorded is refused rather than reported as done.
How does this map to the frameworks our auditors ask about?
Proof packs assemble the ledger evidence into framework-shaped exports: ISO 42001, ISO 27001, SOC 2, GDPR and EU AI Act style evidence, produced by normal use rather than by a compliance project.
Where does our data actually live?
On the boundary you choose. On our fleet, your tenant is isolated and your data never mixes with another customer's. On your own Azure subscription, nothing leaves your boundary at all: your Key Vault, your storage, your network, and an audit ledger signed with a key you hold.
Ask the GRC desk about any of this, live.
The Governance, Risk & Compliance desk answers governed, on-soil, right on the homepage.