Compliance as a byproduct of running the work.
You do not run the platform and then assemble evidence. The evidence is what the platform leaves behind.
Private data never reaches the model. Watch it happen.
One request, end to end: the name is tokenized on your soil, only tokens cross the trust boundary, and what comes back is made whole again on your servers.
Every lane is masked
Not just chat: connector reads, retrieval, tool inputs and tool outputs all pass the same masking gate before any model sees them. An unknown category fails closed, to masked.
Schema masking, per connector and document
For structured data you can go further: a deterministic masking schema per connector or document type says exactly which fields tokenize, every time. 100 percent data control, by construction.
Every job ends in a verified receipt.
Not a log line you have to trust, but a receipt you can check: the masking count, the human approval, rehydration on-soil, the sealed ledger event, the metered cost.
Masked before any model
The count of items protected, and the plain fact that raw personal data never reached the provider.
Approved, then rehydrated
A person said yes where it mattered; real names were restored only after, only on your servers.
Sealed and metered
A signed event in the append-only ledger, and the per-job actual cost, never an estimate.
Rehydrated at the gate; the mail left with real names.
A rejected hold NEVER rehydrates.
budget checked before it ran
Mapped to the frameworks your auditor already knows.
Trace it yourself: pick a law set, then click any law, control, module or proof to light its whole chain across all four columns, both ways.
Trace the framework
Click any node: its whole chain lights across all four columns, both ways.
From the clause to the module that enforces it.
Every governed turn, tool call and decision lands on the append-only ledger; click any row to open the signed receipt it left behind.
sample events, illustrative · your console reports its own live, hash-chained ledger
Events
| Verdict | Time | Agent | Kind | Source | Categories | Masked | Policy |
|---|---|---|---|---|---|---|---|
| 14 masked | 2026-07-16 09:02 | Sales Agent | Governed turn | Teams | PERSONORGFIN-AMOUNT+1 | 14/14 | v7 |
| clean | 2026-07-16 08:57 | Compliance Agent | Policy change | Console | - | - | v7 |
| held | 2026-07-16 08:41 | Finance Agent | Approvals | Console | FIN-AMOUNT | 3/3 | v7 |
| 22 masked | 2026-07-16 07:31 | Chief of Staff | Governed turn | Web chat | PERSONEMAILPHONE | 22/22 | v7 |
| clean | 2026-07-16 06:14 | Marketing Agent | Governed turn | SharePoint | - | - | v7 |
| clean | 2026-07-15 18:22 | Ask Ali | Governed turn | Web chat | - | - | v7 |
| 31 masked | 2026-07-15 16:44 | HR Agent | Governed turn | Word | PERSONEMAILPHONE+1 | 31/31 | v7 |
| 6 masked | 2026-07-15 15:10 | Operations Agent | Tool call | CRM | PERSONEMAIL | 6/6 | v7 |
| clean | 2026-07-15 14:03 | Compliance Agent | Governed turn | Console | - | - | v7 |
| 7 masked | 2026-07-15 11:30 | Project Manager | Governed turn | Teams | PERSON | 7/7 | v7 |
| clean | 2026-07-15 09:05 | Help Desk | Governed turn | Teams | - | - | v7 |
| 18 masked | 2026-07-14 17:20 | Finance Agent | Governed turn | Word | IBANFIN-AMOUNTORG | 18/18 | v7 |
| held | 2026-07-14 12:02 | Sales Agent | Tool call | Outlook | EMAILPERSON | 4/4 | v7 |
| refused | 2026-07-14 10:41 | Compliance Agent | Tool call | Console | - | - | v7 |
| 7 masked | 2026-07-14 09:12 | Operations Agent | Governed turn | Teams | PERSON | 7/7 | v6 |
| clean | 2026-07-13 16:40 | Compliance Agent | Policy change | Console | - | - | v6 |
| clean | 2026-07-13 10:15 | HR Agent | Approvals | Console | EMAILPHONE | 2/2 | v6 |
| 5 masked | 2026-07-12 08:30 | Marketing Agent | Governed turn | SharePoint | PERSONORG | 5/5 | v6 |
A focused pack, shaped to the framework that asked.
A regulator does not want a data dump. Pick an agent and a framework and assemble the pack a supervisor actually reads: the system card, the controls trace, the signed event extract, the masking summary. Every claim in it cites a signed event.
Pick a scope and a framework, then assemble the pack. The preview is illustrative; a live console builds it from the signed ledger.
We work the way regulators read.
A supervisor should not wade through raw logs. They get the registry, the risks, and the packs, each row backed by the ledger. Here are the systems we run and the risks we carry, stated plainly.
AI System Registry
The ten agents as registered AI systems: purpose, model routing, data classes, and the human gate.
| System | Purpose | Model routing | Data classes | Human gate | Status |
|---|---|---|---|---|---|
Marketing Agent sys-mkt-01 | Drafts campaigns and posts from approved brand and field sources. | policy-routed: claude-sonnet-5 for long-form, claude-haiku-4.5 default | Public / brand · occasional PERSON, ORG | Outbound publishing held for approval | active |
Sales Agent sys-sales-01 | Researches accounts and drafts outreach before first touch. | policy-routed: claude-sonnet-5 for research, zeroh-ft-3 for alerts | PERSON, ORG, EMAIL, FIN-AMOUNT | Outbound mail held for approval | active |
Finance Agent sys-fin-01 | Reads spend, flags anomalies, drafts variance notes. | policy-routed: claude-haiku-4.5 default, claude-sonnet-5 for narrative | FIN-AMOUNT, IBAN, ORG | Session unmask + posting held for DPO | active |
HR Agent sys-hr-01 | Screens candidates blind and drafts people documents. | policy-routed: claude-sonnet-5 for scoring, claude-haiku-4.5 default | PERSON, EMAIL, PHONE, LOCATION | Unmask + decisions held for People Partner | active |
Operations Agent sys-ops-01 | Keeps CRM clean, captures decisions, preps reviews. | policy-routed: claude-haiku-4.5 default | PERSON, EMAIL, ORG | CRM writes card-approved | active |
Compliance Agent sys-cmp-01 | Assembles proof packs, watches policy, answers the GRC desk. | policy-routed: zeroh-ft-3 for packs, claude-sonnet-5 for consult | Governance metadata · no raw PII | Policy writes versioned, DPO-approved | active |
Help Desk sys-help-01 | Answers handbook and IT questions, grounded on approved corpora. | policy-routed: zeroh-ft-3 default | Handbook / policy · minimal PERSON | Escalations handed to a human | active |
Project Manager sys-pm-01 | Tracks programs, drafts status, surfaces blockers and owners. | policy-routed: claude-haiku-4.5 default | PERSON, ORG · project metadata | Status posts reviewed before send | active |
Chief of Staff sys-cos-01 | Runs morning digests and cross-team synthesis for the executive. | policy-routed: zeroh-ft-3 for digests, claude-sonnet-5 for synthesis | PERSON, EMAIL, PHONE · cross-team | Sensitive summaries held for the sponsor | active |
Ask Ali sys-ali-01 | Grounds Shariah and compliance answers on the governed corpus. | policy-routed: zeroh-ft-3 default, claude-sonnet-5 for long-form | Doctrine / citations · no personal data | Rulings cite sources; disputes escalate | onboarding |
Risk Registry
An honest AI risk register: the two that matter most first, each mitigation backed by a signed event.
| Risk | Likelihood | Impact | Mitigation | Evidence |
|---|---|---|---|---|
AI concentration | High | High | Over-relying on one model or provider is itself a risk. Policy routing spreads jobs across models and providers (claude-haiku-4.5, claude-sonnet-5, gpt-5.4-mini and the tuned zeroh-ft-3), with per-job model economics and no single-model dependency. | Model routing summary · the leaderboard models line · per-turn model on every receipt |
PII shared with AI | High | High | Masking runs on-soil before any model call, so raw personal data never reaches a provider. PII reaches a model only with your explicit approval: session-unmask grants and human gates. | Masking summary · the per-turn masked-before-model receipt · session-unmask approvals record |
Hallucination / ungrounded output | Medium | Medium | Retrieval grounding, refuse-over-guess, and a quality bar the turn must clear before it lands. | Grounded turns cite sources · refusals are their own sealed events |
Prompt injection | Medium | High | Governed tools only, tool allowlists, and an SSRF guard on any web fetch. | Blocked tool calls on the ledger · the gate-refusal control on the receipt |
Data residency | Low | High | On-soil masking and rehydration, per-tenant deployment; rehydration maps live in memory only. | On-soil deployment attestation · the rehydration proofline on every turn |
Runaway cost | Medium | Medium | Soft budgets, per-job metering, and day pools that cap public-desk spend. | Per-job actual cost on every receipt · the spend KPI on the board |
Model drift | Medium | Medium | Eval gates and ratified improvements: a change ships only past the gate. | Eval-loop runs · the skill-promotion events on the ledger |
Vendor lock-in | Low | Medium | Multi-provider routing keeps the work portable across models and providers. | Model routing summary · the multi-provider spread on the board |
Built for the regulator that will ask.
The QCB AI guideline mapped clause-by-clause, with proof packs generated from the live ledger, the kind a regulated bank can file.
Mapped clause-by-clause
The Qatar Central Bank AI guideline traced to controls and the modules that enforce them.
Quarterly proof pack, filed
Regulator-grade, generated from the live ledger, in ISO 42001 / QCB pack formats.
The rulebook tiles
The specific clauses the platform answers to, each backed by a receipt.
Every AI output traceable to a signed record
Human approval before external effect
Model inputs stripped of personal identifiers
Ask the GRC desk about any of this, live.
The Governance, Risk & Compliance desk answers governed, on-soil, right on the homepage.