AI governance

Governing a policy is not governing an agent.

Most AI governance platforms document what your company intends to do. Once an agent acts on its own, someone will ask what it actually did — and a policy library cannot answer that.

  • No card to start
  • Nothing is blocked until you say so
  • Your proof stays yours if you leave
The two things sharing one name

One label, two products.

Knowing which one you are shopping for saves a quarter. They are bought by different people, for different questions.

Assurance tooling

Proves your organisation is well run.

Policy libraries, control mapping, vendor questionnaires, evidence collection for SOC 2 and ISO 27001. Bought by security and compliance leads who need a certificate. Vanta, Drata and Sprinto live here.

Answers: is this company trustworthy?

A system of record

Proves what a specific agent did.

Every model call, tool call, decision and approval, written as it happens into a record where a later edit is computable. Bought by whoever has to answer a regulator, an auditor, or a customer's security review. Auditant is this.

Answers: what did it do, and who allowed it?

You may well need both. They are not substitutes, and a vendor who tells you otherwise is selling the one they have.

What to ask a vendor

Five questions that separate them.

Ask these of anyone selling AI governance, including us. The answers sort the category faster than a feature matrix.

What does it govern?
Assurance toolingYour company — its policies, controls, vendors and staff training.
A system of recordYour agents — every action each one takes, one record per action.
When does it act?
Assurance toolingAt audit time, and on a review cycle.
A system of recordBefore the action executes. A rule that runs afterwards is a report.
What does it produce?
Assurance toolingA questionnaire response, a policy library, a certificate.
A system of recordA sealed record of what happened, and a file your auditor checks.
Who has to trust whom?
Assurance toolingThe reader trusts the vendor's export.
A system of recordNobody. The verifier runs offline with no account and nothing from us.
What happens when you leave?
Assurance toolingAccess ends with the subscription.
A system of recordThe format is open and the records still verify without us.
Why now

The dates are already set.

Three jurisdictions want a record of what your agents did, and none of them accept a policy document as one.

  • EU AI Act, Art 12

    Automatic logging over a high-risk system's lifetime

    2 Dec 2027
  • India DPDP Act §8(5)

    Keep personal data safe, and report it when you do not

    13 May 2027
  • Colorado SB 26-189

    Retain records of consequential decisions for three years

    1 Jan 2027

Each is answered from the same record — and it only counts if you were already keeping it when they asked. How the record works →

Asked honestly

What people actually want to know.

Including the one that sometimes costs us the sale: whether you need this at all yet.

01What is an AI governance platform?
Software that keeps a company accountable for what its AI does. In practice the label covers two different products: tools that document your policies and controls so you can pass a certification, and tools that record what your models and agents actually did. Both get called governance. Only the second answers “what did it do on the fourteenth”.
02Do we need one if we already have SOC 2?
SOC 2 says your company runs sound controls. It does not say what your agent did to a particular customer on a particular day, and an examiner asking that question will not accept a certificate as the answer. They are different artefacts for different questions.
03Is this the same as LLM observability?
No. Observability answers “is the model behaving” for engineers, on logs built to be cheap and short-lived. Governance answers “prove what it did, and that nobody edited the record” for the person who signs. Observability logs are usually mutable and expire in weeks; the obligations they would have to satisfy run for years.
04What does the EU AI Act actually require?
Article 12 requires automatic logging over the lifetime of a high-risk system, from 2 December 2027. Article 50 requires telling people they are interacting with a machine, already in force. Article 99 sets penalties at €15M or 3% of worldwide turnover, whichever is higher.
05Can a governance platform stop an action?
Most cannot — they describe after the fact. Enforcement means the rule is evaluated before the action executes, and the refusal is recorded beside it. That is the difference between evidence of control and evidence of activity.
Start

Record it before anyone asks.

Two lines in one agent, free while you evaluate. Or open the demo — it needs no account.

  • No card to start
  • Nothing is blocked until you say so
  • Your proof stays yours if you leave