Safely release AI applications and agents
A release gate that derives its own verdict from evaluation evidence, and a shadow mode that shows what enforcement would have done before you switch it on.
AI SECURITY AND GOVERNANCE PLATFORM
Secure every AI interaction — from model request to agent action — with enforceable policy and audit-ready evidence.
Register AI systems, enforce policy across prompts and agent actions, and produce runtime evidence from one control plane.
“Find the account profile for jane.doe@enterprise.com and card 4242-xxxx-xxxx-1234”
[REDACTED_EMAIL], [REDACTED_CARD]
audit_7b92…e41f
Sub-millisecond regex & JSON schema checks with negligible latency in the critical path.
Auditable, verifiable rule engines with zero model hallucinations in security enforcement.
Cryptographically linked records per tenant, exportable in CEF and JSONL to Splunk and Sentinel.
Route OpenAI, LangChain, or Anthropic clients by modifying the base URL alone.
WHAT YOU GET
Every outcome below is enforced in the request path and recorded as evidence. Nothing here is a report written after the fact.
A release gate that derives its own verdict from evaluation evidence, and a shadow mode that shows what enforcement would have done before you switch it on.
Sensitive values are detected and redacted in the request path, before they reach a model or return to a user.
Tools run only against a declared schema, and high-risk ones wait for a human who is not the requester.
Policy is resolved from risk tier and tenant configuration rather than written per system, and evidence is produced as a by-product of running.
Every decision is append-only and hash-chained, so an altered or missing record is detectable rather than deniable.
ONE CONTROL PLANE
Governance stays attached to the system, the policy, the model request, the agent action, and the release decision — not scattered across point tools.
Inventory systems, owners, models, data classes, tools, and jurisdictions.
Resolve controls from risk tier, organization configuration, and enforcement mode.
Measure detector coverage and stop unqualified releases from reaching production.
Inspect prompts, responses, context, and tool calls in the request path.
Persist append-only decisions and export evidence to enterprise security systems.
RUNTIME CONTROLS
gardai labs runs the controls attached to each system and records what happened — whether the request was observed, redacted, blocked, or held for approval. Detectors are deterministic and inspectable, and every one is replaceable with your own.
Open gateway lab →Deterministic detection and redaction of supported PII, payment and secret patterns, applied before a value reaches a model or a user.
Prompts are normalised against invisible-character and homoglyph evasion, then inspected for instruction-override attempts.
Tool allow-lists, JSON Schema contracts and approval-bound arguments, checked before a call is made.
What a tool or MCP server returns is checked for instructions aimed at the model and for sensitive values, before it enters the context.
RAG responses are measured against the supplied context and the tenant's own threshold.
Require server-derived evaluation results before a governed system is promoted.
Policy version, every detector verdict, the action taken and its latency — append-only, hash-chained per tenant, exportable as CEF or JSONL.
CAPABILITY MAP
A platform that tells you what your AI is doing should be exact about what it does itself. Everything marked available is enforced in the request path now and recorded as evidence; nothing below is inferred from a label.
High-risk tools wait for a person who is not the requester. Approvals bind to the exact arguments, expire, cannot be decided twice, and notify everyone holding the permission to clear them.
Tools run only if declared, and arguments are validated against a JSON Schema contract before a model is reached.
Append-only, hash-chained per tenant, anchored externally, and delivered through a durable outbox as CEF or JSONL — the format Splunk and Sentinel ingest today.
Private cloud, on-premises, and gateway/API deployment ship as Docker images, Kubernetes manifests and AWS Terraform. The tenancy model is proven to a hundred organizations on one deployment.
Posture score, risk distribution and governance-gate readiness are live. Blocked-attack trends, unresolved-risk ageing and policy-coverage rollups are being added.
Any SIEM that accepts CEF or JSONL over a webhook works now. Named connectors for ServiceNow and Jira ticketing are in progress.
Tool authorization, argument validation and malicious tool-response detection are enforced in the request path — a tool result carrying instructions for the model, or sensitive values on the way back, is caught before the model reads it. Inspecting MCP calls themselves and per-server permission control are still to come.
An attack corpus covering injection, jailbreak, data leakage, excessive agency, unsafe tool execution and indirect injection runs against a system's own resolved controls, and the campaign is recorded in the audit chain. Runs on demand today; scheduled continuous campaigns are next.
Systems come under governance by being registered. Automatically identifying models, agents, RAG applications, data sources and MCP servers is not something gardai labs does yet.
Evidence is complete and exportable, but mapping it to NIST AI RMF, ISO 42001, OWASP LLM Top 10 and the EU AI Act is still manual.
DEPLOY YOUR WAY
Run gardai labs beside the applications it protects. Keep model traffic and governance evidence within infrastructure you operate.
Web apps, autonomous agents, RAG services & microservices
Deterministic inspection, active policy enforcement & append-only cryptographic evidence.
Cloud and self-hosted model backends
from openai import OpenAI
import os
# Point your existing client to gardai labs reverse proxy:
client = OpenAI(
base_url="https://gateway.gardailabs.internal/v1", # 1-line integration
api_key=os.environ["GARDAI_API_KEY"],
)
# Prompts, tools, and responses are inspected and governed in real time:
response = client.chat.completions.create(
model="gpt-4o",
messages=[{"role": "user", "content": "Find account profile"}],
)
# Returns sanitized response + cryptographically signed audit evidence.
OIDC verification, role-based permissions, organization boundaries, and scoped runtime access.
Structured logs, OpenTelemetry traces, dependency readiness, and SIEM-compatible exports.
Python service, PostgreSQL persistence, Docker packaging, Kubernetes manifests, and three SDKs.
START WITH VISIBILITY
Start in shadow mode. Enforce when the evidence says you should.