Govern
Policy runs inline on governed inference, tool calls, and agent actions. Blocks and redactions happen before completion.
Runtime assurance
Glacis governs your AI agents in the path of action and seals evidence of every governed call. When a customer, auditor, or board asks “How do you know?”, you can answer without sending us your data.
Evidence is signed today. Independent witnessing is next. This sentence changes when that ships.
Our own agents run governed, including the ones that shipped this page. No reports written. No evidence filed. The record follows the work.
1M+signed evidence records from governing our own AI agents
A published lower bound, not a simulated live counter.
The audit log says a human approved it. The human never saw it.
“The model has not changed since the evaluation.” It has changed four times.
Somewhere between demo and deployment, a guardrail was switched off and never switched back on.
Boilers got inspection plates. Aviation got black boxes. Once failure became answerable, entire industries became buildable.
Glacis sits where AI acts, applies your policy before the action completes, and leaves behind evidence another party can check.
Policy runs inline on governed inference, tool calls, and agent actions. Blocks and redactions happen before completion.
Each governed action seals a signed, hash-chained, content-free receipt. Prompts and outputs stay inside your boundary.
Anyone can verify a receipt offline in a browser or CLI. No Glacis account and no network call are required.
{
"operation_type": "tool_call",
"policy": { "id": "customer-boundary-v1", "mode": "enforce" },
"decision": "redact_then_allow",
"content_included": false,
"signature_algorithm": "Ed25519",
"witnesses": []
}
The first useful result arrives before the account setup. Start on one machine, then decide whether the rest of the team needs it.
Install Glacis and mint a real signed receipt locally. No account. No network.
Give Claude Code, Codex, or Cursor the quickstart and let it perform the install with you watching.
Open the quickstart →Add shared policy, workspaces, and fleet coverage when one governed path becomes many.
See team options →Free forever: mint and verify, unmetered · Paid: workspaces, team policy, and fleet · Next: independent witnessing
If the claim outruns the product, the build fails. A test reads our marketing. Another keeps every receipt’s witness list empty until an independent witness exists.
We steward OVERT, an open, royalty-free standard for evidence that can travel across vendors, models, clouds, and review systems.
Inspect the standard →