Platform Platform
System
ConceptsEnginePolicy as codeDeclarationsSafe changeGatewaysIntegrationsObservabilityAdministrationSecurityHuman reviewAudit and evidenceData retentionSecrets and data classification
Controls
Registries and documentationAuthentication and authorizationInjection detectionData redactionCode fingerprintingRole and judge checksContent classificationSpend and loop limitsBusiness rules
Solutions Solutions
By what you do
Sell into the enterpriseControl the AI you run
By industry
Financial servicesDigital assetsInsuranceHealthcareLegalUser-generated content
By discipline
AI governanceTrust and safetyRisk and compliance
Cases Cases Embedded control planeSource-code leakTrading agents over MCPLive firehoseRefund assistant
Compare Compare LiteLLMNVIDIA NeMo GuardrailsOPAROOSTAgent Governance Toolkit
Resources Resources
Guides
Enterprise review questionsPrompt injectionAgent and control layerAgent architecturesDecision system mapAI control maturity model
Standards
Standards OWASP Agent Control StandardEU AI ActPMI AI standardNIST AI RMFERC-8004
Book a demo
Solutions · By discipline

AI governance

The risk comes from the model: it can leak data, follow an instruction hidden in something it read, or step out of the role you deployed it in. Governance starts with a list of what you run, and that is where most programs stall.

A check has to sit outside the agent

The right check depends on the decision. A payment threshold or a sanctions screen needs a strict rule that gives the same answer every time. Whether a support reply broke your tone policy, or an assistant stayed in its role, needs a model that reads your rulebook.

We run both, and everything in between, hosted or on your own hardware:

  • a rule;
  • a small trained classifier;
  • a check on a criterion you typed this morning;
  • a judge model reading your whole policy document.

Most deployments use several, and the cheap ones decide what reaches the expensive ones.

Any of them is a control when four things are true:

  • it is declared outside the thing it guards;
  • it is versioned;
  • it can be tested before it is promoted (put into service);
  • what it decided is recorded.

The same judgment written into the agent's own system prompt is a hope, because the agent you are asking to obey the rule is the one that was talked out of it.

The list of what you run comes from the traffic

Ask an organization to list every AI system it runs and you get a spreadsheet somebody updated in March. Ask which of them can move money, read customer records, or send email, and you get silence.

Here an agent is added to the registry by its first call through Swiftward, so the registry stays current. What is on the record for each agent.

We produce the evidence. Your system's risk tier under the law is your decision, made with your counsel: see our read of the EU AI Act.

A control with no record is only a claim

An auditor does not take "we block prompt injection" for an answer. They ask for the decision record: the rule that fired, the frozen version that was live, and the request you can point at.

Where each question is answered

What am I running?Registries and documentation
Who may call what?Authentication and authorization
What arrived from outside?Injection detection
What must not leave?Data redaction · code fingerprinting
Did it stay in role?Role and judge checks
What is it costing me?Spend and loop limits
What did it actually do?Audit and evidence

Where it applies

Every industry that runs AI: financial services, digital assets, insurance, healthcare, legal, platforms carrying user content.

Related: case: trading agents over MCP · case: source-code leak at a large enterprise
Book a demo