The Platform

Every layer of AI risk, in one console.

Runtime enforcement, data posture, agent governance and audit-grade evidence — unified in a single platform an enterprise can turn on the same afternoon. No firewall change, no model swap, no vendor fabric.

Architecture

One enforcement plane between your people and every model.

Isometric XAIGuard architecture: user and application layers at the top, a mint-highlighted enforcement plane in the middle with PAC, browser extension and API proxy entry paths, model providers on the right, and a hash-linked evidence chain at the base
01

Runtime Enforcement

Every prompt and response, scored inline before it moves.

RT-01

Prompt risk scoring

Every prompt scored across 8 risk dimensions through a 4-stage classify → validate → policy → verdict pipeline.

Learn more
RT-02

Data loss prevention

Inline detection and redaction of PII, secrets, credentials and API keys in prompts and responses.

Learn more
RT-03

Natural-language policies

Write a rule in plain English; the platform turns it into an enforced guardrail with a verdict.

Learn more
RT-04

Bulk and API scanning

Score prompts in batches or from your own services over REST.

Learn more
RT-05

Guardrail generation

Generate system-prompt guardrails from your policy set.

Learn more
02

Data & Posture

Know what data AI can reach, and what reaches AI.

DP-01

AI DSPM

Classify data flowing into AI, track posture and detect drift.

Learn more
DP-02

Datastore inventory

Catalogue the stores AI can reach and their sensitivity.

Learn more
DP-03

Identity risk

Humans, service accounts, agents and tokens scored for dormancy, secret age, MFA and privilege.

Learn more
DP-04

DataWatcher

Monitor for exposure and breach signals.

Learn more
DP-05

Shadow-AI discovery

Ingest proxy, firewall or CASB logs and surface GenAI usage happening outside enforcement.

Learn more
DP-06

AI code scanning

Scan source for AI-specific vulnerability patterns.

Learn more
DP-07

Model artifact scanning

Flag unsafe deserialization, pickle-format artifacts, Keras Lambda layers, unpinned or remote model sources, trust_remote_code, and missing checksums.

Learn more
DP-08

Supply chain analysis

Dependency and component risk scoring with mitigations.

Learn more
DP-09

RAG security hub

Assess retrieval pipelines for injection, leakage and access-control gaps.

Learn more
03

Agents & MCP

Autonomous systems, held to the behaviour you approved.

AG-01

Agent discovery

Agents are registered automatically from observed traffic.

Learn more
AG-02

Agent drift detection

Behavioural change against the approved baseline, with alerts.

Learn more
AG-03

Blast-radius policy

Per-agent allowed tools, allowed egress domains, hourly request ceilings and daily spend ceilings, enforced inline.

Learn more
AG-04

Automatic quarantine

A violating agent is suspended and the event is written to the audit chain.

Learn more
AG-05

MCP server registry

Inventory MCP servers and their tools, rate scopes, and approve or block them.

Learn more
AG-06

GenAI governance

Usage inventory, SaaS data sources and tool approval workflow.

Learn more
04

Compliance & Evidence

Proof an auditor accepts, produced continuously.

CE-01

Tamper-evident audit chain

Hash-linked entries, Ed25519-signed exports.

Learn more
CE-02

Auditor portal

A scoped read-only role for external auditors.

Learn more
CE-03

Evidence locker

Collected artifacts, ready to hand over.

Learn more
CE-04

Continuous red teaming

On-demand campaigns across five attack families, plus scheduled weekly adversarial probes.

Learn more
CE-05

Framework mapping

OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, ISO/IEC 42001, EU AI Act, GDPR and SEC disclosure.

Learn more
CE-06

Assessments

AI readiness assessment and an SEC incident materiality decision tree.

Learn more
CE-07

Privacy operations

DSR intake and handling, and ROPA records.

Learn more
CE-08

Reporting

Exportable PDF reports for boards, auditors and regulators.

Learn more
05 — Enterprise readiness

Built for the enterprise from day one.

  • Role-based access control with five roles
  • TOTP multi-factor authentication
  • Multi-workspace, org-scoped isolation
  • REST API and API keys
  • Slack notifications
  • Email alerts and weekly digests
  • Scheduled scans
  • CSV/JSON import and export
Next step

See it run against your own prompts.