For regulated organisations

Prove your agents are
under control.

Sooner or later a customer, an auditor or a regulator will ask you to demonstrate it. A control that decides by judgement cannot be certified — standards approve mechanisms an inspector can open and examine. enclawed is that mechanism.

Why probabilistic controls cannot close this

Model-judged guardrails

An LLM reviewing another LLM lowers the rate of bad actions. It cannot guarantee one, and there is no certificate for a rate.

Governance platforms

Control depends on a semantic model built and maintained by hand, and an LLM reasoning over it. Whatever is not modelled is not governed.

enclawed

Permitted if and only if the action matches declared policy. No model to maintain, no interpretation step, and a single component an assessor can evaluate.

A structural difference, not a feature gap. A control that reconciles many policies at interaction time cannot be enumerated in advance — and what cannot be enumerated cannot be certified, nor reconstructed for an inspector after an incident. A fixed list can be both.

What an assessor gets

  • Deterministic admission control. Per-tool authorisation, evaluated before any irreversible action executes.
  • A tamper-evident record. Cryptographically chained, independently re-verifiable, with four linked entries per request so the trace can be reconstructed.
  • A hardware root of trust. Physical entropy source; tamper detection meeting FIPS 140-3 Level 2 on the current device, with the architecture designed for Level 3/4 and Common Criteria.
  • Fail-secure behaviour on violation. A mismatch between what happened and what was recorded halts operations and latches — surviving restart, clearing only by human recovery with the bound device present, with a forensic snapshot captured at the moment of the event.

What it maps to

FrameworkWhere enclawed supplies evidence
EU AI Act (Reg. 2024/1689)Human oversight, robustness, and event logging for high-risk systems.
NIS2Risk-management measures and traceability of automated action on essential systems.
GDPRDemonstrable technical control over automated access to personal data.
DORAOperational-resilience evidence and an operations register for financial entities.
FIPS 140-3Level 2 met by the current device; Level 3/4 is the design target of the module programme.

Frameworks certify the deploying organisation. enclawed supplies the controls and the evidence, not the certificate.

Published, peer-reviewed, and on the standards track. Six papers filed in four months; one examined by independent reviewers and accepted at an ACM workshop. Two live Standards Track proposals to extend the Model Context Protocol — one authored, one co-authored, whose canonicalisation is aligned to the first.

Sector briefs

Written for the people who have to sign: threat model, control mapping and the evidence each framework expects.

Federal & DoD Financial services Healthcare AI & LLM operators Critical infrastructure Cloud & DevSecOps

See the measurements · Research & papers · For security teams

Begin with an exposure review

Every deployment is bespoke, so it starts by looking: which agents run, under which credentials, and what they can reach. You keep that finding either way.

Talk to us