Every AI call your team makes — every prompt, every multi-agent run, every Cursor session — passes a policy gate, lands in a tamper-evident audit log, and exports as a signed Evidence Pack your auditor can verify offline.
Built for CISOs and Risk Officers who need to defend AI use cases before a regulator does.
Every AI decision lands in a hash-chained log keyed by org_id
so cross-tenant tampering is mathematically detectable. Export as a signed
Evidence Pack — the tools/verify_evidence_pack.py CLI ships
with the bundle so your auditor verifies offline, no backend access.
NIST AI RMF · ISO 42001 · EU AI Act — 59 baseline controls pre-mapped
per skill, with per-org overrides. Closed-set hallucination guard cross-checks
every cited control ID against a 259-entry truth set: a fabricated
NIST AI RMF GV-9.99 can't pass.
Per-org monthly USD cap with audited refusal — over budget, the LLM call never fires. Four hallucination signals run on every output: closed-set membership, LLM-as-judge grounding, semantic-entropy consensus, cross-vendor disagreement.
Two reflection loops, same HITL contract. Dreams watches the audit log for drift / hallucination / low-score signals and proposes prompt edits against the org's own failure cases. Parallel Universe watches the external world — curated AI-research RSS feeds + arXiv. When relevance crosses threshold it auto-sandboxes a Repo Coder session against the latest technique, and only the diff a human approves opens a PR.
Compose Skills (24 governance tasks across 8 categories), multi-agent primitives (consensus / adversarial review), and cron triggers on a visual canvas. AI Builder chat edits the graph for you. Every node execution writes a row into the same hash-chained audit log — the canvas is the planning view, the chain is the proof.