Obiguard Governance AI inspects every prompt, response, and tool-call across your stack — enforces policy, blocks exfiltration, and gives security & legal a single ledger of evidence. It also red-teams your agents against the Project Moonshot catalogue, scores their outputs for bias and fairness every night, and reports coverage against five AI governance frameworks.
A live project dashboard shows token usage, cost, request volume, errors, threats blocked, and average latency. The Violations view surfaces every policy breach — filtered, searchable, and exportable.
Violations flagged for human judgment land in the Review Queue. Assign, annotate, and resolve — with a full audit trail from the original event to the decision.
Group enforcement rules into Policy Sets and assign them to AI Agents. Each set defines criteria, action (block / flag / allow), and whether violations route to the Review Queue.
Maintain a living registry of every AI Use Case and Agent in your organisation. Link each agent to its policy set — so governance follows the workload, not the calendar.
Every prompt, response, tool-call, and policy decision is written to an Audit Log. Export it to CSV for your GRC stack, or hand the auditor a timestamped record.
Define organisation-wide Controls and the Criteria that trigger them. Controls carry an approval workflow with segregation of duties — a submitter cannot approve their own control.
A nightly job samples the previous day’s traces and scores each one against six LLM judge criteria — toxicity, demographic bias, sentiment consistency, fairness, misinformation, and privacy leakage. Anything below 60 is flagged for review.
Benchmark and red-team your registered agents against the Project Moonshot catalogue from AI Verify Foundation — safety, bias, jailbreak resistance, privacy leakage, and capability. Every run is graded and retained as governance evidence.
See how your policies, controls, criteria, use cases, and violations line up against NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, AISCF, and Singapore’s MGF for GenAI. Each category shows covered / partial / not covered, with the evidence behind it.
Go deeper on any of them: inspection, Policy Sets, the Audit Ledger, Ethics & Bias reporting, Project Moonshot evaluations, and framework mapping.
Create a project, generate an Access Key, and route your AI agents through Obiguard. Works with OpenAI, Anthropic, Bedrock, Vertex, Azure OpenAI, and any OpenAI-compatible endpoint.
Add your AI Use Cases and register each AI Agent in the platform. Link agents to the business function they serve — so every governance decision has full context.
Build a Policy Set — define your Criteria, set the action (block or flag), and assign the set to your agents. Violations surface immediately in the dashboard.
Red-team each agent against the Moonshot catalogue, let the nightly Ethics & Bias job score live traffic, and read framework coverage off one page. Violations still land in the Audit Log and Review Queue — export the whole lot as evidence.
Everything below is running in the product today — including Project Moonshot evaluations, the nightly Ethics & Bias report, and framework coverage across five standards. Inspection runs at the gateway layer: no retraining, no access to your weights or training pipeline.
Jailbreak/injection, PII, NSFW, toxicity, gibberish, profanity, ban list, competitor mentions, and format guards — plus keyword, regex, and LLM-judge criteria you write yourself.
OpenAI, Anthropic, Bedrock, Azure OpenAI, Vertex AI, and more — one gateway in front of all of them.
NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, Malaysia’s AISCF, and Singapore’s MGF for GenAI — as a self-assessment aid, not a certification.
Toxicity, demographic bias, sentiment consistency, fairness, misinformation, and privacy leakage — scored on a random sample of yesterday’s traces.
The US reference vocabulary for AI risk — Govern, Map, Measure, Manage. What most enterprise risk teams have already adopted internally.
The only certifiable standard here — an AI management system in the same family as ISO 27001, audited by an accredited body.
How LLM applications actually get broken — injection, disclosure, excessive agency. The list your security team already works from.
Malaysia’s national framework from NACSA — 42 security activities across a seven-phase AI system lifecycle, from Inception to Retirement.
Singapore’s baseline for trusted generative AI from IMDA and AI Verify Foundation — nine dimensions, five of them a deployer can evidence.
Define your own Controls and Criteria with custom labels and evidence mapping — the same coverage view, scored against the policy your organisation actually wrote.
Don't see what you're looking for? Our solutions engineers respond within one business day.
Talk to an SE →A 20-minute call with a solutions engineer is enough to scope your pilot. Most customers are enforcing policy in production within two weeks.